LEGAL AGREEMENT // PRIVACY POLICY

A Privacy Policy for a Privacy Company.

Last Updated: July 21, 2026

Most privacy policies are written by lawyers trying to find loopholes to exploit your data. Ours is written to explain exactly how we protect it.

OptOutScout exists for one reason: to help you reclaim your digital footprint. It would fundamentally violate our core mission to turn around and monetize your information. We have engineered our entire infrastructure around the principle of "Security through Subtraction"—meaning if we don't absolutely need a piece of data to do our job, we refuse to collect it.

The following document outlines exactly how we ("OptOutScout") handle the information you ("the user") entrust to us. If you need to contact us regarding any privacy-related matters, you can reach us directly at privacy@optoutscout.com.


1. Jurisdiction & Audience

OptOutScout is built exclusively for current and recent residents of the United States. The data brokers and people-search engines our systems target are primarily focused on aggregated US public records. Because of this, our architecture is not designed to successfully locate or remove records for residents of other countries.

2. Data Minimization Architecture

We only ask for the precise variables required to successfully match and verify your profile within a data broker's system. To execute removals on your behalf, we typically need:

  • Your full legal name (and any previously used aliases)
  • Current and historical residential addresses
  • Email addresses and phone numbers associated with you
  • Your date of birth
  • Names of immediate relatives (frequently required by brokers to distinguish you from someone with the exact same name)

The Hard Line: We will never require you to provide a Social Security Number (SSN), upload a photograph of your Driver's License, or sign a formalized Power of Attorney. If a specific broker aggressively demands a government ID to process a removal, we will securely route that broker's link to you so you can handle that specific interaction on your own local machine.

3. Cookies, Local Storage, & Logging

We don't follow you around the internet, and we don't use invasive analytics pixels. Here is exactly what we store on your device and our servers:

  • Signup Progress (Local Storage): During the onboarding process, we offer an optional checkbox to "save your progress." If you enable this, the information you enter is temporarily saved directly in your own browser's local storage. We do not beam incomplete form data back to our servers. It stays on your device until you are ready to submit it or clear your browser data.
  • Authentication & "Remember Me": We use secure, strictly necessary session cookies to keep you logged into your dashboard. If you select the "Remember Me" option during login, we place a secure, persistent cookie or local token in your browser so you don't have to re-authenticate as frequently.
  • Security Logs: To defend against DDoS attacks and fraudulent abuse of our platform, our servers log incoming IP addresses and basic browser metadata. These security logs are automatically purged after 30 days.
  • Disaster Recovery: We maintain encrypted database backups to ensure we can restore the service in the event of a catastrophic server failure. These rolling backups are kept for a maximum of 7 days before being permanently overwritten.

4. The Paradox of Data Sharing

Your data is never monetized. We do not sell, rent, swap, or trade your personal information to advertising networks, third-party marketers, or data enrichment platforms. Our financial survival is tied 100% to your subscription payments.

However, there is an inherent paradox in our industry: to remove your data from a broker, we must send your data to that broker. We will transmit your information to third-party data brokers solely for the purpose of locating your exposed records and issuing legally binding opt-out requests.

Sponsor-Provided Access Accounts: If your access tier or monthly subscription data plan is funded through an employer benefit program or corporate compliance sponsorship framework, we may securely share enrollment dates or contact status credentials with that organizing sponsor solely for aggregated corporate billing tracking.

Critical Disclaimer Once we submit an opt-out request to a third-party data broker, the way they handle the data we transmitted is governed by their privacy policies, not ours. While we only send the minimum amount of data required to verify your identity, please do not provide OptOutScout with any piece of personal information that you are entirely unwilling to have submitted to a broker's compliance department.

5. Internal Access & Offshore Policies

Our core team is based entirely in Boise, Idaho. We do not outsource "complex" or "manual" opt-out requests to offshore contractors or third-party virtual assistants. Only highly vetted, key members of our U.S.-based engineering team have the access required to interact with user variables when a manual removal intervention is necessary.

Furthermore, by utilizing passwordless Magic Links for authentication, we completely remove the risk of hackers stealing your password from our servers or compromising your account via credential stuffing.

6. Data Sovereignty & Automated Retention Lifecycle

You maintain full sovereignty over your data footprint within our ecosystem. Regardless of your geographic state of residency, we universally respect the core rights established under modern privacy frameworks like the CCPA and CPRA.

To perform continuous monitoring and automated removal sweeps, your identity parameters must remain actively compiled while your account status is current.

Automated Purge Protocol: If you cancel your subscription or if your recurring renewal payment permanently fails, our server lifecycle loops automatically initiate a hard delete sequence. All identity parameters, contact maps, historical addresses, and family configurations are completely and permanently wiped from our production database environments within 7 days of subscription termination.

If you require an immediate manual data purge prior to this automatic 7-day window clearing, you may submit a formal request to our privacy desk at privacy@optoutscout.com and your information will be wiped immediately.

Note: Basic Stripe transactional metadata and tax history must be retained indefinitely to satisfy accounting compliance and federal audit requirements.

7. Enterprise Infrastructure Partners

OptOutScout utilizes world-class enterprise infrastructure to maintain security. The following partners process data on our behalf:

  • Enterprise Google Cloud: Our application layer and isolated databases are hosted on Google Cloud infrastructure located strictly within the United States. We utilize their commercial enterprise environments, meaning your data is encrypted at rest and in transit, and Google is strictly prohibited from scanning our databases for advertising profiles.
  • Stripe: All billing and subscription management is handled by Stripe. We do not collect, process, or store your credit card numbers or banking details on OptOutScout servers.
  • Transactional Email: We use secure third-party email routing to deliver your login Magic Links and critical account alerts. We actively disable invasive open-rate and click-tracking pixels on our system emails.

We built OptOutScout to be the tool we wanted to use to protect our own families. If you have any further questions about our engineering architecture or privacy practices, our team is ready to answer them at privacy@optoutscout.com.

OptOutScout LLC Boise, Idaho Built for Digital Sovereignty