Legal
Privacy Policy
Effective date: July 22, 2026
1.The short version
We collect the minimum needed to find and reduce your exposure, we encrypt the sensitive parts, we never sell your personal information, and we delete it when you ask. This policy explains each of those claims in detail.
2.What we collect and why
| Category | Examples | Purpose | Retention |
|---|---|---|---|
| Account data | Email address, verification status | Run scans you request, deliver results, secure your account | Life of account; purged within 30 days of deletion request |
| Identity details (optional) | First and last name, city, state | Search people-search sites and submit removal requests as your agent | Life of subscription; encrypted at the column level (AES-256-GCM); purged within 30 days of deletion request |
| Scan findings | Breaches your email appears in, broker listings matched to your identity | Show your exposure report, drive removals and monitoring | Life of account; purged with account deletion |
| Billing data | Subscription status, transaction records (card details stay with our payment processor) | Process payment, honor the money-back guarantee | Retained as required by tax and accounting law |
| Consent records | Auto-renewal consent text, version, timestamp, IP; signed authorization letters | Prove authorization and renewal consent | At least 3 years, per legal requirements |
3.How we use your information
We use your information solely to operate the service: verifying you own the email you scan, checking it against publicly searchable breach catalogs, searching people-search sites for listings that match you, submitting removal requests as your authorized agent, showing you results, processing payment, and sending service email. We send marketing email only with consent, and every marketing message includes a working unsubscribe.
4.We do not sell or share your personal information
Erasery does not sell your personal information and does not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act. We disclose personal information only to service providers who process it on our instructions — payment processing, email delivery, infrastructure hosting, and the removal-fulfillment vendor that transmits opt-out requests to brokers — under contracts that prohibit any other use.
5.Security
Data in transit is protected with TLS; databases are encrypted at rest. Identity fields used for removals (name, city) and signed authorization documents are additionally encrypted at the application layer with AES-256-GCM before storage. Details on our Security page.
6.Your rights (including CCPA rights)
Depending on your state, you may have the right to know what personal information we hold about you, to correct it, to delete it, to obtain a portable copy, and to be free from discrimination for exercising those rights. California residents have these rights under the CCPA. To exercise any of them, email support@erasery.com or use your account settings; we verify requests and respond within the statutory window. Account deletion purges personal information within 30 days, except billing and consent records we are legally required to keep. California residents can also use the state’s free DROP service (privacy.ca.gov) to request deletion from registered data brokers directly.
7.Children
Erasery is for adults. The service is not directed to children under 16, and we do not knowingly collect their information; if you believe a child has provided us data, contact us and we will delete it.
8.Changes and contact
If we change this policy in a material way, we will notify you by email or in-product notice before the change takes effect. Questions or requests: [Entity name], support@erasery.com, [Postal address placeholder].