Legal
Privacy Policy
Deindex is a privacy company, so we hold ourselves to the standard we sell. We collect the least data we can, we tell you exactly what each piece is for, and we never sell it.
Last updated July 13, 2026
At a glance
- We collect the identity details you give us to run a scan and to file a removal, and little else.
- We never sell your personal data, and we run no advertising trackers.
- To ask a broker to delete you, we have to share the specific record you want removed. That is inherent to the service.
- You can access, export or delete your data at any time by emailing [email protected].
Who we are
Deindex ("Deindex", "we", "us") operates deindex.io, a service that finds where a person's personal data is published by data brokers and people-search sites and files lawful removal requests on their behalf. For the purposes of the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Deindex is the data controller of the personal data described in this policy. You can reach our privacy team at [email protected].
Data minimization
Our starting principle is to collect as little as possible. We do not ask for a Social Security number, a date of birth, or a government ID to run a scan. A scan needs a name and a city or state, and optional details you choose to add, such as a maiden name or a past address, only make the match more accurate. You decide how much to give us, and more data is never required to use the service.
What we collect and why
The table below lists every category of personal data we process and the reason for it.
| Data | Why we collect it |
|---|---|
| Search identity | The name, city or state, and any name variants, past addresses, phone or email you add. Used to search the broker catalog and to identify the exact listing to remove. |
| Account | Your email address and a hashed password. Used to sign you in, save your report, and send removal updates. We store a one-way hash of your password, never the password itself. |
| Scan results | Which sites list you, the listing URLs, the data categories each one publishes, and the before and after evidence screenshots. Used to build your report and prove each removal. |
| Removal records | The legal basis we filed under and our correspondence with each broker. Used to run the request and to give you an auditable trail. |
| Billing | Your plan and subscription status. Card payments are handled by our payment processor. We never see or store your full card number. |
| Technical and security | Your IP address and a session identifier, used to meter free usage, keep the service secure, and prevent abuse. |
Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Contract. Running your scan, filing removals and maintaining your account is necessary to provide the service you signed up for.
- Legitimate interests. Keeping the service secure, preventing abuse and metering free usage, balanced against your rights.
- Legal obligation. Keeping the records we are required to keep, for example for tax and accounting.
- Consent. Where you add optional details to widen a scan, you may withdraw that consent at any time.
How we use your data
- To run exposure scans and build your report.
- To file lawful removal requests and to monitor for relisting.
- To send you service messages: a verification code, a report, or a removal status update.
- To take payment and manage your subscription.
- To keep the service secure and to meet our legal obligations.
We do not use your data to build advertising profiles, and we do not sell it.
Sub-processors
We rely on a small set of vetted providers, each under a data processing agreement:
| Role | What they process |
|---|---|
| Cloud hosting | Runs the application and stores your data in encrypted form. |
| Payment processor | Takes card payments and manages subscriptions. Holds your card data, which we never see. |
| Email delivery | Sends verification codes, reports and removal updates, and delivers erasure requests to brokers. |
| Web font mirror | Serves our fonts from a privacy-respecting mirror that does not log or track visitors. We use no Google Fonts. |
We keep an up-to-date sub-processor list and will provide it on request to [email protected].
How long we keep it
We keep your account and removal data for as long as your account is active, because monitoring for relisting is an ongoing job. When you close your account, we delete your personal data within 30 days, except records we must keep by law, such as billing records for tax purposes, which we retain for the required period and then delete. Anonymous scan data that is no longer linked to you is deleted or aggregated.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access a copy of the data we hold about you.
- Correct data that is wrong or out of date.
- Delete your data (GDPR Article 17, CCPA/CPRA delete). We practise this on brokers, and we honour it for ourselves.
- Port your data to another service in a portable format.
- Object to or restrict certain processing, and withdraw consent where we relied on it.
- Non-discrimination: we will not treat you worse for exercising any of these rights.
To exercise any right, email [email protected]. We respond within the time the law allows, generally within 30 to 45 days, and we may need to verify your identity first. You may also authorise an agent to act for you. If you are in the EU or UK and are unhappy with our response, you have the right to complain to your local data protection authority.
Security
We encrypt data in transit and at rest, hash passwords, restrict access to the people who need it, and log administrative actions. No system is perfectly secure, but because our whole reason to exist is protecting personal data, we treat a breach of yours as the most serious thing that can happen here. If a breach ever affects your data, we will notify you and the relevant authority as the law requires.
International transfers
We may process data in the United States and other countries. Where we transfer personal data out of the EU, the UK or other regions with transfer rules, we rely on an approved safeguard such as the European Commission's Standard Contractual Clauses, together with additional measures where needed.
Children
Deindex is for adults. We do not knowingly create accounts for anyone under 18. A Family plan may cover adult household members and, at a parent's or guardian's direction, a minor's exposure, but the account holder must be an adult. If you believe a child has given us data directly, contact us and we will delete it.
Changes to this policy
If we change this policy, we will update the date at the top and, for material changes, tell you by email or in the app before they take effect. Continuing to use Deindex after a change means you accept the updated policy.
Contact us
For any privacy question, or to exercise a right, email [email protected]. This is the only address to use to reach us about your data.