Data Security
Last updated: July 23, 2026
1. Our security commitment
Protecting the personal information you entrust to us is central to our mission. Data Remover is designed so your information is used only to find, remove, and monitor your records across the 31 data brokers and people-search sites we track — not to build advertising profiles, resell data, or support unrelated third-party marketing.
Security is an ongoing process. We combine technical controls, operational safeguards, vendor management, and employee practices to reduce risk across the Service.
2. Encryption
We protect data using industry-standard encryption and transport security:
- In transit: connections to the Service use TLS 1.2 or higher, with TLS 1.3 preferred where supported.
- At rest: stored data is encrypted using AES-256 or equivalent standards on production systems and backups.
- Field-level protection: especially sensitive identifiers used for broker matching and opt-outs receive additional application-layer encryption.
Encryption reduces risk but cannot eliminate it entirely. You also play a role by using a strong password and protecting access to your account.
3. Access controls
Access to production systems and customer data is granted on a least-privilege basis and limited to personnel and systems with a documented business need.
- role-based permissions for engineering, support, and operations staff;
- multi-factor authentication for administrative and internal tools;
- automated decryption limited to removal workflows that require it;
- logging and review of privileged or sensitive access events.
Support staff can access account information only when necessary to assist you and in accordance with internal policies.
4. Infrastructure and network security
The Service is hosted on cloud infrastructure providers that maintain independent security certifications and controls. Our environment includes measures such as:
- network segmentation and private service communication where appropriate;
- web application firewall and abuse protection at the edge;
- regular patching and vulnerability management;
- encrypted, geographically redundant backups with tested restore procedures;
- monitoring, alerting, and centralized logging for security-relevant events.
5. Application and account security
We protect user accounts through strong password requirements, secure session handling, optional multi-factor authentication, and the ability to sign out of active sessions. We review authentication flows and account recovery processes to reduce account takeover risk.
6. Data minimization
We collect and retain only the information needed to operate the Service effectively. This typically includes your legal name, addresses, phone numbers, email addresses, aliases, and removal activity associated with your account, used to scan and remove your records from the 31 data brokers and people-search sites we track. You can review, update, or request deletion of much of this information through your dashboard or by contacting us.
7. Vendor management
We use carefully selected service providers for hosting, payments, email delivery, analytics, and customer support. Vendors that process personal information on our behalf are required to implement appropriate security measures and use data only for the services they provide to us.
8. Incident response
We maintain procedures designed to detect, investigate, and respond to security incidents. If we become aware of a breach that affects your personal information in a manner that requires notification under applicable law, we will notify you and relevant authorities as required.
9. Employee practices
Employees and contractors with access to sensitive systems receive security and privacy training and are subject to confidentiality obligations. Background checks may be used where appropriate for roles with elevated access.
10. What we never do with your data
- We do not sell your personal information.
- We do not use your data to train unrelated advertising models.
- We do not share your information with third parties except as needed to operate the Service, comply with law, or submit broker removals on your behalf.
11. Compliance and your controls
Our privacy and security practices are designed to align with applicable requirements, including GDPR, CCPA, and CPRA where relevant. You can export your data, manage account settings, and request account deletion. Most account data is deleted within 30 days of a verified deletion request, subject to limited legal or billing retention needs. See our Privacy Policy for more information about your rights.
12. Reporting a security issue
If you believe you have discovered a security vulnerability or unauthorized activity involving the Service, contact security@dataremover.io. Please include enough detail for us to investigate. We ask that you do not publicly disclose vulnerabilities until we have had a reasonable opportunity to address them.
13. Changes to this page
We may update this page as our technology, vendors, or legal obligations evolve. Material changes will be communicated through the Service or by email where appropriate.