We Read Every Competitor's Privacy Policy So You Don't Have To

Published August 13, 2026 | Updated August 13, 2026 | 12 min read

Key Takeaways

Every privacy-removal service asks you to hand over your name, address, phone number, date of birth, and sometimes your Social Security number, so it can find and delete your data from other companies. That means the service itself becomes one more company holding your sensitive information — which makes its own privacy policy the single most important document it publishes.

Almost nobody reads them. So we did. Below is what seven of the best-known privacy and data-removal services say about themselves, in their own words, with a direct link to the source so you can check every quote yourself. We are a competitor in this space and we are not neutral — but every claim here is a citation, not an opinion.

Table of Contents

1. Aura 2. DeleteMe 3. Incogni 4. Kanary 5. Optery 6. Privacy Bee 7. Cloaked 8. Side-by-Side Comparison 9. Where Vigilant Privacy Stands

1. Aura

Aura is a large identity-protection company that suffered a real data breach in March 2026 (ShinyHunters gained access to roughly 900,000 records via a vishing attack on an employee account — we covered the details in a separate post). Its own privacy and cookie policies disclose the following about how it operates day to day, breach aside.

It reads your email inbox

"If you activate our email protection services and connect your email service provider inbox to Aura, we will collect the emails in your inbox and emails that you receive on an ongoing basis."
Source: aura.com/legal/privacy-policy, Section 1.1

Its cookie policy names 15+ ad and marketing partners

Aura's cookie policy lists 24 third-party vendors across its analytics, pixel-tracking, and ad-partner sections. Excluding pure opt-out registries, that's still 15+ genuine advertising and marketing vendors, including Google Ads, Google Analytics, Bing Ads, Meta, LinkedIn, TikTok, Reddit, The Trade Desk, Rokt, and ActiveCampaign.

Source: aura.com/legal/cookie-policy

Its own policy says its cookies count as a "sale" under California law

"Some of our uses of cookies and/or pixels, however, may be considered a 'sale' or 'share' under California law."
Source: aura.com/legal/privacy-policy, Section 3.1

2. DeleteMe

It keeps your data for 3 years after you cancel

"Retention period: 3 years, which is based on the applicable limitation period for enforcing legal claims and the statutory retention period for accounting documents."
Source: deleteme.com/privacy-policy

It lists "lead generation" as a reason it processes your data

"(iv) lead generation, sending newsletters and other direct marketing communications"
Source: deleteme.com/privacy-policy — listed as one of DeleteMe's own stated purposes for processing personal data. The same policy also discloses sourcing data from "marketing lead contact search engines, and other business partners."

It uses cookies

"We use cookies and similar technologies to collect and process data on our website."
Source: deleteme.com/privacy-policy

3. Incogni

Incogni is owned by Surfshark, part of the Nord Security group. Its privacy policy names its data recipients directly.

It shares your data with a long list of named third parties

"We share your personal information with the following recipients (data processors): Customer support service software provider Zendesk, Inc. ... Marketing service providers: Mailchimp ... we share with them your email address ... Analytics service providers, such as Snowplow Analytics Limited ... Payment service providers Paddle.com Market Limited, Surfshark Limited, and Surfshark Inc."
Source: incogni.com/privacy-policy. The same policy also names Amazon Web Services and Google BigQuery (infrastructure), Tune Inc. (affiliate tracking), and Cloudflare and Sentry (security) as additional recipients.

It uses cookies and pixels

"We collect Device Information using cookies and pixels. Cookies and pixels are data files that are placed on your device and often include an anonymous, unique identifier."
Source: incogni.com/privacy-policy

4. Kanary

Kanary doesn't publish its data practices under a page called "Privacy Policy" — its actual disclosure lives at a page titled "Privacy & Security."

It uses PostHog for app analytics

"We use a[n] open source product for app analytics, PostHog."
Source: kanary.com/privacy-and-security

It's hosted on AWS

"All data is stored in a separate access-controlled database within Amazon Web Services (AWS) data centers."
Source: kanary.com/privacy-and-security

Its mobile app tracks your location

"On our mobile apps, we track the minimal identifiers and location that allow the app to function at a high quality and our team to fix issues quickly."
Source: kanary.com/privacy-and-security — Kanary's own framing describes this as minimal and functionality-driven, not extensive tracking, which we think is a fair characterization of their own language.

5. Optery

It uses Google Analytics and retargeting/advertising cookies

"Essential, Functional, Performance/Analytical (including Google Analytics), and Retargeting/Advertising" cookies. "We do not support 'Do Not Track' requests at this time."
Source: optery.com/privacy-policy. Subprocessors named: Amazon Web Services, Google Workspace, and Stripe.

It discloses a CCPA-style "share" of your data via ad retargeting, while stating it doesn't sell data for money

"Optery is not a data broker and does not sell or rent Personal Data for monetary consideration" — but separately discloses it "may sell and/or share your Personal Data, subject to your right to opt-out," in connection with "delivery of retargeted digital advertising with vendors such as Google."
Source: optery.com/privacy-policy

Account data is deleted quickly

"When a consumer deletes their Optery account, all of their Optery account information is immediately deleted. Any data remaining in our secure backups is cleared within 7 days."
Source: optery.com/privacy-policy — the fastest post-cancellation deletion window of any service in this comparison.

6. Privacy Bee

Credit where it's due: Privacy Bee's own policy is genuinely strong on the specific points we checked. We're not going to pretend otherwise just because they're a competitor.

It states it uses no ad-tech trackers

"Zero ad-tech: no Google Analytics, no Meta Pixel, no third-party trackers — anywhere in our Services."
Source: privacybee.com/privacy-policy, Section 2.3.6

It states it does not sell your data

"We do not sell your personal data — full stop. We share it only with the vendors that keep the service running (hosting, email, payments) under our instructions, with your consent, or when the law genuinely requires it."
Source: privacybee.com/privacy-policy, Section 4

Data retention after cancellation: up to about a year

"We keep your data only while you use the service (plus up to a year, for legal compliance and dispute resolution). Ask us to delete it and we purge it as fast as the law allows."
Source: privacybee.com/privacy-policy, Section 9

7. Cloaked

It also reads your email inbox, with consent

Like Aura, Cloaked's own policy discloses collecting email inbox content as part of its monitoring features, when a user opts in.

Source: cloaked.com/privacy

It states it will never sell your data, but does send third-party marketing

"Cloaked will NEVER... Sell your data." Elsewhere: "we and third parties acting on our behalf may subsequently send you electronic newsletters or contact you about the Service."
Source: cloaked.com/privacy

No specific data retention period is disclosed

"We will only retain your information for as long as necessary to fulfill the purposes for which we collected it or as otherwise permitted by applicable law."
Source: cloaked.com/privacy — no specific number of days, months, or years is given anywhere in the policy.

8. Side-by-Side Comparison

ServiceCookies / TrackersNamed Ad or Analytics PartnersData Retention After CancellationCCPA "Sale/Share" Disclosed
AuraYes15+ (own cookie policy)Not specified in policyYes, explicitly
DeleteMeYesNot named individually3 yearsNot specified
IncogniYes (cookies + pixels)7+ named (Zendesk, Mailchimp, Snowplow, AWS, Tune, Cloudflare, Sentry)Not specified in policyNot specified
KanaryYes (PostHog)PostHog (analytics)Not specified in policyNot specified
OpteryYes (incl. retargeting)Google Analytics, Google Ads7 daysYes, explicitly
Privacy BeeNone disclosedNone disclosed~1 yearNot disclosed
CloakedYes (minimal disclosure)None disclosed (payment/VPN vendors only)Not specified (vague)Not disclosed
Vigilant PrivacyNoneNone30 days*Nothing to disclose — no sale or share

*Except records legally required to be kept, such as tax and chargeback records — see our Privacy Policy for the exact language.

A note on fairness: Every quote above comes directly from the company's own currently-published policy, linked so you can verify it yourself. Policies change — if any of these companies update their practices, the quotes here may no longer reflect their current policy. We checked these on August 13, 2026.

9. Where Vigilant Privacy Stands

We built Vigilant Privacy specifically to avoid the trade-offs above. Our own Privacy Policy makes the same kind of specific, checkable claims we just held everyone else to:

You don't have to take our word for it any more than you should take a competitor's marketing page at face value — read our actual privacy policy the same way we read everyone else's.

See What We Actually Do

Read our privacy policy, then start a free 7-day trial. No credit card required.

Start Your Free 7-Day Trial

No credit card required. Cancel anytime. We never sell your data.