Security
An honest account of how your data is protected today, and what's still in progress.
Why we're writing this the way we are
A service built to protect your privacy should be straightforward about its own security posture, including the parts that aren't finished yet. This page describes what's actually true about how Delist My Data handles data today, not an aspirational checklist. We'll update it as things change, whether something is added or taken away.
In transit
- Every connection to Delist My Data is encrypted. Unencrypted requests are redirected to the encrypted site; there is no unencrypted way to use it.
At rest
- Removal-search data is held by our hosting provider in the United States as ordinary records and files, without field-level encryption. That covers everything you submit to be searched for, your date of birth included, along with the matches we find and each screenshot and report made from them. Encrypting this data at rest is planned and will be turned on before the service holds submissions at any meaningful scale. We'd rather say that here than let you assume otherwise.
Your account
- Invite-only, one account per invitation. Accounts are currently created by invitation. Each invitation code admits exactly one account and may be tied to a single email address. Left unused, it expires.
- Passwords we can't read. Your password is stored only in a form that cannot be reversed to recover it, and must be at least 12 characters. If you'd rather not have one at all, you can sign in with Google instead.
- Confirmed email before anything sensitive. Your account won't accept names, dates of birth, addresses, or phone numbers until you've confirmed the email address on it.
- Your sign-in ends after 10 minutes without any interaction. A minute before that, a notice offers to keep you signed in. Ignore it and every tab you have open signs out together. No sign-in lasts longer than 12 hours however active it's been, and closing your browser ends it as well. Once you're signed out, your browser isn't allowed to keep copies of account pages, so the back button won't bring your details back. Signing out yourself ends it immediately.
- Sign-in and sign-up are rate-limited, as is entering data, so that bulk submission and automated guessing don't work.
- Your data is yours alone. The account area shows each person only their own records. There is no path through it from one user's data to another's.
Access control
- Internal access to removal-search data is limited to the small team operating the service and is used only to run it. That means searching for your listings and filing removals, and answering when you write to us.
- Reviewing your results is a permission you hold. A setting on your account decides whether our team may open your results and the details you entered. While we're in early release it starts switched on; with it switched off, the internal review tool will not open your account at all.
- The review tool looks and cannot act. It renders your account the way you see it and refuses every action that would change anything, from starting a scan to editing what you entered. That refusal is built into the tool rather than left to the person using it. A review session ends on its own after 30 minutes, or after 10 if the reviewer stops doing anything.
- Every access is recorded, and you can read it. Opening an account for review, and viewing it as its owner, each write a dated record of who did it. That record is shown to you on your own account page. This is the logging this page previously said was still on our list.
- What that record does not cover. It's held in the same database as the rest of the service, so it bounds what the application permits, not what someone with direct access to our servers could do. Moving it somewhere it can only be appended to is the next step, and we'd rather say that than let the word “recorded” carry more weight than it has earned.
What we don't do
- We don't ask for your Social Security number or a government ID, and we don't take payment or financial details. Nothing in the service needs them, which also means there is nothing financial for our own team to see when reviewing your results.
- We don't sell your personal information, and we don't share it for cross-context behavioural advertising.
- We don't run advertising or remarketing tags, or anything that tracks you across other sites. We removed the Google Ads tag this site briefly carried.
- We do run Google Analytics 4 for traffic measurement, with ads-personalisation signals switched off. It receives site-usage data only. Nothing you enter to be searched for reaches it, and neither does anything we find or generate for you. See the Privacy Policy for the full disclosure and how to opt out.
Reporting a security issue
If you believe you've found a security vulnerability affecting Delist My Data, please email contact@delistmydata.com with details. We ask that you give us a reasonable window to investigate and address the issue before any public disclosure.
For how we handle your data more broadly, see our Privacy Policy and Terms of Service.