What this covers
This page covers this website and the accounts behind it. It is not a certificate, an audit, an uptime promise, or the result of a security test.
Everything below is true of the site as it runs today. We update this page when that changes.
We collect as little as possible
Before you sign in, this site takes no personal details, no card details, and no records about you. It sets no advertising or analytics cookies, and loads no third-party trackers.
- A form sends only what its page says it sends, and only to us.
- Our passwords and keys are stored outside the code we deploy.
- The site is not reachable directly, and runs without admin rights.
What an account holds
Once you sign in, we store your removal profile and your signed broker permission against your account. Here is what that does and does not mean.
- Your password is never stored. Supabase Auth keeps a salted hash instead.
- Card details never reach this site. Stripe collects them on its own page.
- We never accept a Social Security number or a government ID.
- Deleting your account removes eligible records within 7 days, and backup copies expire within 30.
Your receipts are protected and private
We send real broker requests and store the evidence behind your receipt. A receipt holds a screenshot or a copy of the message we sent, with private parts blacked out. We store it apart from your profile, and never pass it to a data broker or anyone else.
- Your data is encrypted, stored and in transit, with the keys held elsewhere.
- Only staff in a named role can access it, and we keep an audit trail of that access.
- How long each record is kept, and how it is deleted, follows the schedule on our Privacy page.
Report a problem
Email security@databrokerremover.com. Tell us the page, what you did, and what you saw. We reply by email. We do not promise a response time, and we do not pay bounties.