We operate Vigilant Privacy, a data removal service. We are a competitor to every company analyzed below. We have an obvious bias. We include ourselves in this analysis and hold ourselves to the same standard. Every finding below is sourced directly from each company's published privacy policy as of August 2026.
Before trusting any company with your personal information, we recommend a simple test. Copy the company's privacy policy from their website. Paste it into any AI chatbot — ChatGPT, Claude, Gemini, or any other. Ask one question: "Should I have any concerns about my data with this company?"
We encourage everyone — including potential Vigilant Privacy subscribers — to run this test on our own privacy policy at vigilantprivacy.com/privacy.html. We designed our privacy practices to pass this test, and we believe transparency is the minimum standard for a company that asks you to trust them with your personal data.
Here is what the test reveals about each major privacy service.
Advertising Partners: Shares data with Google Ads, Meta (Facebook/Instagram), LinkedIn, Reddit, TikTok, and The Trade Desk
Their Own Words: Their policy states that certain cookie-based sharing "may be considered a sale or share under California law"
Data Breach: March 2026 — 903,100 records stolen by ShinyHunters from a marketing database inherited from Circle Media Labs (acquired 2021)
Email Inbox Access: If you activate email protection, Aura accesses your entire email inbox to scan for threats
Tracking: Uses cookies and tracking pixels across advertising partners
Data Collection: Collects device identifiers, browser types, usage patterns, location data, and demographic information including age and gender for marketing
Data Retention: Retains subscriber data for 3 years after cancellation — far longer than necessary for service delivery
Marketing Use: Uses data for lead generation and direct marketing purposes
Tracking: Uses cookies for analytics and tracking
Data Processing: Processes data for "managerial decision making" — a vague category that could encompass many uses
No Breach: No known data breaches
Corporate Sharing: Shares data with parent company Surfshark and other companies in the Surfshark group
Third-Party Sharing: Shares data with Zendesk, Mailchimp, Tune Inc (a marketing performance tracker), and Snowplow Analytics
Tracking: Uses cookies and tracking pixels
Paddle.com: Payment processing through Paddle, which has its own data collection practices
No Breach: No known data breaches
Tracking: Uses some analytics tools but is more restrained than competitors
Transparency: Provides the clearest reporting of any service with before-and-after screenshots
No Breach: No known data breaches
Data Practices: Among the better policies in the industry, though not tracking-free
Analytics: Uses PostHog for analytics tracking
Storage: Data stored in AWS cloud infrastructure (not self-hosted)
Mobile: Tracks "minimal identifiers and location" on mobile
No Breach: No known data breaches
Data Deletion: Offers immediate data deletion upon cancellation
Tracking: Uses some analytics tools
Identity Masking: Provides genuine email and phone masking — they practice what they preach
No Breach: No known data breaches
Tracking Cookies: Zero — no cookies of any kind
Analytics: Zero — no Google Analytics, no third-party analytics
Advertising Partners: Zero — no data shared with any advertising company
Data Retention: 30 days after cancellation — all data deleted
No Breach: No data breaches
Infrastructure: Self-hosted single server with one access point (founder only)
Honesty: We are the newest service on this list with the least track record. We are transparent about that.
| Practice | Aura | DeleteMe | Incogni | Optery | Kanary | VP |
|---|---|---|---|---|---|---|
| Tracking cookies | Yes | Yes | Yes | Some | PostHog | None |
| Ad partners | 6+ | Lead gen | Surfshark group | Minimal | Minimal | None |
| Data retention post-cancel | Unknown | 3 years | Unknown | Unknown | Immediate | 30 days |
| Breached | Yes (903K) | No | No | No | No | No |
| Admits data "selling" | Yes (own words) | No | No | No | No | No |
| Self-hosted | Cloud | Cloud | Cloud | Cloud | AWS | Yes |
A privacy company should have the cleanest data practices in any industry. The bar is simple: collect only what you need, share with nobody, delete promptly when asked, and track nothing. Most privacy companies fail at least one of these criteria. Some fail all of them.
The irony of a privacy company sharing your data with TikTok's advertising platform is not lost on anyone who reads the fine print. The irony of a privacy company retaining your data for three years after you cancel is equally striking. And the irony of a privacy company suffering a data breach that exposed 903,100 customer records speaks for itself.
We built Vigilant Privacy specifically to avoid these contradictions. Zero tracking, zero advertising partners, 30-day data deletion, self-hosted infrastructure. We are not perfect — we are new, small, and have limited track record. But we believe the standard for a privacy company should be higher than the standard for the companies it claims to protect you from.
A privacy company that tracks you is just another data broker with better marketing.
Copy our privacy policy at vigilantprivacy.com/privacy.html. Paste it into any AI chatbot. Ask if you should have concerns. We designed our practices to pass that test. $9.95/month.
Start Your Free 7-Day TrialNo credit card required. Cancel anytime. We never sell your data.