How it works
Six steps. Two of them are yours and take about two minutes in total.
- 1
Prove the address is yours
A six-digit code, no password, no account.- This is also why Cartograph cannot be used against anyone. A scan only ever runs for an address that has entered its own code.
- 2
We look
About 3 minutes.- 503 data brokers and profile sites.
- Breach databases, including which fields leaked, not just that you were in one.
- Infostealer logs, where credentials taken by malware end up.
- And the AI models themselves: we ask what they say about you and record every source they cite.
- 3
You decide what goes
Ninety seconds.- Your home address, phone number, family and anything about health, money or legal matters get asked about one at a time.
- Your job title and city usually do not. Those default to fine and you can change any of them.
- 4
We send the requests
Same day.- If you live in California, we file through the state platform first. It is free and legally stronger than anything a company can send.
- In the EU or UK, an Article 17 erasure request with an Article 21 objection behind it.
- In other US states, we cite your state's own statute by name. Not vague talk about privacy law.
- Where a company supports the Data Rights Protocol, we submit machine to machine and get a machine-readable answer back.
- 5
We work the replies
For as long as it takes.- Most opt-outs reply with a link that must be clicked. We hold a dedicated mailbox for your case and click it.
- A reply saying “we received your request” is not a removal, and we do not record it as one.
- Anything past its legal deadline is flagged for escalation to the regulator.
- 6
We prove it changed
Every quarter.- The same questions, the same models, the same country. Then the difference.
- We only claim a removal when the page is actually gone or the company confirmed it. Models reword themselves constantly, so a single before-and-after proves nothing and we will not pretend otherwise.
When removal is the wrong tool
Sometimes the problem is not that something private is public. It is that something public is wrong. A model calls you the head of a company you left years ago, because it read an old profile page.
Deleting that page does not make the model correct. It makes it silent, or sends it to the next stale page saying the same thing. So subscribers can publish a short profile stating what is actually true, built to be read by the crawlers that feed the models.
It says plainly, on the page and in its machine-readable data, that you wrote it about yourself and that we verified only your email address. We are not in the business of making unverified claims look official.