Last updated: July 19, 2026 · Effective: July 19, 2026
Because idsealed removes personal data for a living, holding your data responsibly is the entire business. This policy explains exactly what we collect, why, who we share it with, how we secure it, how long we keep it, and the rights you have. We never sell or share your personal information for advertising.
idsealed LLC ("idsealed," "we," "us"), a Wyoming limited liability company, operates a personal-data-removal, identity-masking, and monitoring service. We act as your authorized agent to file privacy requests. We are not a data broker, and we do not sell your data. This policy applies to our websites, apps, and services, including our mailsealed.com email-masking domain (together, the "Service"), and forms part of our Terms of Service.
We practice data minimization — we collect only what we need to deliver the Service. The categories are:
Identity & contact information — name (and prior names), email address, phone number, and postal address.
Removal-profile information — the details needed to find and remove your listings: date of birth, current and prior addresses, phone numbers and emails you want removed, and (for family plans) the same categories for enrolled household members.
Verification information — one-time codes and, where a broker, the ICO process, or our Financial Partners require it, identity-verification details (see Sections 5 and 6).
Disguise Services data — Alias and Masked Number configuration and usage metadata, and Virtual Card transaction records, as detailed in Section 6.
Account, payment & subscription data — plan, billing status, and payment method handled by our payment processor (we do not store full card numbers).
Evidence & results data — broker listings found, before/after removal proof, and exposure-scan results associated with your account.
Technical & log data — device, browser, IP address, and security logs (redacted as described in Section 13).
Support communications — messages you send us and our replies.
We collect information: (a) directly from you when you scan, sign up, or contact us; (b) from public records and data-broker/people-search sites we search on your behalf to find your listings; (c) from breach and dark-web data sources we query to assess exposure; (d) from service providers that help us operate (for example, payment, card issuing, and messaging); and (e) automatically, through the operation of the Disguise Services you use (Section 6).
We use your information only to:
search data brokers and breach sources for records that match you;
submit opt-out, deletion, and objection requests on your written mandate under UK GDPR Articles 15, 17 and 21 (and the EU GDPR for EU residents);
verify removals, capture before/after proof, and monitor for re-listings;
provide the Disguise Services (masked email, masked phone, and Virtual Cards), including legally required identity verification;
send you verification codes, your scan results, security alerts, and status updates by email and SMS, and — only if you opt in — marketing messages by email, SMS, or phone;
process payments, prevent fraud and abuse, and provide support;
comply with law and enforce our Terms.
We do not use your information for advertising, profiling for third parties, or any unrelated purpose. Where required, our legal bases are performance of our contract with you, your consent, our legitimate interests in operating and securing the Service, and compliance with legal obligations.
Some information we handle is "sensitive" under privacy laws. We treat it with extra care:
idsealed never displays or stores a full Social Security number. In exposure results, SSN exposure is shown only as an indicator or a masked last-four, and only to you after identity verification.
Virtual Card identity verification is different and is required by federal law. To issue a Virtual Card, our Financial Partners must verify your identity under bank customer-identification rules. That verification may require your full name, date of birth, address, and government identifiers (which may include your Social Security number), and is collected by and submitted to our Financial Partners through their secure verification flow for that legally required purpose. We design this flow so that idsealed does not store your full SSN on our systems.
We use sensitive information solely to provide the Service you requested — never to infer characteristics about you for marketing.
Sensitive fields are encrypted and access-restricted, and we honor your right to limit their use.
Operating the Disguise Services requires processing some data about how you use them. Plainly:
Masked email (mailsealed.com). To forward your mail, message content passes through our relay in transit. We do not read your messages; automated processing is limited to routing, spam, malware, and abuse protection. Forwarded messages are not stored — the relay forwards them in transit and retains no message bodies, and we keep Alias metadata (the alias address, forwarding target, and delivery logs) to operate the feature. We never scan relayed mail for advertising or any commercial purpose.
Masked phone numbers. We process message and call metadata (numbers, timestamps, delivery status) to relay your communications, enforce usage allowances, and prevent abuse. Relayed message content is not stored. We do not monitor the content of your communications except automated abuse and carrier-compliance filtering.
Virtual Cards. As the card program, idsealed can see card-transaction records (merchant, amount, date, status). We use them only to provide the card service, display your history to you, prevent fraud, and support disputes — never for advertising, profiling, or sale, and we do not monetize your purchase behavior in any way.
We share the minimum information necessary, and only:
with the data brokers and businesses that are the recipients of your removal/opt-out requests — limited to the identifiers needed to find and remove your records;
with our Financial Partners (our card-issuing platform and its partner bank) to provide Virtual Cards, including the identity-verification data federal law requires;
with our Telecommunications Providers to provision Masked Numbers and relay your communications;
with service providers who process data on our behalf under contract (Section 8);
to comply with law — if we receive a subpoena, court order, or other valid legal process seeking records (for example, about a Masked Number or Virtual Card), we disclose only what the process lawfully requires, we require valid legal process before disclosing user records, and where lawful and safe to do so, we will make reasonable efforts to notify you before disclosure;
to protect the rights, safety, and security of you, us, or others;
in a business transfer (merger, acquisition, or sale of assets), subject to this policy.
We use vetted providers under confidentiality and data-processing terms. Current categories include:
Payment processing & card issuing (subscription billing; Virtual Card issuing platform and partner bank);
Telecommunications (Masked Number provisioning and message/call relay; relayed calls are not recorded);
Messaging & SMS delivery (sending verification codes, scan results, and status or marketing texts you have consented to);
Email infrastructure (transactional and marketing email, and mailsealed.com relay delivery);
Cloud hosting & storage (encrypted application and database hosting);
Breach & exposure data sources (queried to assess your exposure);
Identity verification (one-time codes; card KYC via our Financial Partners);
Security, monitoring & support tooling.
A current list of providers is maintained at idsealed.com/providers and available on request. Providers are permitted to use your data only to perform services for us.
idsealed does not sell your personal information, and does not share it for cross-context behavioral advertising, as those terms are defined under the UK GDPR and similar laws. We do not trade, rent, or monetize your data — including your card-transaction history and your relayed communications. Disclosures to brokers are made solely to *remove* your data at your direction.
This section explains how we contact you and how you control it. It covers communications idsealed sends to you; messages and calls that others send to you through your Masked Number are your own communications and are covered in Section 6.
Service & transactional messages. When you give us an email address or mobile number, we use it to send messages needed to operate the Service — one-time verification codes, your free-scan results and the link to view them, removal status updates, billing and renewal notices, and security alerts. When you submit a phone number for a free scan, we send a limited, automated set of texts to verify the number and deliver your results. These messages are part of the Service you requested and continue while your account is open.
Marketing messages. Only if you opt in, we may send promotional messages about idsealed by email, SMS, and/or telephone — including, where you have given the required prior express written consent, marketing calls or texts sent with an autodialer or a prerecorded or artificial voice. Marketing consent is never a condition of using the Service, and you can withdraw it at any time.
Your controls. Message and data rates may apply and frequency varies. Reply STOP to opt out of a texting program or HELP for help, use the unsubscribe link in any marketing email, adjust your account notification settings, or email privacy@idsealed.com; we honor opt-outs made by any reasonable method. Opting out of marketing does not stop the essential account messages above. We handle email consistent with the UK Privacy and Electronic Communications Regulations (PECR) and GDPR consent rules, and register our messaging campaigns with carriers and our messaging provider as required (for example, UK sender-ID registration), screen against the UK Telephone Preference Service (TPS/CTPS) before any marketing calls.
Calls are not recorded. idsealed does not place routine service phone calls and does not record or monitor telephone calls; Masked Numbers relay your calls without recording their content. We do not share your phone number with third parties for their own marketing.
We use strictly necessary cookies to operate the site and keep you signed in, and may use limited, privacy-respecting analytics to understand and improve the Service. We do not use third-party advertising cookies. You can control cookies through your browser; some features may not work without them. Where required, we honor Global Privacy Control (GPC) signals as an opt-out of sale/share (we already do not sell or share).
We keep your profile only while you are an active Member. When you cancel or revoke your authorization, we delete your personal profile and supporting evidence within 30 days, except:
limited records we must retain to prove a privacy request was made, resolve disputes, or enforce our agreements;
financial records we are legally required to retain — identity-verification and Virtual Card transaction records are kept by us and our Financial Partners for the period federal financial regulations require (generally around five years), then deleted;
records preserved in response to a valid legal hold or legal process.
Backups are purged on a rolling schedule. Aggregated or de-identified data that cannot reasonably identify you may be retained.
Encryption in transit (TLS) and at rest, with sensitive fields protected by authenticated encryption keys held separately from the database.
Access controls & least privilege — internal access is restricted, and customer endpoints require the customer's own token.
Redacted logging, rate limiting, and abuse controls to prevent scraping or enumeration.
An identity-verification gate before any sensitive value (such as an SSN last-four) is shown, and never in email.
Encrypted backups, a written incident-response plan, and cyber and errors-and-omissions insurance.
No system is perfectly secure, but protecting your data is the core of our business and we design accordingly.
Depending on where you live, you may have rights to:
Know / access the personal information we hold about you;
Delete your personal information (subject to the legally required retention in Section 12);
Correct inaccurate information;
Port a copy of your information;
Opt out of sale/sharing and targeted advertising (we already do none);
Limit the use of sensitive personal information;
be free from discrimination for exercising your rights.
UK and EU residents have these rights under their respective laws. To exercise any right, email privacy@idsealed.com or use your account settings. We will verify your request (and may ask for information to confirm your identity), respond within the timeframe required by law, and let you appeal a denial where the law provides an appeal. We do not share personal information with third parties for their direct marketing.
You may use an authorized agent to submit a rights request on your behalf; we may require proof of the agent's authority and verification of your identity. Conversely, when *we* act as *your* agent to file removals, the recipient may require you to verify your identity directly, and we facilitate that process.
The Service is for adults. We do not knowingly collect personal information from anyone under 18 except where a parent or legal guardian enrolls a minor under a family plan and provides verifiable consent for the limited purpose of protecting that minor's data. Disguise Services (including Virtual Cards and Masked Numbers) are not available for minors. If you believe a child's data was provided without authorization, contact us and we will delete it.
This edition of the Service is intended for residents of the United Kingdom and the European Union. Our operating company is idsealed LLC (USA); where your data is transferred outside the UK/EEA we rely on the UK Extension to the EU–US Data Privacy Framework, adequacy decisions, or standard contractual clauses, and you understand your information will be processed in the U.S. under U.S. law.
We may update this policy from time to time. We will post the new version with an updated date and, for material changes, notify subscribers by email. Your continued use after the effective date constitutes acceptance.
idsealed LLC
30 N Gould St, Ste N, Sheridan, WY 82801, USA
Privacy: privacy@idsealed.com · Support: support@idsealed.com