DataBrokerRemover
Draft: pending founder approval. Not yet the acceptance-bound version.

Privacy Policy

Last updated 2026-07-21. Draft version 2026-07-21-draft-v2.

1. Overview

Data Broker Remover, Inc. ("DBR", "we") is a privacy service that submits removal and opt-out requests to US data broker and people-search sites on your behalf. This policy explains what we collect, how we use it, and who else ever sees it.

If you read only one line: we never sell your personal information, and we never share it for marketing, advertising, or list-building. The only parties that ever touch it are the service providers listed in this policy that help us operate DBR itself, and the specific data broker we are opting you out of on your behalf, under your authorization. Not advertisers. Not analytics vendors. Not other data brokers. Not affiliates.

2. What we collect

To submit removal requests on your behalf, we collect:

  • Identity: your first, middle, and last name.
  • Location: one current address (street, city, state, ZIP, and country) that you provide.
  • Contact: the email address and phone number you provide.
  • Date of birth: some brokers require it to match your record and complete a removal; we collect it only for that purpose.
  • Mobile advertising ID (optional): used only for brokers whose opt-out process is keyed to an advertising identifier.
  • Social media handles you optionally add (for example X/Twitter, Instagram, Facebook), used only to help match your records on brokers that key off them.
  • Removal status: the Scheduled, Submitted, or Submission confirmed state of each request, with the broker's final success screenshot as proof of submission where we have one.
  • Operational logs: standard service logs (request method, path, status, coarse network origin) used for debugging and security, kept only as long as needed and then deleted or anonymized.

Government IDs: never accepted through DBR. Brokers that require ID verification, such as certain credit bureaus, are not part of our roster today; if one is ever added, you would complete verification on that broker's own secure portal, and the ID never touches our systems.

What we never collect: your Social Security number, a government-issued ID image, financial account or payment card numbers (Stripe handles those directly), or anyone else’s personal information without their own authorization.

3. How we use it

  • To submit opt-out and deletion requests to data brokers on your behalf, as described in "Authorization to act on your behalf" below.
  • To capture the broker’s final success screen as proof that a request reached Submission confirmed. This is proof of submission, not proof that the broker deleted your information.
  • To resubmit your removal requests on a quarterly schedule, as a scheduled part of the paid plan.
  • To communicate with you about your account: request status, action needed, invoices, and security notices.
  • To process payments through Stripe.

4. What we never do

  • We never sell your personal information to anyone.
  • We never share it for marketing, advertising, or list-building.
  • We never train AI models on your personal information.
  • We do not act as a data broker, and we will resist any legal reclassification that would make us one.

5. Retention

Account data. While you have an account, your identity and request records persist so we can continue submitting and tracking removals. To request an export of your data or ask us to delete your account, email privacy@databrokerremover.com.

Account deletion. When you delete your account, we delete your data within 30 days, most within 7. Anonymized billing records may be kept as required by tax law.

Operational logs. Kept only as long as needed for security and debugging, then deleted or anonymized.

6. Third parties we share with

We share only the minimum data each of the following needs to do its job, under agreements that limit their use of it:

  • Stripe: payment processing. Card details are entered directly into Stripe-controlled fields and never reach our servers.
  • Supabase: our authentication provider (your login email, authentication metadata, and delivery of sign-in link emails) and our database (your identity stored only in encrypted form, plus owner IDs and acceptance, authorization, billing, task, and proof metadata).
  • Vercel: runs our application. Your identity may exist in memory on this platform briefly while a request is processed and encrypted; it is not stored there in plain text, and application logs are PII-redacted.
  • Postmark: delivers account and service notices, and, for California requests only, the CCPA authorized-agent opt-out emails we send to a broker on your behalf. We do not yet send that kind of state-privacy-law email for other states.
  • Fastmail, our mailbox provider: receives inbound broker replies at a per-request alias address on a domain we control, so we can retrieve proof of submission.
  • The one specific data broker your request concerns: to submit that request, we transmit only the identifiers that broker’s form requires. Only the broker actually handling your request receives it; never an aggregator or a broker outside your request.
  • Anthropic's Claude API: used in narrow, specific steps to read a broker's page during an automated removal and to decide the next bounded action, under your recorded authorization. Our prompts instruct the model not to echo your personal information back, and responses are scrubbed before logging.
  • Third-party CAPTCHA-solving services: may be used to get past bot checks on broker sites. These vendors receive only the CAPTCHA image or challenge, scrubbed of your personal information; they never receive your identity.
  • A residential proxy network: may carry the network request to a broker site that blocks standard data-center addresses. It sees only that network request, not your account or identity.

Free government options. For California residents, we always point you to the state's free DROP registry as an additional option. Using DROP is free and does not require DBR Protection.

We do not share your information with analytics vendors that profile users.

7. Authorization to act on your behalf

When you complete the authorization step, you grant DBR the authority to act as your authorized agent for the exact data brokers listed at signing, using the personal information you provided.

For most of those brokers, we do this by submitting the broker's own removal or opt-out form. For a smaller set of brokers whose process is a formal email request under a state privacy law, such as California's CCPA/CPRA, we currently send that request only for California residents. We plan to add other states as we complete legal review for each one; we do not send a state-privacy-law request on behalf of a resident of a state that has not been cleared.

Revoking. You can revoke this authority at any time from your account or by emailing privacy@databrokerremover.com.

8. Your rights (CCPA/CPRA)

  • Right to know: request an export of what we hold about you by emailing privacy@databrokerremover.com.
  • Right to delete: email privacy@databrokerremover.com to request deletion of your account and its data.
  • Right to correct: update your details from your account.
  • Right to opt out of sale or sharing: not applicable. We do not sell your information or share it for cross-context behavioral advertising.
  • Right to non-discrimination: we will never charge you more or provide a lower level of service because you exercised any of these rights.

California residents can also file a complaint with the California Privacy Protection Agency at cppa.ca.gov.

9. Where we operate

Data Broker Remover operates in the United States only. Our intake flow accepts a US state or the District of Columbia; we do not knowingly accept personal information from residents of the European Union, the United Kingdom, or other jurisdictions whose privacy laws we are not currently positioned to comply with end to end.

10. Security

Encryption at rest. Identity data is encrypted before it is stored; our database never holds your identity in plain text.

Encryption in transit. All connections to our service use TLS 1.2 or higher.

Access controls. Row-level database security is enabled on every table that holds your data, so access is scoped to your own account by default.

11. Children's data

Data Broker Remover is for adults 18 and older. Signup requires you to confirm you are at least 18. If we learn we have collected information from a minor, we will delete it.

If you believe a minor has submitted information, contact privacy@databrokerremover.com and we will remove it.

12. Changes to this policy

We will email account holders at least 30 days before any material change to this policy. A change that only expands your rights or clarifies an existing practice may take effect immediately.

13. Contact

Privacy questions and data requests:
privacy@databrokerremover.com