Delist handles sensitive identity and exposure data. This page states the controls we can substantiate, the data that leaves our systems to perform the service, and the assurance work we have not yet completed.
Security facts last reviewed August 27, 2026.
The canonical customer profile record is encrypted with AES-256-GCM using a scrypt-derived key before it is written to the database. Authentication tags detect modification as well as protect confidentiality.
Not every operational record is application-layer encrypted. Scan findings, workflow and email records, listing URLs, and removal evidence may contain personal information and are protected by infrastructure and application access controls. We do not describe the entire datastore as AES-encrypted.
The public web edge accepts TLS 1.2 and TLS 1.3. Data sent onward to service providers and removal targets uses their secured network endpoints where available; “end-to-end encrypted” would be inaccurate for an opt-out service.
A scan job receives its own server-side directory. Decrypted profile files are permission-restricted, and cleanup runs after job expiry and during startup recovery. This is bounded temporary disk processing, not memory-only processing.
Scanning and much of the removal workflow are automated. Authorized operators may access customer information when needed to run, support, secure, or troubleshoot the service. We do not promise that no person can ever view a customer record.
Subscriptions are our only revenue. There's no second business model here.
We collect identity details, scan inputs and results, removal workflow records, security and operational logs, and first-party product events needed to provide and improve the service. We do not use third-party advertising trackers or sell this information.
Delist relies on providers for hosting and storage, payments, email, search, breach lookup, page retrieval, and automated analysis. Each receives only the information needed for that function. See the Privacy Policy for the current list and purposes.
Account deletion removes the profile and linked application records and attempts to cancel active billing. Private evidence files age out under a storage lifecycle of up to 365 days. Limited payment, audit, security, and anti-reingestion records may remain when required.
| SOC 2 | No report currently published or claimed |
|---|---|
| Independent penetration test | No report currently published |
| Internal security review | Security findings and remediations are tracked in the engineering repository |
| Automated controls | Security-focused tests cover authentication, authorization, input handling, erasure paths, webhooks, and other high-risk boundaries |
Internal review and automated tests are useful controls, but they are not equivalent to independent certification. We will update this page when the assurance status changes.
Your full name, email address, US phone number, and home address, with birth year optional. The canonical profile record is encrypted before database storage.
The service decrypts the profile for scanning. A permission-restricted temporary job file may be used, and findings are stored for the report and future comparison.
We send the identifying details needed to locate and suppress your record to data brokers, people-search sites, and supporting service providers. Workflow and delivery records are retained to track the request.
Paid plans run a full scan each month. Findings and removal history are retained while the service needs them to compare results, show progress, and re-file eligible requests.
Questions about how we handle your data.
Delist uses automated systems for scanning and removal work, but authorized operators may access customer information when needed to run, support, secure, or troubleshoot the service. Service providers receive the data needed for their role, and removal targets receive the information needed to identify and suppress a record.
The canonical customer profile record is encrypted with AES-256-GCM using a scrypt-derived key before it is stored. Scan findings, workflow records, email records, and evidence may be stored separately and are protected by infrastructure and application access controls; Delist does not claim that every database field is application-layer encrypted.
Delist uses first-party, cookie-free event collection. It records a session-scoped random identifier, page path, attribution parameters when present, and allowlisted product events. Once you run a scan or sign in, those session events are associated with your account. The public event endpoint is designed not to collect scan answers or profile fields.
Account deletion removes the profile and linked application records and cancels an active subscription when possible. Evidence files can remain in private storage until their lifecycle deletion, currently up to 365 days. Limited payment, audit, security, and anti-reingestion records may remain where legally or operationally necessary.
Encryption reduces the impact of some compromise scenarios but does not make a breach harmless. Delist investigates incidents and will provide legally required notices. The effect depends on which systems and records are involved.
Yes. Delist uses providers for hosting and storage, payments, email, search, breach lookup, page retrieval, and automated analysis. It also sends identifying information to removal targets when needed to process an opt-out. Delist does not sell personal information or share it for third-party advertising.
No SOC 2 report or independent penetration-test report is currently published for Delist. The service has internal security reviews and automated security tests, but those are not substitutes for independent assurance.
See where you are exposed, review the result, and decide whether ongoing removal is right for you.