Privacy Policy
PrivacySweepApp™ is built privacy-first. We collect as little as possible and never store the sensitive personal records you're trying to remove.
What we store
- Account: email address and authentication metadata.
- Purchase: Stripe customer ID and a record of your one-time purchase. We never see or store card numbers.
- Tracker data: broker name, public profile URL you choose to paste, status, dates, and your own non-sensitive notes.
- Generated prompts: the text you generate, so you can re-use it.
- Consent logs: which legal versions you accepted and when.
What we never store
- Social Security Numbers, government IDs, driver's license or passport numbers.
- Full date of birth or financial account numbers.
- Copies of exposed broker records.
PrivacySweepApp™ is intentionally designed so you never have to type these into the tool, and we don't display sensitive personal data back to you.
How data is protected
Data is stored in Supabase with row-level security so only your account can read or write your data. Payments are processed by Stripe.
Sharing
We do not sell your data. We use Stripe (payments) and Supabase (database/auth) as sub-processors. We do not share your data with data brokers, advertisers, or marketers.
Your rights
You can request access, export, correction, or deletion of your account data at any time by contacting support. Depending on where you live, you may also have the right to object to or restrict processing, and to complain to your local data protection authority. We do not discriminate against you for exercising these rights.
Data retention and deletion timelines
- Acknowledgement: we confirm receipt of a deletion request within 5 business days.
- Verification: we may ask you to confirm from your account email; verification typically completes within 5 business days.
- Deletion: your profile, removal cases, generated prompts, and tracker notes are deleted from our live production database within 30 days of a verified request. In-app account deletion removes this data immediately.
- Backups: encrypted backups are rotated on a rolling schedule and any residual copies are overwritten within 90 days. Backups are never used to restore deleted accounts.
- Inactive accounts: accounts with no sign-in for 24 months may be deleted after email notice.
- What we keep: minimal purchase and consent records (transaction ID, date, amount, legal version accepted) are retained for up to 7 years where required for tax, accounting, fraud-prevention, and legal-defense purposes. Stripe retains payment records under its own policy.
Deleting your PrivacySweepApp™ account does not withdraw removal requests you already sent to third parties — those are handled by each broker under their own retention rules.
Security
We use row-level security, encrypted transport (HTTPS), encryption at rest via our hosting provider, and least-privilege access. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
Children
PrivacySweepApp™ is not intended for anyone under 18, and we do not knowingly collect data from children. If we learn we have, we delete it promptly.
International transfers
Our infrastructure and processors are located in the United States. If you access PrivacySweepApp™ from elsewhere, you consent to your data being processed in the U.S.
Limitation of liability
Our liability for any claim relating to this Privacy Policy or the handling of your data is subject to the liability cap and other limitations in our Terms of Service.
Governing law
This Privacy Policy is governed by the laws of the State of Texas, United States, without regard to conflict-of-laws rules, and is subject to the jurisdiction and dispute resolution terms in our Terms of Service.
Changes
We may update this policy. Material changes will be posted here with a new "last updated" date, and continued use means you accept the update.
Contact
Questions about this policy? Reach out via the contact link in the footer.
Last updated: 8/12/2026