We sell privacy. A policy nobody can read would be a strange way to prove we mean it, so this one is written in plain sentences and says the awkward parts out loud.
Last updated 24 September 2026
The short version. We are paid by you, never by advertisers or data brokers. We never sell or share your data. The free scan stores nothing at all unless you ask us to. If you have an account, deleting everything we hold is a button in your dashboard — immediate, with a receipt.
None of Their Business is operated from the United Kingdom. For the account details and protected-person details we hold, we are the data controller. When we write to data brokers on your behalf, we act as your agent — we exercise your rights, in your name, on your instruction.
Privacy questions, requests and complaints go through our contact form, which opens a tracked ticket so nothing gets lost in a mailbox. The law gives us a month to answer and we aim to be quicker. Mark it "privacy request" and it is routed to a human, not a queue.
The free scan is anonymous and stateless. You do not need an account, and we do not create one. What you type is used to run the scan and is then gone — we do not write your name, your city or your results to a database.
| What you give | What we do with it |
|---|---|
| Name, city, state / postcode / country | Used in memory to search data-broker sites for a listing that matches you. Not stored. We fetch the brokers' own pages directly wherever we can — and where a broker blocks us, your name and city go to a search index instead, which is section 3b and is the one place they leave our systems during a scan. |
| Employer (optional) | Used in memory to tell you apart from everyone who shares your name on the sites that sell working professionals — those records are filed under where you work, not where you live, so without it we cannot safely say a listing is yours. Not stored. Sent to the search index with your name, as above. |
| Email (optional) | Checked against a public breach index. See section 3 — this one leaves our servers, and you should know that before you type it. |
Your results are shown in your browser and never leave it, unless you choose to save the report — which creates an account (section 4). We deliberately blur addresses, phone numbers and any relative's name in the free scan: it is unauthenticated, so anyone could run it against anyone, and we are not going to become the thing we remove.
Our servers keep short-lived operational logs — request time, path, status, and the IP address the request came from — to rate-limit abuse and keep the service up. Scan inputs are not written to them. Rate-limit counters hold an IP address in memory for 15 minutes and are then discarded.
Where our hosting provider adds a country header to your request, we use it to guess your country; otherwise, or if you prefer, you choose your country with the flag. We use it purely to choose the right form fields and the right broker list. We do not run an IP-geolocation lookup and no third-party geolocation service ever sees your address. You can override the guess with the flag in the navigation; that choice is stored in your own browser, not by us.
If you type an email into the scan form, we look it up in a public breach index (currently LeakCheck) to show you which known data leaks already contain your data, and what those leaks exposed.
Your email address is sent to that index. That is a third party receiving an email address, and we are not going to bury it. Three things make us comfortable offering it, and you should judge them for yourself:
We also refuse the comfortable lie here: if the lookup fails, we tell you we couldn't check. We never report "no breaches found" when what actually happened is that we didn't get an answer.
Many of the largest brokers refuse to serve us at all. Their pages about you are still public — a search engine has already read them — so rather than give up and tell you nothing, we run one search per scan and read what is already indexed.
That search goes to a third party: Brave Search. It receives your name, your city and — if you gave one — your employer. We are not going to bury that. What we think makes it defensible, and you should judge it yourself:
If you would rather this did not happen, the scan works without it; it simply reports more brokers as blocked.
If you create an account or buy a plan, we hold:
All personal data is encrypted at rest at field level. The columns we can query are kept to an account id, a status, a date and an email address — the one you sign in with, which is how we find your account; any address on our do-not-contact lists; and the addresses on mail a broker sends us, which is how we match a reply to your removal — and everything else a person wrote or that identifies them is sealed.
To stop two different people claiming the same protected person, we store a salted one-way hash of the name and city. It cannot be reversed, and we hold no plaintext identity in that table by design: a register of people who asked to be hard to find must never itself become a directory.
| Why | Basis |
|---|---|
| Running the free scan | Your request — Art. 6(1)(b), steps at your request before a contract |
| The optional breach check | Your consent, given by typing the address — Art. 6(1)(a). Withdraw it by not using it |
| Delivering a paid plan | Performance of our contract with you — Art. 6(1)(b) |
| Corresponding with brokers | Your instruction. We act as your agent exercising your Art. 15 and Art. 17 rights |
| The authorisation record | Legitimate interests — Art. 6(1)(f): preventing this service being used against the very people it protects |
| Security, rate limits, fraud | Legitimate interests — Art. 6(1)(f) |
We do not sell, rent, licence or trade personal data. Nobody buys access to it. The only companies that see any of it are the ones that make the product function — almost all of them processors acting on our instructions, and where one is not, the row says so:
| Who | What they get, and why |
|---|---|
| Data brokers | Your name and city, in a removal request — because that is the request. Never your full address, date of birth or email; replies come back to a per-customer relay address, not your own inbox. |
| Netcup | Hosts the application and its database, on a server in Vienna, Austria. |
| Amazon Web Services (SES) | Sends our email — sign-in links and removal correspondence. |
| Stripe | Takes payment. We never see or store your card details. Stripe learns an email address and an amount, nothing about what was found about you. |
| Anthropic | Powers the assistant that helps us answer support questions and keep our broker playbooks working. It receives broker ids, statuses, dates and counts — never your words, your name or your location. That limit is enforced in our code rather than by policy: a function called mayShowToModel refuses to hand anything classified as your data to a model we do not host, and the classification is applied where the data is created rather than where it is sent, so a new field cannot quietly default to sendable. We are standing up a model on our own infrastructure so that even this stops involving a third party. |
| Brave Search | Receives one query per scan — your name, city and optional employer — so we can read what brokers who block us have already published about you (section 3b). It is never told which brokers we check, and never receives a URL, your email or anything we found. |
Only if you choose to sign in with Google. We ask for the scope openid email and nothing wider, and of what comes back we keep the email address alone. Google is a recipient here, not a processor: it is not acting on our instructions and does not handle your data on our behalf — it is answering you, on its own screen, about your own Google account. We send it nothing about you, and nothing about what was found about you. | |
| LeakCheck | Only if you use the optional breach check, and only the email address you typed (section 3). |
Where a vendor is unavoidable, each one has one job and gets one thing. Our payment processor does not learn what we found about you. The model that helps us answer your email does not learn your name. None of them is given your identity.
We rejected a third-party page-reader service that would have unlocked two extra brokers, because it would have put your name in a log we do not control. We would rather cover less and be able to say that.
Subscriptions bought inside an iPhone or Android app cannot go through Stripe — Apple and Google require their own billing. If we launch there we will use a subscription service (RevenueCat) that would learn that a subscription exists and which tier it is, and nothing about what was found about you. It is not enabled today, and this page will name it here on the day it is.
We operate from the UK and serve the UK, the EU and the United States. Some of the providers above process data in the United States, under the UK Addendum to the EU Standard Contractual Clauses or an equivalent transfer mechanism.
Removal requests necessarily go wherever the broker is — a US people-search site is in the US. That transfer is inherent in the instruction you give us, and it is the only way to get your data removed from it.
| What | How long |
|---|---|
| Free scan inputs and results | Not stored at all |
| Breach-check email | Not stored at all |
| Rate-limit counters | 15 minutes, in memory |
| Account and protected-person data | Until you delete your account, which happens the moment you press the button |
| Support conversations | 2 years from the last message |
| Broker replies and letter contents | Deleted with your account |
| Removal evidence core — an internal id, a broker, a status, a timestamp and a hash | 6 years, and it does not identify you (see below) |
That last row deserves an explanation rather than a number, because "we keep some things for six years" is exactly the sort of sentence a privacy policy uses to avoid saying anything.
Six years is the UK limitation period for a contract claim — the window in which someone could still sue us, or we could still need to prove what we did. Keeping records that named you for that long would be excessive, so we don't. When you delete your account we strip the identity out of the evidence first: your name, the broker's reply, the message ids, the letter text. What is left is an internal id, a broker's name, a status, a date and a cryptographic hash.
Nothing in that record identifies you. It exists so that if a broker re-lists you next year, or tells you nobody ever asked them to remove you, the answer is still there. That seemed more useful to you than a clean slate that can't back you up.
We set cookies for one purpose — signing you in — and for nothing else. There are two, and only one of them exists on most visits.
The session cookie is set when you sign in and keeps you signed in.
It cannot be read by scripts, it is SameSite=Lax, and it does nothing
else.
The sign-in flow cookie is set only if you press
“Continue with Google”, and it is set at that moment —
before you are signed in, because it is what makes signing in that way safe. It holds
one-off random values that let us check that the reply arriving back from Google
answers the request you just made, and nothing about you. It is httpOnly,
SameSite=Lax, scoped to /auth/google alone, lasts ten
minutes, and is deleted the moment you come back. It is strictly necessary for a
service you asked for by pressing the button, which is why it needs no consent
— and if you never press that button it is never set.
We run no advertising or tracking cookies, and no third-party analytics — no Google Analytics, no Meta pixel, no analytics company of any kind. We do count how many people reach each step of the site, on our own servers and in a way that does not identify you: what is stored is a step name, a few coarse buckets, whether you are on a phone or a computer, and an identifier that is thrown away when you close the tab and cannot be linked to the next day. No IP address, no browser fingerprint, nothing you typed. Raw records are deleted after 30 days. There is still no consent banner: unless you ask to sign in, nothing is stored on your device and nothing is read from it, and the two cookies above are strictly necessary for the sign-in you asked for. Your region choice and a saved free report are kept in your own browser's local storage, on your device, and never sent to us.
Until this date, the paragraph above began: “We run no advertising, analytics or tracking cookies, from us or from anyone else.”
That was written before we built any measurement of our own. Read strictly it remained true — “analytics” described the kind of cookie, and we set no analytics cookie. Read the way anyone actually reads a sentence, it said we ran no analytics at all, and once we built our own that was no longer accurate.
Nothing about what we collect changed on this date. What changed is that this page now describes it, including the one thing the first draft of the correction still left out: that we record whether you are on a phone or a computer. We would rather log the correction here than make it quietly.
Until this date this section described a single cookie, set only after you had signed in. That was accurate while a mailed link was the only way in. Signing in with Google needs a short-lived cookie set at the moment you press the button, so the section now describes both, when each is set, and how long each lasts.
Nothing was collected before this page said so: the button and the cookie ship together with this wording, not ahead of it.
We are moving the servers that run this service from Fly.io to a server we operate directly, hosted by Netcup in Vienna, Austria, within the EU. Netcup replaces Fly.io in the table of who else sees your data, and Cloudflare is removed from it: we do not use Cloudflare in front of the service today, so listing it was wrong. Your data is carried across using verified, encrypted backups.
This page carried a section headed “If we ever add a search index” saying such a thing was “not enabled today”, while section 3b described that same search index as something we already do. Both could not be true. The search index is live, section 3b is the accurate description, and the contradictory section has been removed rather than quietly reworded.
We would rather log a correction here than make it quietly, and the awkward part is that this one sat on a live page for a day describing live processing in two tenses at once. It was found by reading the page as a reader would, not by reading the change that introduced it.
Deletion is a button, not a request. Sign in and it is at the bottom of your dashboard. It happens immediately, cancels any subscription first, and shows you a receipt of exactly what was removed and what was kept. You do not have to ask us, wait 30 days, or explain yourself.
Under UK and EU data protection law you can also ask us to give you a copy of your data, correct it, restrict or object to how we use it, or hand it to another provider. Where we rely on consent you can withdraw it at any time. Exercising any of these costs nothing and we will not ask you why.
If you are in California, you have equivalent rights under the CCPA/CPRA, including the right to know and the right to delete. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of — but you may ask us to confirm it.
Ask through the contact form. If we get it wrong you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your own EU supervisory authority. We would much rather you told us first.
This service is for adults. We do not knowingly create accounts for under-16s. If you believe a child's data is here, write to us and we will delete it.
If we change how we handle your data in a way that matters, we will update the date at the top and email account holders before it takes effect. We will not quietly add a data-sharing arrangement and hope you don't reread this page.
None of Their Business ·
Home ·
Help ·
Contact
You pay us. That's the only way we make money. That's the point.