Skip to content

Legal

Privacy Policy

Effective October 7, 2026

WipedMe exists to get your information off data-broker and people-search sites, so we try hard to hold as little of it as we can. This policy explains what we collect, why, who receives it, how long we keep it, and the rights you have. The short version: we collect what we need to file your requests, we share it only with the sites we file with and the providers that run WipedMe, and we never sell it.

The short version

  • We collect the details sites match on (names, addresses, phone numbers, emails, and, if you choose, your date of birth), plus what we need to bill you and to prove you authorized us.
  • We never ask for your Social Security number, a government ID number, or a financial account number, and we never see your full card number.
  • We send your details only to the sites we file requests with, to California's DROP platform if you choose to use it, and to the service providers that run WipedMe: Stripe (payments), Supabase (database), Netlify (hosting), Zoho (business email, and file storage for our request log and evidence), and Resend (service emails such as your purchase confirmation and setup links).
  • We don't sell your personal information, share it for advertising, or use it to build profiles. Our site has no analytics or advertising trackers.
  • You can ask to see, correct, or delete your information at any time by emailing privacy@wipedme.com.

Who we are

WipedMe is a trade name of CILE LLC, a Wyoming limited liability company ("WipedMe", "we", "us"). We decide how the personal information described here is used. This policy covers wipedme.com, checkout, onboarding, and the removal service. Our privacy contact is privacy@wipedme.com.

WipedMe is not a data broker, and we don't run a people-search or lookup service. We act as your authorized agent to file opt-out and removal requests.

What we collect

When you buy a plan. Your email address, the plan and billing cycle you choose, and a record of your consent to the automatic renewal terms and our Terms (the time and the version of the terms you saw). You enter your card on Stripe's checkout page, not ours. Stripe tells us whether the payment succeeded and shares limited details such as your billing name, country and ZIP code, and your card's brand and last four digits.

When you onboard, after paying. Your full legal name and any other names you've used; your state; your current address and up to five past addresses; your phone numbers and email addresses; and, only if you choose, your date of birth. Our forms are built to refuse Social Security numbers, and we never ask for government ID numbers or financial account numbers.

When you sign your authorization. The name you type as your signature, your email, your state, the statements you ticked, and the time you signed. As evidence that you signed it, we also record your IP address, your browser's user-agent string, how long the authorization was on screen, and the version and a fingerprint (hash) of the exact text you agreed to. We keep a security log of actions on your onboarding pages, such as saving details or signing, with the time and IP address.

About other adults on your plan. On a Duo or Household plan, you give us the name and email address of each other adult so we can email them a private link. You don't see that link or anything they enter. They give us their own details and sign their own authorization, and we file nothing for them until they do. Only give us someone's contact details if they've agreed.

While we work for you. The requests we file (which site, when, and under what authority), the replies and verification messages sites send us about your requests, what we saw at each check, and your messages with us.

When you visit our site. Our hosting provider keeps standard server logs (IP address, browser type, the page requested, and the time) so we can run and secure the site. We don't use analytics, advertising cookies, or tracking pixels. The site uses your browser's session storage to carry the email address you type on one page to the checkout page, and that's cleared when you close the tab. After checkout, or when you open a setup link we email you, we set one strictly necessary cookie that keeps you signed in to your setup page for up to 30 days. It holds a random code, not your details, and isn't used for tracking. Stripe's checkout and billing pages set their own cookies to process payments and prevent fraud.

Sensitive information. We don't collect sensitive personal information as California law defines it, such as Social Security numbers, government ID numbers, financial account log-ins, precise geolocation, or health information.

What we collect, why, and for how long, at a glance

This table is also our notice at collection under California law. It lists each category of personal information, why we use it, who receives it, and how long we keep it.

Identifiers and contact details

What
Names (including other names you've used), postal addresses, phone numbers, email addresses, and IP address.
Why
Filing and following up on your requests, billing, contacting you, and security.
Who receives it
The sites we file with (only what each request needs), California's DROP platform if you choose it, Stripe, Supabase, Netlify, Zoho, and Resend.
How long
Onboarding details: while your subscription is active, then erased within 90 days after it ends. Your account email: with billing records (below).

Date of birth (optional)

What
Your date of birth, only if you choose to give it.
Why
Some sites need it to find the right record.
Who receives it
Only sites that require it to process your request, and Supabase.
How long
Same as onboarding details.

Commercial information

What
Your plan, billing cycle, payment history, and your consent to the automatic renewal terms (time and version shown).
Why
Billing, renewal and price-change notices, proving your consent, and tax records.
Who receives it
Stripe and Supabase.
How long
Up to 7 years after the transaction, for tax, accounting, and consent records.

Authorization and request records

What
Your signed authorization (typed signature, statements ticked, time, IP address, browser user-agent, time on page, document version), the requests we filed, replies from sites, what we saw at each check, and a security log of onboarding actions.
Why
Proving to sites, regulators, and courts that you authorized each request; re-filing; honest status reports; handling disputes.
Who receives it
Sites that ask for proof of our authority (a copy of the authorization or its redacted verification page), Supabase, and Zoho (our request log, the evidence of listings and confirmations, and email correspondence).
How long
4 years after your authorization ends, then erased.

Communications

What
Emails between you and us.
Why
Support, and keeping a record of what you asked us to do.
Who receives it
Zoho.
How long
Up to 3 years after our last exchange.

Website activity

What
Server logs: IP address, browser type, page requested, and time.
Why
Running and securing the website.
Who receives it
Netlify.
How long
Up to 30 days.

How we use it

  • To file, follow up on, and re-file your opt-out and removal requests, and to report what we filed and what we saw.
  • To prove to sites, regulators, and courts that you authorized us.
  • To bill you, send receipts, renewal reminders, and price-change notices, and keep the records the law requires.
  • To answer your questions and send you service emails.
  • To keep the service secure and prevent misuse under our Acceptable Use Policy.
  • To meet legal obligations and enforce our Terms.

We don't sell your information, share it for cross-context behavioral advertising, use it to build profiles or to train AI models, or use it to make automated decisions about you.

Who receives it

Sites we file with. A request only works if the site can find you, so we send each data broker or people-search site the identifiers it needs to match your record and act on the request. If a site asks for proof of our authority, we send a copy of your signed authorization or a link to its verification page. Once a site has your request, it handles your information under its own privacy policy, and some sites keep a minimal record so they can keep honoring your opt-out.

California DROP. If you live in California and choose to use the state's Delete Request and Opt-out Platform, we work with that platform, run by the California Privacy Protection Agency, as your disclosed authorized agent.

Service providers. These companies process personal information for us under contract, only to run WipedMe:

  • Stripe, Inc.: payment processing, subscriptions, receipts, and the Manage billing portal. Stripe also uses payment information for its own fraud prevention and legal obligations under Stripe's privacy policy.
  • Supabase, Inc.: our database, where onboarding details, authorization records, and request history are stored, encrypted at rest.
  • Netlify, Inc.: hosting for wipedme.com and the servers that run it, including server logs.
  • Zoho Corporation: business email (Zoho Mail), used for support and for correspondence with the sites we file with, and file storage (Zoho WorkDrive) for our request log and the evidence of listings and confirmations (screenshots or PDFs of listings showing your details, and the sites' confirmation pages and emails).
  • Resend: delivers the service emails our website sends, such as your purchase confirmation and private setup links (your email address, your name if it's in the email, and the message).

The verification page. Each signed authorization has a verification link that a site can open to confirm it's genuine. That page shows only a redacted summary, never your full email address, IP address, browser details, or signature.

Legal reasons. When we must comply with a valid subpoena, court order, or other legal process; to investigate misuse of the service; or to protect someone's safety. Where the law allows, we tell you before we disclose anything.

If WipedMe changes hands. If WipedMe is sold, merged, or restructured, your information may transfer as part of that deal, but only to a buyer that agrees in writing to honor this policy and our public commitments. We'll email you before it happens.

No one else. We have never sold personal information. We don't share it for cross-context behavioral advertising, and we don't disclose it to anyone for their own marketing.

How long we keep it

The table above lists how long we keep each category. When a period ends, we erase the information or de-identify it so it can no longer be linked to you. Our database backups roll over within 30 days, so erased information can remain in an encrypted backup until then.

If you ask us to delete your information sooner, we erase your onboarding details and stop filing. We keep only what the law requires or what we need to show the authority behind requests already filed (billing and consent records, and your signed authorization and request history), for the periods above, and we tell you what we kept and why.

How we protect it

Information is encrypted in transit (HTTPS) and stored with Supabase, and our request log and evidence in Zoho WorkDrive, both encrypted at rest. Only our server holds the database key: there are no public database keys, and the database refuses all public access. Access to customer data is limited to the people who do the work and requires a password. Signed authorizations are kept in a tamper-evident log. Card details stay with Stripe.

No system is perfectly secure. If a breach affects your personal information, we'll notify you, and any regulator the law requires, without unreasonable delay. We'll tell you what happened, what information was involved, what we're doing about it, and what you can do.

Your choices and rights

Wherever you live in the United States, you can ask us to:

  • Tell you what personal information we hold about you, and give you a copy.
  • Correct information that's wrong.
  • Delete your information, as described under "How long we keep it".
  • Stop sending you any emails you've opted into, such as marketing.

Deleting your onboarding details means we can no longer file requests for you, so we'll also cancel your subscription. Refunds follow our Refund Policy.

We don't sell or share personal information, or use it for targeted advertising or profiling, so there's nothing to opt out of. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of sale and sharing anyway. We don't track you across other sites, so Do Not Track signals don't change how our site works.

California residents have the right to know, delete, and correct personal information; to opt out of its sale or sharing (we do neither); to limit the use of sensitive personal information (we don't collect any); and not to be discriminated against for using these rights. Residents of other states with privacy laws, such as Colorado, Connecticut, Oregon, Texas, and Virginia, have similar rights, including the right to appeal our decision. We honor these requests for everyone, whether or not a particular law applies to us.

We won't charge you more, give you a worse service, or treat you differently for using any of these rights.

How to make a request, and how to appeal

Email privacy@wipedme.com from the address on your account and tell us what you'd like. To protect you, we verify the request by matching it to your account email, and we may ask a question or two if something doesn't match. We'll never ask for a government ID number or your Social Security number.

You can use an authorized agent to make a request for you. We'll ask for your signed permission for the agent, and we may confirm the request directly with you.

We confirm receipt within 10 business days and respond within 45 days. If we need more time, we'll tell you why within those 45 days and take up to 45 more. Requests are free.

If we turn down a request, we'll explain why. You can appeal by replying with "Appeal" in the subject line. Someone who wasn't part of the first decision will review it and answer within 45 days. If you're still not satisfied, you can contact your state attorney general or, in California, the California Privacy Protection Agency.

Emails we send

Service emails: your subscription confirmation, receipts, renewal reminders, price-change notices, status updates, and security or policy notices. These come with your subscription and stop when it ends, except notices the law requires.

Marketing emails: we don't send them unless you've opted in. If we ever do, each one will identify us, include our postal address, and have a working unsubscribe link, which we honor promptly. Unsubscribing never stops the service emails you need.

Children

WipedMe is for adults, and our plans cover adults only. We don't knowingly collect information about anyone under 18. If you think we have, email privacy@wipedme.com and we'll erase it.

Where your information is processed

WipedMe is a US service for people who live in the United States. We store your information in the United States, and our service providers process it primarily in the United States.

Changes to this policy

We'll post any update here with a new effective date. For a material change, we'll email you before it takes effect. We won't use information we already hold in a materially different way without your consent.

Contact us

Privacy questions and rights requests: privacy@wipedme.com. Account, billing, and cancellation: support@wipedme.com. Anything else: hello@wipedme.com.