Legal

Privacy Policy

Deletemyleaks LLC is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and your rights over it.

1.Who we are

Deletemyleaks LLC is a DMCA takedown and content monitoring service for digital content creators. For privacy-related inquiries, contact us at [email protected].

2.What data we collect

We collect only what is necessary to run the service.

Account information

When you create an account we collect your email address, name, and creator username or handle. This is used solely to create and manage your account.

Content submitted for monitoring

Images, screenshots, or video thumbnails you upload for leak detection. These are used exclusively to identify your content across the web. They are not shared with third parties for any other purpose.

Facial recognition data (biometric)

To find leaked images of you, we may create a facial-recognition template (a mathematical 'embedding') from the reference selfies you provide and compare it against images found across the web. This is biometric data. We create it ONLY after you give explicit, opt-in consent; you can withdraw that consent at any time. We never sell biometric data or share it for any purpose other than detecting your leaks. Templates are held by our facial-recognition processor and referenced by us solely as an enrollment record, and are destroyed when you withdraw consent, delete your account (within the 30-day retention window), or when they are no longer needed to provide the service.

Payment and billing

Payments are processed by Stripe, our PCI-compliant payment processor. We store your subscription status and billing history. Your full card number is never stored on our servers - only a tokenized reference provided by Stripe.

Usage data

Standard server logs: IP address, browser type, device, pages visited, and timestamps. Used for security, debugging, and service quality. Not used for advertising.

Free-scan requests

If you run a free scan without an account, we collect the handle you enter, your email address, your IP address, and the scan report we generate for you. The “Free scans” section below explains exactly how that report is used, who can see it, and when it is deleted.

3.Free scans

When you request a free scan you authorize us to search publicly accessible sources for the handle you provide, and we generate a report: the web addresses where matching content was found, the sites and platforms involved, match counts, and blurred preview images. Because this report can reveal intimate content connected to you, we treat it as sensitive data. We use it to:

  • Show you your results and email you your report.
  • Prevent fraudulent or repeated use of free scans.
  • Carry your report into your account as your starting point if you sign up.
  • Review match quality — including false positives and misses — to test and improve our detection systems.

Who can see it

Your report is encrypted and visible only to you and authorized DeleteMyLeaks staff. It is never sold, published, or shared for advertising.

How long we keep it

Identifiable free-scan reports are kept for up to 90 days. If you create an account, your report transfers into it and account retention applies instead. You can have your report deleted sooner at any time by emailing [email protected].

After deletion

We keep only a one-way hashed record of the email and handle — which cannot be reversed to identify you — solely to prevent repeat free-scan abuse, plus de-identified match statistics (with your email and handles removed) that we do not re-associate with you and use only to measure and improve detection accuracy.

4.How we use your data

We use your data to:

  • Run the leak monitoring and DMCA takedown service you subscribed to.
  • File DMCA notices on your behalf with infringing hosts and search engines.
  • Send account and billing emails (no marketing emails without opt-in).
  • Review scan results and takedown outcomes — including false positives — to test and improve our detection systems.
  • Maintain security and prevent fraud.

5.Legal basis for processing

We process your data under the following legal bases:

Contract performance

Processing your account info and submitted content is necessary to deliver the service you signed up for (GDPR Art. 6(1)(b)).

Legitimate interest

Security logging, fraud prevention, and service improvement are necessary for the safe operation of the service (GDPR Art. 6(1)(f)).

Legal obligation

We may retain billing records where required by tax or financial regulation (GDPR Art. 6(1)(c)).

Explicit consent (biometric data)

Where we process facial-recognition (biometric) data, we rely solely on your explicit, opt-in consent (GDPR Art. 9(2)(a)), which you may withdraw at any time. We maintain a written retention-and-destruction schedule for biometric identifiers consistent with applicable law, including the Illinois Biometric Information Privacy Act (BIPA).

Consent (free scans)

Free-scan reports are processed on the basis of the consent you give when you request the scan (GDPR Art. 6(1)(a) and, to the extent a report reveals sensitive information about you, Art. 9(2)(a)). We record when you consented and the exact wording you agreed to, and you can withdraw consent at any time by asking us to delete your report.

6.Who we share your data with

We do not sell, rent, or trade your data. We share limited data with:

  • DMCA notice recipients: when filing a takedown, the recipient receives your name or username as copyright holder and the infringing URL. No other personal data is shared.
  • Stripe (our payment processor): processes your subscription payment. Governed by Stripe's own privacy policy. We do not receive or store your full card details.
  • Cloud infrastructure: hosting and email delivery providers who process data strictly on our behalf under data processing agreements.

7.Cookies

We use only essential cookies necessary to operate the service (session management, security tokens). We do not use advertising or analytics cookies. For full details see our Cookie Policy.

8.Data security

We apply industry-standard safeguards:

  • All data in transit is encrypted with TLS.
  • Data at rest is encrypted.
  • Access is restricted on a need-to-know basis.
  • Security events are logged and monitored.

9.Data retention

We retain your account data while your account is active and for 30 days after deletion, after which it is permanently removed. Identifiable free-scan reports are retained for up to 90 days unless you create an account (your report then transfers into it), you request earlier deletion, or a longer period is reasonably necessary for fraud prevention, security, or legal compliance. De-identified, aggregated scan statistics may be retained longer. Takedown records may be retained for longer periods where required to comply with legal obligations or to defend against claims.

10.Your rights

Depending on your location you may have the following rights over your personal data:

  • Access: request a copy of the data we hold about you.
  • Correction: ask us to correct inaccurate data.
  • Deletion: request deletion of your account and associated data.
  • Portability: receive your data in a machine-readable format.
  • Objection: object to certain processing based on legitimate interest.
  • Restriction: request that we limit how we use your data.

11.How to exercise your rights

Send a request to [email protected] with the subject line 'Privacy Request'. We respond within 30 days. We may ask you to verify your identity before processing the request.

12.Third-party links

Our site may link to external sites. We are not responsible for the privacy practices of those sites and recommend you review their policies.

13.Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the site. Continued use after changes constitutes acceptance.

14.Contact

For privacy questions or requests: [email protected]. We aim to respond within 5 business days.