OptOut Shelf

Stop Data Brokers From Selling Your Personal Information Online

2026.06.18
Data privacy concept showing how to stop data brokers from selling personal information and protect personal security

How many data brokers and people-search sites are quietly selling your home address to a stranger with a credit card, right now? Most people who haven't looked in a while guess one, maybe two. The honest number is usually a small crowd of them, each holding a slightly different snapshot of your name, your relatives, and where you actually live. Two years spent testing paid removal services and filing manual opt-out requests by hand taught me two things about data privacy: this problem is bigger and more automated than the marketing pages let on, and almost nobody explains what "removed" is supposed to mean once you've paid for it. Personal security in this context isn't a single fix — it's closer to pest control, something you keep doing rather than something you finish.

This breakdown focuses on mechanics, not marketing — what actually happens between filing a removal request and seeing a cleaner search result, based on paid testing across automated services and the slower manual route most people try first with data brokers directly.

Why Manual Opt-Outs Don't Stick

Roughly 500 entities are registered in the California Data Broker Registry alone, and contacting each one by hand is effectively a second job nobody signed up for. Every manual opt-out request also creates a small problem of its own: submitting a fresh, verified email address and a real name confirms to that broker that the person behind the record is active and reachable, which is the opposite of what you're trying to accomplish. It works a little like answering a telemarketer just to tell them to stop calling — the call itself proves there's a real person on the line, which is exactly the information they wanted.

One fix I tried early on was asking my own hosting provider to clear cached copies of pages that listed my address, assuming that would work the way clearing a search engine's cache might. It did nothing, because brokers keep their own independent copies once they've scraped a record — deleting a cache somewhere else doesn't touch the database they already built from it. That distinction is basically the whole argument for automation: the time trade-off between filing everything by hand and paying a service to do it is real, and it comes down to whether your hours or your dollars are the scarcer resource this month.

Laptop screen tracking data broker opt-out and removal progress for personal data privacy

What Incogni, DeleteMe, and Similar Services Actually Cover

Automated services like Incogni typically cover somewhere around 180 different brokers, which accounts for most of the people-search sites and marketing databases cluttering up a typical name search. I tested DeleteMe first and eventually moved away from it as my main tool — not because it failed outright, but because its removal reports were vaguer about what "removed" actually meant, and Incogni's dashboard made that distinction easier to track over time (mostly because it showed its work, broker by broker, instead of one vague all-clear message). Coverage between the two overlaps heavily, though neither lists identical brokers, so the practical difference shows up more in reporting clarity than in raw numbers.

Under the California Consumer Privacy Act, businesses generally get a 45-day window to respond to a removal request, and watching that timeline play out inside a dashboard is a very different experience than tracking it across a personal spreadsheet. None of this makes brokers villains exactly — they function more like a supply chain, acquiring records from public filings and other brokers, packaging them, and reselling access, which is why removal is really about cutting off a sale rather than chasing down one listing at a time.

Removal Isn't the Same as Deletion

A removal service submits opt-out requests on your behalf — it does not, and cannot, guarantee that a broker has permanently deleted your record anywhere in its systems. What it can confirm is that a listing was suppressed or pulled from that broker's public search results at the moment someone checked. Those are two different promises, and the marketing copy on most of these sites blurs the line between them on purpose, because "permanently deleted" sounds a lot better than "not currently showing up in search" (which is the boring, accurate version no one puts in a headline).

Someone I know from a privacy subreddit, Seth Calder, ran a parallel test of a competing removal service around the same stretch I was testing mine, and messaged me privately to correct a figure in my notes when our numbers didn't match up. That kind of check is worth more than it sounds — removal reports are self-reported by the service doing the removing, and a second data point from someone running their own comparison is one of the only ways to catch a dashboard that's overstating its own success.

Metallic Yubikey security key representing personal security beyond data broker removal

How Fast Do Brokers Re-List Your Information?

Certain brokers stay quiet for a long stretch once a record comes down. Others re-list far sooner, and I've written separately about why personal data keeps reappearing on broker sites if you want the mechanics of why that happens. What matters here is that re-listing speed varies enough between brokers that it's worth checking your own results broker by broker rather than trusting a single dashboard summary to catch everything.

The clearest proof that any of this actually works came from Intelius, of all places — a plain confirmation email that I forwarded straight to my partner, because it was the first tangible evidence, not just a status bar, that a record had genuinely come down. A few of these confirmations land at strange hours; one ping showed up around two in the morning from a broker I didn't even remember submitting a request to, which says more about how automated the whole back-and-forth is than any dashboard summary does.

My neighbor Jonah, a financial planner, forwards me a data-breach settlement article every couple of months and asks whether it applies to him. I ran into him at Central Market on North Lamar not long ago and had to explain, again, that a breach settlement check and a people-search listing are two unrelated problems — one is about a company getting hacked, the other is about public records getting scraped and resold, and fixing one does nothing for the other.

After the Dashboard Says 'Complete'

None of the tools discussed here touch the systems sitting right next to this problem. A password manager built around a hardware key secures the accounts themselves, not the public listings, which is a separate decision entirely, and I put together a related list of best password managers for Austin small business owners after a client's breach a while back. Account security after an actual breach — as opposed to routine broker scraping — follows its own separate checklist too. A VPN is worth having for its own reasons, but it encrypts the connection in front of you right now; it does nothing to a record a broker compiled years before you ever subscribed. Wiping a drive properly before selling or donating an old computer is its own separate skill with its own tools, and it has nothing to do with any of this either. The practical rule of thumb, after two years of watching this play out: manual opt-outs make sense for the one or two listings that bother you most, automated services earn their cost once the number climbs into the dozens, and no dashboard — free or paid — replaces the habit of periodically checking your own name, because "complete" is a word marketing pages use far more confidently than the brokers themselves ever earn.