We Read Every Competitor's Privacy Policy So You Don't Have To
Published August 13, 2026 | Updated August 13, 2026 | 12 min read
Key Takeaways
- Every claim below is a direct quote from the company's own current privacy policy, with a link to the exact page
- Aura's own cookie policy names 15+ real ad and marketing partners, and its privacy policy says its own cookies "may be considered a 'sale' or 'share' under California law"
- DeleteMe's own policy states a 3-year data retention period after cancellation and lists "lead generation" as a stated purpose for processing your data
- Incogni's own policy names Zendesk, Mailchimp, Snowplow, AWS, Cloudflare, and its Surfshark/Nord Security corporate family as data recipients
- Not every competitor is bad on every count — Privacy Bee's own policy states zero ad-tech trackers and no data selling, and we say so honestly below
- Vigilant Privacy uses none of the above: zero cookies, zero analytics, zero ad partners, self-hosted infrastructure, 30-day deletion
Every privacy-removal service asks you to hand over your name, address, phone number, date of birth, and sometimes your Social Security number, so it can find and delete your data from other companies. That means the service itself becomes one more company holding your sensitive information — which makes its own privacy policy the single most important document it publishes.
Almost nobody reads them. So we did. Below is what seven of the best-known privacy and data-removal services say about themselves, in their own words, with a direct link to the source so you can check every quote yourself. We are a competitor in this space and we are not neutral — but every claim here is a citation, not an opinion.
1. Aura
Aura is a large identity-protection company that suffered a real data breach in March 2026 (ShinyHunters gained access to roughly 900,000 records via a vishing attack on an employee account — we covered the details in a separate post). Its own privacy and cookie policies disclose the following about how it operates day to day, breach aside.
It reads your email inbox
"If you activate our email protection services and connect your email service provider inbox to Aura, we will collect the emails in your inbox and emails that you receive on an ongoing basis."
Its cookie policy names 15+ ad and marketing partners
Aura's cookie policy lists 24 third-party vendors across its analytics, pixel-tracking, and ad-partner sections. Excluding pure opt-out registries, that's still 15+ genuine advertising and marketing vendors, including Google Ads, Google Analytics, Bing Ads, Meta, LinkedIn, TikTok, Reddit, The Trade Desk, Rokt, and ActiveCampaign.
Its own policy says its cookies count as a "sale" under California law
"Some of our uses of cookies and/or pixels, however, may be considered a 'sale' or 'share' under California law."
2. DeleteMe
It keeps your data for 3 years after you cancel
"Retention period: 3 years, which is based on the applicable limitation period for enforcing legal claims and the statutory retention period for accounting documents."
It lists "lead generation" as a reason it processes your data
"(iv) lead generation, sending newsletters and other direct marketing communications"
Source:
deleteme.com/privacy-policy — listed as one of DeleteMe's own stated purposes for processing personal data. The same policy also discloses sourcing data from "marketing lead contact search engines, and other business partners."
It uses cookies
"We use cookies and similar technologies to collect and process data on our website."
3. Incogni
Incogni is owned by Surfshark, part of the Nord Security group. Its privacy policy names its data recipients directly.
It shares your data with a long list of named third parties
"We share your personal information with the following recipients (data processors): Customer support service software provider Zendesk, Inc. ... Marketing service providers: Mailchimp ... we share with them your email address ... Analytics service providers, such as Snowplow Analytics Limited ... Payment service providers Paddle.com Market Limited, Surfshark Limited, and Surfshark Inc."
Source:
incogni.com/privacy-policy. The same policy also names Amazon Web Services and Google BigQuery (infrastructure), Tune Inc. (affiliate tracking), and Cloudflare and Sentry (security) as additional recipients.
It uses cookies and pixels
"We collect Device Information using cookies and pixels. Cookies and pixels are data files that are placed on your device and often include an anonymous, unique identifier."
4. Kanary
Kanary doesn't publish its data practices under a page called "Privacy Policy" — its actual disclosure lives at a page titled "Privacy & Security."
It uses PostHog for app analytics
"We use a[n] open source product for app analytics, PostHog."
It's hosted on AWS
"All data is stored in a separate access-controlled database within Amazon Web Services (AWS) data centers."
Its mobile app tracks your location
"On our mobile apps, we track the minimal identifiers and location that allow the app to function at a high quality and our team to fix issues quickly."
Source:
kanary.com/privacy-and-security — Kanary's own framing describes this as minimal and functionality-driven, not extensive tracking, which we think is a fair characterization of their own language.
5. Optery
It uses Google Analytics and retargeting/advertising cookies
"Essential, Functional, Performance/Analytical (including Google Analytics), and Retargeting/Advertising" cookies. "We do not support 'Do Not Track' requests at this time."
It discloses a CCPA-style "share" of your data via ad retargeting, while stating it doesn't sell data for money
"Optery is not a data broker and does not sell or rent Personal Data for monetary consideration" — but separately discloses it "may sell and/or share your Personal Data, subject to your right to opt-out," in connection with "delivery of retargeted digital advertising with vendors such as Google."
Account data is deleted quickly
"When a consumer deletes their Optery account, all of their Optery account information is immediately deleted. Any data remaining in our secure backups is cleared within 7 days."
6. Privacy Bee
Credit where it's due: Privacy Bee's own policy is genuinely strong on the specific points we checked. We're not going to pretend otherwise just because they're a competitor.
It states it uses no ad-tech trackers
"Zero ad-tech: no Google Analytics, no Meta Pixel, no third-party trackers — anywhere in our Services."
It states it does not sell your data
"We do not sell your personal data — full stop. We share it only with the vendors that keep the service running (hosting, email, payments) under our instructions, with your consent, or when the law genuinely requires it."
Data retention after cancellation: up to about a year
"We keep your data only while you use the service (plus up to a year, for legal compliance and dispute resolution). Ask us to delete it and we purge it as fast as the law allows."
7. Cloaked
It also reads your email inbox, with consent
Like Aura, Cloaked's own policy discloses collecting email inbox content as part of its monitoring features, when a user opts in.
It states it will never sell your data, but does send third-party marketing
"Cloaked will NEVER... Sell your data." Elsewhere: "we and third parties acting on our behalf may subsequently send you electronic newsletters or contact you about the Service."
No specific data retention period is disclosed
"We will only retain your information for as long as necessary to fulfill the purposes for which we collected it or as otherwise permitted by applicable law."
Source:
cloaked.com/privacy — no specific number of days, months, or years is given anywhere in the policy.
8. Side-by-Side Comparison
| Service | Cookies / Trackers | Named Ad or Analytics Partners | Data Retention After Cancellation | CCPA "Sale/Share" Disclosed |
| Aura | Yes | 15+ (own cookie policy) | Not specified in policy | Yes, explicitly |
| DeleteMe | Yes | Not named individually | 3 years | Not specified |
| Incogni | Yes (cookies + pixels) | 7+ named (Zendesk, Mailchimp, Snowplow, AWS, Tune, Cloudflare, Sentry) | Not specified in policy | Not specified |
| Kanary | Yes (PostHog) | PostHog (analytics) | Not specified in policy | Not specified |
| Optery | Yes (incl. retargeting) | Google Analytics, Google Ads | 7 days | Yes, explicitly |
| Privacy Bee | None disclosed | None disclosed | ~1 year | Not disclosed |
| Cloaked | Yes (minimal disclosure) | None disclosed (payment/VPN vendors only) | Not specified (vague) | Not disclosed |
| Vigilant Privacy | None | None | 30 days* | Nothing to disclose — no sale or share |
*Except records legally required to be kept, such as tax and chargeback records — see our Privacy Policy for the exact language.
A note on fairness: Every quote above comes directly from the company's own currently-published policy, linked so you can verify it yourself. Policies change — if any of these companies update their practices, the quotes here may no longer reflect their current policy. We checked these on August 13, 2026.
9. Where Vigilant Privacy Stands
We built Vigilant Privacy specifically to avoid the trade-offs above. Our own Privacy Policy makes the same kind of specific, checkable claims we just held everyone else to:
- Zero tracking cookies on our website or app
- Zero third-party analytics — no Google Analytics, no Meta Pixel, nothing
- Zero advertising partners — there is no cookie policy naming ad vendors, because there are none
- Self-hosted infrastructure, not a rented cloud stack running someone else's telemetry
- 30-day deletion after cancellation, with the only exceptions being records the law actually requires us to keep (tax records, chargeback defense, compliance audits) for the minimum time required — and never used for anything else
- We never sell or share your data, so there is no CCPA "sale or share" disclosure to write, because the underlying activity doesn't happen
You don't have to take our word for it any more than you should take a competitor's marketing page at face value — read our actual privacy policy the same way we read everyone else's.
See What We Actually Do
Read our privacy policy, then start a free 7-day trial. No credit card required.
Start Your Free 7-Day Trial
No credit card required. Cancel anytime. We never sell your data.