Privacy Policy
Effective date: August 27, 2026
1. Introduction
Delist.ai ("we," "us," "our") is a privacy removal service. This Privacy Policy explains how we collect, use, and protect your personal information when you use our website and services at https://delist.ai.
We built Delist.ai to protect your privacy — and we hold ourselves to the same standard.
2. Information We Collect
Information you provide
- Name, city, and state (required for scanning)
- Phone numbers, email addresses (optional, improves scan accuracy)
- Birth year (optional, for identity verification)
- Home addresses (optional, for exposure scanning)
- Payment information (processed by Stripe — we never store card numbers)
Information collected automatically
- First-party, cookie-free product analytics, including a session-scoped random identifier, page path, referral and campaign parameters when present, and allowlisted interaction events
- Standard server and security data, such as request time, IP address, user agent, and error information
- No tracking cookies are set
- No third-party advertising trackers are used
3. How We Use Your Information
- To scan data broker and people-search sites for your personal information
- To submit opt-out and removal requests on your behalf
- To monitor for re-listings of your data
- To send you scan results, removal updates, and account notifications
- To process payments for subscription services
We do NOT use your information for:
- Advertising or marketing to third parties
- Building profiles or behavioral tracking
- Selling personal information or sharing it for third-party advertising
- Training AI models or machine learning systems
4. How We Protect Your Information
Profile encryption at rest: The canonical customer profile record is encrypted using AES-256-GCM with a scrypt-derived key before database storage. Scan findings, workflow records, email records, listing URLs, and evidence may be stored separately and are not all application-layer encrypted.
Temporary processing: A scan may write a decrypted profile to a permission-restricted, job-specific server directory. The service removes expired job directories and runs recovery cleanup after restarts. We do not claim that processing is memory-only.
Encryption in transit: The public Delist web edge accepts TLS 1.2 and TLS 1.3. Providers and removal targets receive information through their own secured endpoints where available.
Access controls: Customer-facing, internal, and administrative routes use separate authorization checks. Infrastructure and application access are limited to operating the service, but authorized operators may access customer information when support, security, or troubleshooting requires it.
Security assurance: We conduct internal security reviews and maintain automated security tests. As of the effective date, Delist does not publish a SOC 2 report or an independent penetration-test report. See Security & trust for the current status.
5. Browser Extension ("Spam Analyzer")
Our Chrome extension allows users to check suspicious text, links, and webpages for phishing, scams, and social engineering threats. This section describes the extension's data practices specifically.
What the extension sends
- When you right-click selected text and choose "Spam Analyzer", the selected text and the page URL are sent to our API for analysis.
- When you right-click a link, the link URL is sent to our API for analysis.
- When you click "Analyze current page," the visible text content of the page (up to 8,000 characters) and the page URL are sent to our API for analysis.
What the extension does NOT do
- Does not run on any page unless you explicitly trigger an analysis
- Does not read your browsing history
- Does not collect emails, passwords, form inputs, or keystrokes
- Does not track which websites you visit
- Does not send any data in the background without your action
- Does not use cookies or tracking identifiers
Local storage
- Analysis history (verdict, threat level, summary, and timestamp) is stored locally in your browser only. It is never sent to our servers.
- A one-time onboarding flag is stored locally to remember that you've seen the welcome screen.
Permissions
- contextMenus: To add the right-click "Spam Analyzer" menu items.
- activeTab: To read the current page text only when you click "Analyze current page."
- scripting: To extract page text when you explicitly request page analysis.
- storage: To save your local analysis history in the browser.
6. Data Sharing
We share your information only in the following limited circumstances:
- With data brokers and people-search sites, solely to submit removal requests on your behalf (this is the core service)
- With Google Cloud, to host the service and store private removal evidence
- With Stripe, to process payments (Stripe handles card data under its own privacy policy)
- With Mailgun, to deliver account, removal, and transactional email
- With Serper, to run search queries used for exposure discovery
- With Google Gemini, to analyze page content, breaches, and potential threats where those features are used
- With Bright Data, when needed to retrieve public pages that block ordinary requests
- With Have I Been Pwned, to perform breach lookups where that feature is used
- If required by law, court order, or legal process
We do not sell personal information or share it for third-party advertising. Providers receive information for the stated service purpose, and removal targets receive the identifying details needed to locate and suppress a record.
7. Data Retention
- Active accounts: Your encrypted profile and scan history are retained while your account is active.
- Free scans: The details you enter for a free scan (name, email, phone, and location) and the scan results are encrypted at rest. We keep them so your report is still there when you come back. You can have them deleted at any time — email privacy@delist.ai, or delete your account from your dashboard settings once you've subscribed.
- Paid removals: If you subscribe, the information needed to file and verify opt-out requests is retained, encrypted, for as long as your subscription is active — so we can keep removing your data and catch re-listings. You can delete it any time from your dashboard.
- Account deletion: When you delete your account, the service deletes the profile and linked application records and attempts to cancel active billing. Evidence files are stored separately in a private bucket with a 365-day lifecycle, so those bytes may remain until that lifecycle removes them. Limited payment and tax records, anonymized audit entries, security records, and keyed anti-reingestion tombstones may remain where legally or operationally necessary.
- Payment records: Transaction records required for tax and accounting purposes are retained as required by law.
8. Your Rights
You have the right to:
- Access your personal information (viewable in your dashboard)
- Correct inaccurate information (editable in your profile settings)
- Delete your account (available in dashboard settings)
- Opt out of marketing emails (we don't send marketing emails — only transactional notifications)
Depending on your state of residence, you may have additional rights under state privacy laws. Contact us at privacy@delist.ai to exercise them.
9. Cookies
We do not use advertising or analytics cookies. First-party analytics use a random identifier stored for the browser session and send page paths, attribution parameters when present, and allowlisted events to Delist. Once you run a scan or sign in, those session events are associated with your account. Authentication may use secure, httpOnly session cookies; those are functional, not advertising cookies.
10. Children's Privacy
Delist.ai is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us at privacy@delist.ai and we will delete it promptly.
11. Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be sold or transferred as part of that transaction as permitted by law and/or contract. In such event, we will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page. Your continued use of the service after changes constitutes acceptance.
13. Contact
For questions about this Privacy Policy or our data practices:
- Email: privacy@delist.ai
- General support: support@delist.ai