Skip to content

How Removals Actually Work

A plain-English explainer of what your Protection subscription actually does when we file on your behalf.

The short version

You pay. We become your authorized privacy agent under CCPA §1798.135(c).

We send a legally-valid removal request to every broker that has you in their database, attaching a signed authorization PDF (your TPA).

Brokers have up to 45 days to honor the request.

Then we re-scan to check what actually came down.

For as long as your Protection subscription is active we keep re-scanning and re-file the moment a site lists you again.

You get an email every time a broker confirms.

Step 1 — We map you

Right after checkout you complete a short profile: full name, current address, previous addresses, prior names, phone, date of birth.

This is the identity packet brokers need to match you against their databases.

Without it, removal requests often fail validation.

Step 2 — You sign the TPA

The Third-Party Authorization (TPA) is the legal document that authorizes GalaxyWarden to act on your behalf.

CCPA §1798.140(i) requires this for any agent-filed request.

Without a TPA most reputable brokers will (correctly) reject the request as unauthorized.

We generate a signed PDF the moment you type your signature, store the hash for audit purposes, and attach the PDF to every outbound broker email.

Step 3 — We file, and keep filing

Your removal scope is 632 sites across 580 companies.

One filing to a parent like PeopleConnect clears BeenVerified, Intelius, TruthFinder, InstantCheckmate and NeighborWho in one shot.

It does not all happen at once, and we will not pretend it does.

Firing that many letters in an afternoon would get our sending domain blocked and none of them would arrive.

So the sweep goes out at a steady rate, and keeps going month after month until your scope is clear.

The part we commit to in writing is the beginning of it.

Protection sends up to 100 removal requests a month for you. At least 23 go out in the first 14 days — most of what we can send in that time — or you get your money back.

The rest keeps going out at that same rate afterwards.

This is the same promise as the one on our refund & service guarantee, taken from the same place in the code — and if this page and that one ever disagree, that one controls.

Each outbound email sets Reply-To to a unique address on replies.galaxywarden.com so broker responses route to our inbound classifier, not your inbox. Every send is recorded verbatim in your dashboard’s Sent log — full body, recipient and timestamp — which is your record of what went out on your behalf. We deliberately do not copy you on each individual email: a sweep can run to as many as 100 sends in a month, and mirroring those into your inbox buries you. If you would rather receive a copy of every one, you can turn that on in Account settings.

Step 4 — Brokers respond (or don’t)

CCPA gives brokers 45 days to honor a removal request.

We do not print a removal rate.

We do not yet have one we could show you the working for.

A percentage you cannot check is worth nothing to you and would be worth a great deal to us — which is exactly why we do not publish it.

What we can tell you is what happens to every reply, because that part is ours:

  • An acknowledgement or a confirmation. Every reply routes to our inbound classifier rather than your inbox, and moves that broker’s row in your dashboard. You read the broker’s own words, verbatim, with the date.
  • A request to re-supply the TPA. Our system auto-replies with the authorization already on file, without you having to do anything.
  • A demand for identity verification only you can complete — a code sent to your phone, a confirmation link, a document upload on their site. We cannot do those for you. We forward them with instructions.
  • Nothing at all. Some brokers never reply. The 45-day window closes and the row stays at “request sent”. We file again; we cannot make them answer.
  • No route we can file on. A small number of companies will not take a filing from us in any form, or no longer have a working address to take one at. We name every one of them below, with a link to their own removal page wherever one exists, so you can do those yourself.

Step 5 — We verify (a re-scan after the compliance window)

Removal isn’t instant. Brokers have up to 45 days to action a request.

After that compliance window we run a verification re-scan and email you proof of what came down — and flag anything a broker hasn’t honored.

The verification pass is part of your subscription. There is no separate fee for it.

Brokers also re-ingest from public-record sources, so your data can re-appear weeks after a confirmed removal.

Catching those re-lists and automatically re-filing a fresh takedown is ongoing work.

It comes with an active Protection subscription ($14.99/mo or $129/yr): continuous monitoring plus automatic relist re-strikes for as long as you subscribe.

Without it, your data may slowly re-accumulate as brokers re-ingest public records.

What “confirmed” means on your dashboard

The scanning dashboard shows three states per broker:

  • Request sent · awaiting removal confirmation — we filed; the broker hasn’t replied yet (or replied with a generic acknowledgment).
  • Our team is reviewing the broker’s reply — the broker responded with a non-standard request (e.g. asking for a notarized form). We’re handling it.
  • Broker confirmed removal — the broker explicitly confirmed the data has been removed. This is the terminal positive state.

What we don’t cover

  • Federal records: court filings, federal databases, news archives. CCPA doesn’t reach these.
  • Foreign brokers without US presence: CCPA doesn’t reach them either.
  • Brokers operating exclusively under B2B exemptions: some marketing data resellers serve only business buyers and are exempt from consumer-facing CCPA requests.
  • Content you posted yourself on social media, forums, blogs, or your own websites. Removal requires you to take it down or use the platform’s own privacy tools.

Companies we cannot file for — every one of them

Our engine files by email, under the authorized-agent authorization you sign.

A small number of companies are outside that, for three different reasons.

We would rather you read the list than find out from a dashboard after you have paid.

We cannot file these for you.

Some route every request through their own portal or a form that needs a step only you can finish — a code to your phone, a CAPTCHA, an account in your name.

Some published a removal address that stopped accepting mail, and we have not found another route we can verify.

That one is our limit as much as theirs, and we say so rather than keep sending to an address that bounces.

One republishes what other sites publish, so a removal has to happen at the original source.

Each entry below says which it is, and links that company’s own removal page wherever one exists:

  • Whitepages · TruePeopleSearch · Radaris · CheckThem
    Their removal runs through a web form that needs a step only you can finish — a code to your phone, a CAPTCHA, or an account in your name. We cannot complete it for you.
  • FastPeopleSearch · USPhonebook · SearchPeopleFree · CyberBackgroundChecks · USA-People-Search · SmartBackgroundChecks · AdvancedBackgroundChecks · FastBackgroundCheck · PeopleSearchNow · Phonebooks.com
    Mississippi Tornado Alley runs ten people-search sites. Letters to the privacy desk they registered with California are delivered and ignored, and each site has to be opted out separately, so these are yours to submit.
  • FamilyTreeNow
    FamilyTreeNow no longer publishes an opt-out email address; their current notice handles every privacy right through this form.
  • Homemetry · PrivateEye · LocateFamily · Judyrecords · FreeBackgroundCheck.org · PeopleTrail · VeriPages · PeopleByName · BackgroundAlert · Arrests.org · JailBase · OpenGovUS · SignalHire · InfoFree · Near Intelligence
    The removal address they publish stopped accepting mail, and we have not found another route we can verify. We would rather say that than keep sending to an address that bounces.
  • Epsilon
    Epsilon rejects automated email submissions and requires the consumer (or authorized agent) to submit directly through their privacy portal.
  • Blackbaud
    Blackbaud does not process opt-outs by email; all CCPA/data-subject requests must be submitted directly through their Data Subject Rights Request portal.
  • Oracle Data Cloud
    Oracle Data Cloud routes all CCPA/privacy requests through their hosted privacy form rather than an email channel.
  • LiveRamp
    LiveRamp’s opt-out is a self-service web form; they do not accept CCPA requests by email.
  • Social Mention
    This one republishes what other sites publish. Removal has to happen at the original source, so filing here would achieve nothing even if they answered.
  • NeighborReport
    NeighborReport’s domain no longer resolves — there is no website, form or mailbox behind it. Nothing can be filed with this company until it reappears.
  • USA-Trace
    USATrace handles opt-outs through the form on their privacy page; their notice publishes no authorized-agent email route.
  • Skopenow
    Skopenow’s mail gateway rejects our sender, so this one goes through their redaction form. Note that Skopenow suppresses your details from search results rather than deleting them — they say they hold no database of their own — so list the exact names, addresses, phone numbers and emails you want redacted.
  • 5x5 US, LLC
    The address 5x5 registered with California no longer exists — the domain has been abandoned. The company is still trading and takes opt-outs through its own privacy portal.
  • Adttribution Inc (DBA Adttribution)
    AdTtribution publishes no working opt-out mailbox and its notice says nothing about authorized agents, so this one has to go through their form.

Nobody keeps this list by hand.

It is built from the same rule that builds your queue, so it cannot fall behind: a company that starts accepting our requests drops off it and goes back into your sweep on its own.

Two other limits belong next to it, because they are the same kind of thing. Some brokers demand a verification step only you can finish — a code to your phone, a link in your email, an ID upload on their own site. And CCPA gives every broker up to 45 days to act, after which we can file again but cannot compel anyone. We control the filing. We do not control what the company decides. That sentence is from our refund & service guarantee, and it is the whole shape of what we sell.

Audit trail you keep forever

Every email we send is logged in your dashboard under Sent log.

Each entry includes the recipient, subject, full body, reference token, and date sent.

If a broker disputes your request, or you need to escalate to a state regulator (CA Attorney General, FTC), you have the receipts.

Run my free scan Free · no account · no card

See also: refund & service guarantee — the page that controls this one · terms of service · privacy policy