We Read Every Competitor's Privacy Policy So You Don't Have To

Published August 13, 2026 | 12 min read

We operate Vigilant Privacy, a data removal service. We are a competitor to every company analyzed below. We have an obvious bias. We include ourselves in this analysis and hold ourselves to the same standard. Every finding below is sourced directly from each company's published privacy policy as of August 2026.

Key Takeaways

The Test We Recommend

Before trusting any company with your personal information, we recommend a simple test. Copy the company's privacy policy from their website. Paste it into any AI chatbot — ChatGPT, Claude, Gemini, or any other. Ask one question: "Should I have any concerns about my data with this company?"

We encourage everyone — including potential Vigilant Privacy subscribers — to run this test on our own privacy policy at vigilantprivacy.com/privacy.html. We designed our privacy practices to pass this test, and we believe transparency is the minimum standard for a company that asks you to trust them with your personal data.

Here is what the test reveals about each major privacy service.

Aura

Advertising Partners: Shares data with Google Ads, Meta (Facebook/Instagram), LinkedIn, Reddit, TikTok, and The Trade Desk

Their Own Words: Their policy states that certain cookie-based sharing "may be considered a sale or share under California law"

Data Breach: March 2026 — 903,100 records stolen by ShinyHunters from a marketing database inherited from Circle Media Labs (acquired 2021)

Email Inbox Access: If you activate email protection, Aura accesses your entire email inbox to scan for threats

Tracking: Uses cookies and tracking pixels across advertising partners

Data Collection: Collects device identifiers, browser types, usage patterns, location data, and demographic information including age and gender for marketing

DeleteMe

Data Retention: Retains subscriber data for 3 years after cancellation — far longer than necessary for service delivery

Marketing Use: Uses data for lead generation and direct marketing purposes

Tracking: Uses cookies for analytics and tracking

Data Processing: Processes data for "managerial decision making" — a vague category that could encompass many uses

No Breach: No known data breaches

Incogni

Corporate Sharing: Shares data with parent company Surfshark and other companies in the Surfshark group

Third-Party Sharing: Shares data with Zendesk, Mailchimp, Tune Inc (a marketing performance tracker), and Snowplow Analytics

Tracking: Uses cookies and tracking pixels

Paddle.com: Payment processing through Paddle, which has its own data collection practices

No Breach: No known data breaches

Optery

Tracking: Uses some analytics tools but is more restrained than competitors

Transparency: Provides the clearest reporting of any service with before-and-after screenshots

No Breach: No known data breaches

Data Practices: Among the better policies in the industry, though not tracking-free

Kanary

Analytics: Uses PostHog for analytics tracking

Storage: Data stored in AWS cloud infrastructure (not self-hosted)

Mobile: Tracks "minimal identifiers and location" on mobile

No Breach: No known data breaches

Data Deletion: Offers immediate data deletion upon cancellation

Cloaked

Tracking: Uses some analytics tools

Identity Masking: Provides genuine email and phone masking — they practice what they preach

No Breach: No known data breaches

Vigilant Privacy (Us)

Tracking Cookies: Zero — no cookies of any kind

Analytics: Zero — no Google Analytics, no third-party analytics

Advertising Partners: Zero — no data shared with any advertising company

Data Retention: 30 days after cancellation — all data deleted

No Breach: No data breaches

Infrastructure: Self-hosted single server with one access point (founder only)

Honesty: We are the newest service on this list with the least track record. We are transparent about that.

The Summary Table

PracticeAuraDeleteMeIncogniOpteryKanaryVP
Tracking cookiesYesYesYesSomePostHogNone
Ad partners6+Lead genSurfshark groupMinimalMinimalNone
Data retention post-cancelUnknown3 yearsUnknownUnknownImmediate30 days
BreachedYes (903K)NoNoNoNoNo
Admits data "selling"Yes (own words)NoNoNoNoNo
Self-hostedCloudCloudCloudCloudAWSYes

What This Means for You

A privacy company should have the cleanest data practices in any industry. The bar is simple: collect only what you need, share with nobody, delete promptly when asked, and track nothing. Most privacy companies fail at least one of these criteria. Some fail all of them.

The irony of a privacy company sharing your data with TikTok's advertising platform is not lost on anyone who reads the fine print. The irony of a privacy company retaining your data for three years after you cancel is equally striking. And the irony of a privacy company suffering a data breach that exposed 903,100 customer records speaks for itself.

We built Vigilant Privacy specifically to avoid these contradictions. Zero tracking, zero advertising partners, 30-day data deletion, self-hosted infrastructure. We are not perfect — we are new, small, and have limited track record. But we believe the standard for a privacy company should be higher than the standard for the companies it claims to protect you from.

A privacy company that tracks you is just another data broker with better marketing.

Test Our Privacy Policy Yourself

Copy our privacy policy at vigilantprivacy.com/privacy.html. Paste it into any AI chatbot. Ask if you should have concerns. We designed our practices to pass that test. $9.95/month.

Start Your Free 7-Day Trial

No credit card required. Cancel anytime. We never sell your data.