Privacy Policy
There is a contradiction at the center of this service, and it should be the first thing you read rather than something you discover later: to get a data broker to remove your records, we have to tell that broker who you are. We cannot ask them to delete you without identifying you. Everything below is an attempt to be precise about what that means, what we hold, and who else sees it.
Who this is about
Vanishpoint is a service operated by Moonhead LLC, a California limited liability company. It submits privacy requests to data brokers and people-search sites on your behalf, acting as your authorized agent. Where this policy says "we" or "us", it means Moonhead LLC. This policy covers vanishpoint.co and the service behind it, and it applies to you whether you are a customer, someone on the waitlist, or just reading the site.
It does not cover the data brokers themselves. Once a broker receives a request from us, that broker's own privacy practices govern what it does with the information — we can compel a response through the law, not through this document.
What we collect, and why each piece exists
We collect the following, and nothing else. Each item is here because a specific part of the service does not work without it.
- Account details — your email address and name. Used to sign you in and to reach you about your own requests. Authentication is handled by Clerk; we store the resulting user ID, email, and name.
- Matching information — your full name and any name variants, date of birth, phone numbers, current address, previous addresses, and previously used email addresses. This is the set brokers match on. A broker that cannot match you will not remove you, which is why previous addresses matter more than they might seem to.
- Consent and eligibility records — the version of the authorization you agreed to, the date and time, the method, and the IP address the agreement came from; plus a record that you confirmed you are 18 or older, and the IP address of that confirmation. These exist so that our authority to act on your behalf can be evidenced if a broker challenges it.
- Billing details — a Stripe customer ID, a subscription ID, and your plan status. Your card number never reaches our servers: payment is taken on Stripe's own hosted checkout, and we receive back identifiers and a status, not payment credentials.
- Request records and evidence — for each broker request, what we sent, when, where it went, and what came back, including page captures and broker reply emails. This is the product's audit trail: it is how you can see that a request was actually made rather than take our word for it.
- Waitlist signups — an email address and the date, if you joined the waitlist before signing up.
- Support correspondence — if you email us, we keep the email.
What we deliberately do not collect
This list is as much a part of the policy as the one above, and we intend to keep it accurate rather than convenient.
- No analytics, no tracking pixels, no advertising SDKs, no third-party trackers of any kind. The site does not measure you. This is not a setting you have to find and switch off; the code that would do it does not exist.
- No Social Security number, driver's licence number, passport number, or government ID. Some brokers ask for ID to verify a request. We do not collect it and do not pass it on.
- No financial account numbers, and no card details.
- No browsing history, no location tracking, no device fingerprinting, no data purchased about you from anyone else.
- No biometric data, and no data about your health, religion, politics, or sexual orientation.
What we use it for
We use your information for four purposes, and we do not use it for anything else: to submit and re-submit privacy requests on your behalf; to verify your identity and prevent fraud; to run your account and subscription; and to show you what has happened with your requests.
This is the same limit that 11 CCR § 7063(d) places on authorized agents. We commit to it here as well, so that it binds us contractually and not only as a matter of regulation.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act. We have never done so and the service has no mechanism for it.
Who receives your information
Data brokers and people-search sites, first and most importantly. To remove your record, we submit your matching information — name, date of birth, addresses, contact details — to the broker holding it, through whatever channel that broker requires: a web form, an email, an API, or postal mail. This is the service working as intended, and it is disclosure of your personal information to a third party. There is no version of this product where that does not happen.
Beyond that, a small number of vendors process data on our behalf in order for the service to function. Each is bound to use it only to provide their service to us:
- Clerk — authentication. Holds your email, name, and login credentials.
- Stripe — payments and subscriptions. Holds your billing and card details directly; we never see the card.
- Postmark — email delivery and receipt, both for messages to you and for correspondence with brokers. Broker correspondence contains your matching information.
- Vercel — website hosting, and private storage for request evidence.
- Railway — our database and the worker process that submits requests.
- Temporal Cloud — schedules and tracks each request through its lifecycle, including re-submissions.
- Bright Data — network proxying for broker submissions, so that requests reach brokers reliably. Broker form traffic passes through it.
- 2Captcha — solves the CAPTCHA challenges some broker sites put in front of their opt-out forms. It receives the challenge itself, not your profile.
- Anthropic — reads incoming broker reply emails to classify whether a reply confirms an actual removal or merely acknowledges receipt. Those emails can contain your name and address. Content sent through the API is not used to train models.
We will also disclose information if the law requires it — a valid subpoena, court order, or legal process. If that happens we will tell you, unless we are legally prohibited from doing so.
If Moonhead LLC is ever acquired or merged, your information would transfer as part of that business. We would give you notice before it did, and the acquirer would be bound by this policy until you agreed to a different one.
How we protect it
The information brokers match on — your name and variants, date of birth, phone numbers, current and past addresses, and email history — is encrypted at rest with AES-256-GCM before it is written to our database, under a key held outside the database itself. A leaked database URL, a stolen backup, or unaudited database-console access would yield ciphertext rather than a ready-made profile of you.
Evidence records — the exact bytes we sent a broker and what came back — are stored privately, addressed by a hash of their own contents, and reachable only through short-lived signed links minted at the moment something needs to display them. A leaked dashboard link does not become a permanent key to the underlying data.
Here is the honest limit of that protection: the service has to decrypt this information in memory to type it into a broker's form. Encryption at rest defends against a stolen copy of the database. It cannot defend against a compromise of the running application, and we would rather say so than imply a guarantee we cannot make.
How long we keep it, and what deletion actually does
We keep your information while your account is open, and for as long as we are submitting requests on your behalf. Removals do not stay done — brokers rebuild their files from public records — so an active subscription means an active profile to re-submit from.
When your subscription ends, we stop submitting immediately, and different things then have different lifespans. Nothing in the law requires us to keep any of this, so these periods are ours to justify:
- Your matching information — name and variants, date of birth, phone numbers, and address history — is deleted 90 days after your subscription ends. This is the most sensitive thing we hold and the first to go. The 90 days exist only so that resubscribing after a change of mind does not mean rebuilding your profile from scratch; nothing else needs it, and after that it serves no purpose we are permitted to act on.
- If you set up an account but never subscribed, the same 90 days apply, counted from when you finished setup. You gave us the most sensitive information we hold and got no service in return, so there is even less reason to keep it.
- Your request records and evidence — what we sent each broker and what came back — are kept for 12 months after your subscription ends, then deleted. These are the proof that a request was made, which is what a complaint to a regulator is built on, and they are worth more to you than to us. Every record is viewable from your dashboard, and you can ask us for a copy of all of it at any time.
- Your consent records — which authorization you agreed to, when, and from what IP address — are kept as evidence that we were authorised to act for you at the time we acted. A record of authority that expires before the acts it authorises can be questioned is not evidence of anything.
- Billing records are kept as long as tax and accounting law requires, which is longer than any of the above and is not our choice.
You do not have to wait for any of it. Deleting your account deletes your profile and matching information, your request history, and your stored evidence records straight away, stops all scheduled re-submissions, removes your login, and cancels your subscription.
One thing no deletion reaches, and it is worth being clear about: requests already submitted to brokers are not withdrawn. We have no way to un-ask a broker to stop selling your data, and you would not want us to. Deleting your account removes our copy of the record, not the request itself.
Your rights
You have the right to know what personal information we hold about you, to get a copy of it, to correct it, and to have it deleted. You have the right not to be discriminated against for exercising any of these — the service works the same either way, and the price does not change.
Depending on where you live, you may also have the right to appeal a refusal. If we deny a request, we will tell you why and how to appeal it.
Most of this you can do without asking us: your profile is editable in your dashboard, and deleting your account does what the section above describes. For anything else, email hello@vanishpoint.co. We will verify that the request is really from you before acting on it — a deletion request we cannot authenticate is a security hole, not a privacy feature — and we will respond within 45 days.
California residents
The categories of personal information we collect, in the CCPA's own terms, are identifiers, personal information under Civil Code § 1798.80, commercial information, and internet activity limited to the consent records described above. The categories we disclose for a business purpose are identifiers and § 1798.80 information — disclosed to the brokers and vendors named above. We do not sell or share personal information, including that of anyone under 16.
On DROP, California's Delete Request and Opt-out Platform: we cannot file it for you. The state verifies identity through its own gateway, and no agent can complete that on a consumer's behalf. We show you how to file it yourself and track the deadline afterwards. Your DROP identifier, if you give it to us, is stored so we can show it back to you.
Cookies
The site sets a session cookie so that you stay signed in, and before public launch a cookie that grants preview access to the site. That is the complete list. There are no advertising cookies, no analytics cookies, and consequently no cookie banner asking you to accept anything.
Children
Vanishpoint is for adults. You confirm you are 18 or older during setup, and we do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it. If you believe a minor has given us information, email hello@vanishpoint.co and we will act on it.
Where your data is processed
Vanishpoint is a United States service, built around United States state privacy laws, and your information is processed in the United States. If you are reading this from elsewhere, be aware that United States law will govern the handling of anything you send us.
Changes to this policy
If we change this policy we will publish a new version with a new effective date, and previous versions stay published so you can see what changed. If a change materially affects how we handle information we already hold about you, we will email you before it takes effect rather than rely on you noticing.
Contact
hello@vanishpoint.co, for any question about this policy or to exercise any right described in it. If something here is unclear or reads as evasive, that is worth telling us — this document is meant to be checkable against what the service actually does.
By post: Moonhead LLC, PO Box 2987, Vista, CA 92084. Email reaches us faster, and a privacy request sent by post takes longer to verify simply because there is no quick way to confirm it came from you.