Frequently Asked Questions

How data broker removal works, what Sirveil costs, and what your privacy rights are.

General

What is Sirveil?+

Sirveil is an AI-native data broker removal service that finds and removes your personal information from data broker websites, dark web databases, and people-search sites. Available on iOS (App Store), Android (Google Play), and the web, Sirveil combines automated scanning with legally-grounded removal requests to reduce your digital exposure across hundreds of data sources.

Unlike traditional removal services that rely on manual labor or basic automation, Sirveil uses artificial intelligence to scan for your data, assess takedown likelihood, and prepare legally-cited removal requests — you review each finding and initiate every takedown, staying the claimant throughout. The app monitors your exposure continuously and notifies you when your information appears on new sites or resurfaces after previous removals.

How does Sirveil work?+

Sirveil works in four stages: scan, verify, remove, and monitor. First, you provide basic identifying information (name, email, phone number, addresses). Sirveil's AI engine then scans data broker databases, people-search sites, and dark web sources for matches to your profile. When exposures are found, you confirm which records are yours, and Sirveil prepares and submits legally-grounded removal requests citing applicable state privacy laws for the takedowns you initiate. Finally, Sirveil continuously monitors for data reappearance so relisted records are one tap from the next removal.

Each removal request references the specific privacy statute in your state — whether that is the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), or one of the other state privacy laws currently in effect. Brokers are required to respond within the timeframes set by these statutes, typically 30 to 45 days.

What makes Sirveil different from other removal services?+

Sirveil differentiates in four ways: AI-powered scanning instead of manual searches, built-in dark web monitoring via DeHashed integration, FOIA request filing as an add-on service, and true native mobile apps on both iOS and Android.

The deeper difference is posture. You stay the claimant: Sirveil sweeps, prepares, tracks and re-files, but never acts without a tap from you. Every finding is shown to you with its source URL so you can check it before authorising anything, and we say plainly what we cannot do — see "Does Sirveil guarantee removal?" below. Independent testing of this category has repeatedly found that no automated service removes everything, and that careful manual opt-out remains highly effective but is difficult to sustain over time. We would rather tell you that than imply otherwise.

Is Sirveil available on mobile?+

Yes, Sirveil is available as a native app on both iOS (App Store) and Android (Google Play), as well as on the web at sirveil.ai. The mobile app is not a web wrapper — it is a full native application built with Capacitor that supports Apple In-App Purchase and Google Play Billing for subscriptions.

You can run your first scan, review exposures, track removal progress, and manage your subscription entirely from your phone. Push notifications alert you when new exposures are detected or when removal requests are confirmed.

How much does Sirveil cost?+

Sirveil costs $7.99 per month on a monthly plan or $79.99 per year when billed annually (about $6.67 per month), a promotional rate through 31 December 2026 (regular price $13.99 per month). An optional FOIA Request add-on is available for a one-time fee of $49.99 per order. There are no hidden fees, setup costs, or per-broker charges.

The full price is shown inside the app before you enter any payment details, and you can cancel in two taps. Consumer pricing is authoritative at sirveil.ai/terms.html. The separate Sirveil Exposure Verification API for businesses is priced and billed independently — different product, different rail.

Data Brokers

What is a data broker?+

A data broker is a company that collects, aggregates, and sells personal information about individuals, typically without their direct knowledge or meaningful consent. Data brokers pull information from public records, social media, purchase histories, app usage data, voter registrations, and dozens of other sources to build detailed profiles that include names, addresses, phone numbers, email addresses, family members, income estimates, and more.

The global data broker industry is valued between $290 billion and $333 billion as of 2025. Over 750 data brokers are registered in U.S. state registries (California, Oregon, Vermont, Texas, and others), though the actual number operating worldwide is estimated at 4,000 to 5,000. Buyers of this data include advertisers, insurance companies, employers, landlords, and unfortunately, scammers and identity thieves.

Note that "data broker" is also a legal term with a narrower meaning than the everyday one — see the California section below, where the difference decides what a deletion request can reach.

How many data brokers have my information?+

Most adults in the United States have their personal information listed on dozens to hundreds of data broker sites. An estimated 4,000 to 5,000 data brokers operate globally, with over 750 registered in U.S. state registries alone. If you have ever used the internet, voted, owned property, or had a phone number, your data is almost certainly in multiple broker databases.

People-search sites like Spokeo, BeenVerified, and Whitepages are just the most visible layer. Behind them are data aggregators, marketing list providers, and risk-scoring companies that trade information in bulk. California's data broker registry has flagged 33 brokers that sell U.S. consumer data to foreign entities. Running a scan with Sirveil shows you exactly where your information appears so you can take targeted action.

Can I remove my data from brokers for free?+

Yes, you can manually opt out of data broker sites for free, but the process is extremely time-consuming. Each broker has a different opt-out procedure — some require email verification, others require phone calls, and a few demand notarized identity documents. Opting out of the most common 100+ sites takes an estimated 40 to 80 hours of work.

If you are a California resident, start with DROP — it is a free state platform and one request reaches every registered California data broker. See the California section below. Beyond that, independent testing has found manual opt-out to be highly effective in the short term; the challenge is not effectiveness but sustainability. Thirty to forty percent of removed listings reappear within 90 days as brokers re-scrape public records, so maintaining your privacy manually means repeating the process every few months indefinitely. Services like Sirveil automate that ongoing work for a monthly fee.

How long does data broker removal take?+

Most data broker removal requests take 30 to 45 days to process, which is the legal response window required by state privacy laws like the CCPA and VCDPA. Some brokers process removals within 24 to 48 hours, while others take the full statutory period or longer.

Sirveil tracks the status of every removal request through its full lifecycle: submitted, acknowledged, pending verification, confirmed deleted, or escalated. If a broker does not respond within the legal timeframe, Sirveil sends follow-up requests with escalating language and state-specific legal citations. The app sends you notifications as each removal is confirmed so you can see progress in real time.

Will my data come back after removal?+

Yes, in most cases your data will reappear on broker sites after removal. Studies show that 30 to 40% of removed listings reappear within 90 days, and most listings resurface within 12 to 18 months. This happens because data brokers continuously re-scrape public records, purchase new data sets, and rebuild profiles from updated sources.

This reappearance cycle is why one-time removal is not enough and why continuous monitoring matters. It is also why the California Delete Act's forward-looking suppression obligation is such a significant change — see below. Sirveil monitors for data reappearance on an ongoing basis, and when your information resurfaces, relisted records are one tap from the next takedown — you stay in control of every request.

California: the Delete Act and DROP

What is the California Delete Act?+

The California Delete Act (SB 362, signed October 2023) requires data brokers to register annually with the California Privacy Protection Agency and required the state to build a single place where any California resident can tell every registered data broker at once to delete their personal information. That platform is DROP. The Act also imposes ongoing suppression: after processing your request, a broker must also delete information it acquires about you in the future, which is a structural answer to the industry's habit of re-listing people after a removal.

Fuller explanation: California's Delete Act and DROP, explained.

What is DROP, and can I use it?+

DROP — the Delete Request and Opt-out Platform — is California's free state-run service at privacy.ca.gov/drop. A California resident files one verified request and it reaches every data broker registered with the state. It went live on 1 January 2026.

It costs nothing, and eligibility requires California residency. Anyone charging a fee to "submit your DROP request" is charging you for a state form.

What changed on 1 August 2026, and when does the first cycle close?+

Consumers have been able to file with DROP since 1 January 2026. What changed on 1 August 2026 is the obligation on the other side: from that date, registered data brokers must access DROP and process the deletion list, and must access it at least every 45 days.

Forty-five days from 1 August places the outer edge of the first mandatory access window in mid-September 2026. Individual brokers may access more often — the statute sets a floor, not a schedule. See the first DROP cycle, explained.

I filed a DROP request and heard nothing back. Why?+

Two structural reasons, and neither is a fault on your side. First, the report goes to the regulator, not to you: brokers report processing status to the California Privacy Protection Agency, and nothing requires a broker to write to the consumer. No confirmation email is coming.

Second, the platform hashes your identifiers before brokers retrieve them, and brokers match those hashed values against their own records. If a broker holds you under a former surname, an old address, a misspelling or an email you no longer use, the hashes do not agree and nothing happens — no error is raised. So the single most useful thing you can do is go back into DROP and widen your profile with every former name, address, phone number and email you can recall.

Does DROP reach every company that has my data?+

No. The Delete Act defines a data broker as a business that sells the personal information of a consumer with whom the business does not have a direct relationship. Every company you have actually dealt with — the retailer, the airline, the app, the gym, the utility — is outside that definition, is not on the registry, and does not read DROP. Those need a direct CCPA deletion request instead.

DROP also does not reach sites that ignore the registration requirement, copies of your data already circulating in breach corpora, or public records held by government agencies — that last one is a FOIA question rather than a deletion one. The full picture: what the statute means by "delete".

Does DROP reach the credit bureaus?+

To the extent an entity is covered by the federal Fair Credit Reporting Act, it is excluded from the Delete Act's "data broker" definition. The same is true of entities covered by the Gramm-Leach-Bliley Act, the Insurance Information and Privacy Protection Act, and the health-information exemption — so consumer reporting, banking, insurance and health entities largely sit outside DROP.

Note the words "to the extent that": the exclusion attaches to the processing, not to the whole company, so a business can be a data broker for one line of business and exempt for another. The FCRA provides its own disclosure and dispute rights, which are separate from and older than the Delete Act.

Does deletion mean the broker keeps nothing about me?+

No, and it cannot. Ongoing suppression requires a broker to keep deleting your information going forward and not to sell or share new information about you — which is only possible if it retains enough to recognise you when you turn up again in a new data feed. California law also permits a business to keep a confidential record of the deletion request itself, specifically so that what was deleted is not re-sold.

So "deleted" under this statute means your data removed, and a marker for you retained. That is not a loophole; it is the price of the part that actually works.

Are data brokers going to be audited?+

Possibly — but nothing is in force yet. On 7 August 2026 the California Privacy Protection Agency board voted proposed regulations out to formal rulemaking that would require every registered broker to undergo an independent audit of its DROP deletion processing, with a first report due 1 November 2028 covering the period 1 August 2026 through 1 August 2028.

These are proposals and may change or be withdrawn. The public comment window is not open as of this writing; it begins on publication of the notice in the California Regulatory Notice Register, not on the board vote. Detail: the proposed DROP audit rules.

Does Sirveil verify that a broker actually deleted my data?+

No, and we will not claim to. What is observable from outside a company is whether a named individual's information is publicly indexed at a named website at a given moment. We report that observation in three outcomes: INDEXED, NOT INDEXED, or INDETERMINATE — and the third is common, because sites go down, block automated retrieval, or return ambiguous pages.

The limit matters and we state it plainly: index presence is not proof that a deletion request was ignored, and index absence is not proof that data was deleted. A record can sit in a database and never surface publicly. What a check gives you is a dated observation; a series of them gives you a record.

Nothing in this section is legal advice. Sirveil writes as a commercial party with a disclosed interest, not as counsel, and no attorney-client relationship is created. Statutes and dates are cited as published, and proposed regulations are identified as proposed. Confirm anything you intend to rely on with the agency and with your own counsel.

Features

What is dark web monitoring?+

Dark web monitoring is the process of scanning hidden internet marketplaces, forums, and databases for your personal information. Sirveil integrates with DeHashed to check whether your email addresses, passwords, phone numbers, or other personal data appear in known data breaches or dark web listings.

The dark web is where stolen data is bought and sold. Social Security numbers sell for $1 to $6, credit cards with CVV for $10 to $40, and medical records for $250 to $310 each. In 2025, there were 3,322 reported data breaches in the U.S. alone. Sirveil's dark web monitoring alerts you if your data appears in these compromised databases so you can take immediate protective action — changing passwords, freezing credit, or monitoring financial accounts.

What is a FOIA request and how does Sirveil help?+

A FOIA (Freedom of Information Act) request is a legal mechanism that allows any person to request records that federal government agencies hold about them. Sirveil's FOIA Request add-on (one $49.99 order covering six federal agencies: FBI, DEA, IRS, DOJ, FTC, and CFPB) prepares and electronically transmits formal FOIA requests on your behalf. DHS and CBP records are shown for transparency but require those agencies' own online portals, so they are not part of the submitted set.

Filing a FOIA request on your own requires understanding the correct agency to contact, the proper format and legal citations, and the specific records to request. Federal agencies are required to respond within 20 business days, though complex requests can take longer. Sirveil handles the preparation, formatting, legal citations, and electronic submission, and tracks the response on your behalf.

How does AI-powered scanning work?+

Sirveil's AI-powered scanning uses machine learning to match your personal information across data broker databases, people-search sites, and dark web sources. Rather than simple keyword matching, the AI assesses name-match confidence, cross-references multiple data points (addresses, phone numbers, email addresses), and scores each finding for takedown likelihood.

Each scan result is categorized with a takedown likelihood badge — from "Very Likely" for commercial data brokers to "Very Unlikely" for government or news sources. The AI also identifies which specific privacy law applies to each broker based on their jurisdiction and provides a source URL so you can verify each finding yourself before authorizing removal. This transparency is by design: you always see exactly what was found and where.

What brokers does Sirveil scan?+

Sirveil scans across major people-search sites (Spokeo, BeenVerified, Whitepages, TruePeopleSearch, FastPeopleSearch, and others), commercial data aggregators, marketing list providers, and dark web breach databases via DeHashed. The broker list is continuously updated as new sources are identified.

Each broker in Sirveil's registry includes verified privacy contact information, expected response timelines, known behavioral patterns, and escalation rules. When new U.S. state data broker registries come online — New Jersey, Delaware, Michigan, and Alaska are developing registries — Sirveil adds newly registered brokers to its scan coverage. The goal is comprehensive coverage, not inflated marketing numbers.

How often does Sirveil check for my data?+

Sirveil runs continuous monitoring for active subscribers. After your initial scan, the service monitors for new data broker listings and dark web exposures on an ongoing basis. Removal follow-up checks run daily to track the status of pending requests and escalate overdue responses.

You receive push notifications (on mobile) and email alerts whenever new exposures are detected or when a removal request is confirmed. You can also manually trigger a new scan at any time from the app. The daily follow-up job checks all pending and escalated removal requests and sends follow-up emails to brokers that have not responded within their legal response window.

Privacy & Security

Is my data safe with Sirveil?+

Yes, Sirveil uses industry-standard security practices to protect your data. All data is encrypted in transit (TLS) and at rest. The backend runs on Supabase with row-level security (RLS) policies that ensure users can only access their own data. Authentication supports email/password, Apple Sign-In, and Google Sign-In.

Sirveil collects only the personal information necessary to perform scans and submit removal requests on your behalf. Your data is never sold, shared with third parties for marketing purposes, or used to build advertising profiles. The irony of a privacy service mishandling your data is not lost on us — protecting your information is the entire point of the product.

Do I need to provide my real information?+

Yes, you need to provide your real personal information for Sirveil to effectively scan for and remove your data from broker sites. This typically includes your full name, email addresses, phone numbers, and current and past addresses. The more accurate the information you provide, the more comprehensive the scan results will be.

This is a necessary trade-off in any data removal service: to find where your data is exposed, the service needs to know what to search for. Sirveil uses this information exclusively for scanning and removal purposes. It is never sold, and it is protected by the same security infrastructure described above. If you cancel your subscription, you can request that Sirveil delete all of your stored personal data.

Can I cancel anytime?+

Yes, you can cancel your Sirveil subscription at any time with no cancellation fees or penalties. If you subscribed through Google Play, you manage your subscription through your device's subscription settings. If you subscribed through the web, you can cancel from your account settings.

When you cancel, your subscription remains active until the end of your current billing period. After that, active monitoring and new removal requests stop. Any removal requests already submitted will continue to be processed by the data brokers according to their legal obligations. You retain access to your account and historical data until the end of the billing period.

Does Sirveil guarantee removal?+

No, Sirveil does not guarantee 100% removal from all data broker sites, and any service that makes that claim is being misleading. Data removal depends on individual broker compliance with legal requirements, and some brokers are slower or less cooperative than others.

What Sirveil does is submit legally-grounded removal requests citing applicable state privacy laws on your behalf, follow up when they are overdue, and escalate when brokers fail to respond. Sirveil tracks every request through its full lifecycle and keeps you informed of the status. Most compliant brokers process removals within 30 to 45 days. For brokers that refuse or ignore requests, Sirveil provides documentation that can support formal complaints to state attorneys general.

What happens to my data if I cancel?+

When you cancel your Sirveil subscription, your personal data remains stored in your account until the end of your billing period. After your subscription expires, active scanning and removal requests stop, but your account data is retained for 90 days in case you choose to resubscribe.

After the 90-day retention period, you can request complete deletion of all your personal data from Sirveil's systems by contacting privacy@sirveil.ai. Upon receiving a deletion request, Sirveil will remove all stored personal information, scan results, removal history, and account data. This is consistent with the same privacy rights Sirveil helps you exercise with data brokers — you have the right to be forgotten by us, too.

Last updated: 6 September 2026

Still have questions?

The fastest way to see what Sirveil does is to run a scan and see where your data is exposed.

Get Sirveil

Available now on the App Store and Google Play.