How Removals Actually Work
A plain-English explainer of what your Protection subscription actually does when we file on your behalf.
The short version
You pay. We become your authorized privacy agent under CCPA §1798.135(c).
We send a legally-valid removal request to every broker that has you in their database, attaching a signed authorization PDF (your TPA).
Brokers have up to 45 days to honor the request.
Then we re-scan to check what actually came down.
For as long as your Protection subscription is active we keep re-scanning and re-file the moment a site lists you again.
You get an email every time a broker confirms.
Step 1 — We map you
Right after checkout you complete a short profile: full name, current address, previous addresses, prior names, phone, date of birth.
This is the identity packet brokers need to match you against their databases.
Without it, removal requests often fail validation.
Step 2 — You sign the TPA
The Third-Party Authorization (TPA) is the legal document that authorizes GalaxyWarden to act on your behalf.
CCPA §1798.140(i) requires this for any agent-filed request.
Without a TPA most reputable brokers will (correctly) reject the request as unauthorized.
We generate a signed PDF the moment you type your signature, store the hash for audit purposes, and attach the PDF to every outbound broker email.
Step 3 — We file, and keep filing
Your removal scope is 632 sites across 580 companies.
One filing to a parent like PeopleConnect clears BeenVerified, Intelius, TruthFinder, InstantCheckmate and NeighborWho in one shot.
It does not all happen at once, and we will not pretend it does.
Firing that many letters in an afternoon would get our sending domain blocked and none of them would arrive.
So the sweep goes out at a steady rate, and keeps going month after month until your scope is clear.
The part we commit to in writing is the beginning of it.
Protection sends up to 100 removal requests a month for you. At least 23 go out in the first 14 days — most of what we can send in that time — or you get your money back.
The rest keeps going out at that same rate afterwards.
This is the same promise as the one on our refund & service guarantee, taken from the same place in the code — and if this page and that one ever disagree, that one controls.
Each outbound email sets Reply-To to a unique address on replies.galaxywarden.com so broker responses route to our inbound classifier, not your inbox. Every send is recorded verbatim in your dashboard’s Sent log — full body, recipient and timestamp — which is your record of what went out on your behalf. We deliberately do not copy you on each individual email: a sweep can run to as many as 100 sends in a month, and mirroring those into your inbox buries you. If you would rather receive a copy of every one, you can turn that on in Account settings.
Step 4 — Brokers respond (or don’t)
CCPA gives brokers 45 days to honor a removal request.
We do not print a removal rate.
We do not yet have one we could show you the working for.
A percentage you cannot check is worth nothing to you and would be worth a great deal to us — which is exactly why we do not publish it.
What we can tell you is what happens to every reply, because that part is ours:
- An acknowledgement or a confirmation. Every reply routes to our inbound classifier rather than your inbox, and moves that broker’s row in your dashboard. You read the broker’s own words, verbatim, with the date.
- A request to re-supply the TPA. Our system auto-replies with the authorization already on file, without you having to do anything.
- A demand for identity verification only you can complete — a code sent to your phone, a confirmation link, a document upload on their site. We cannot do those for you. We forward them with instructions.
- Nothing at all. Some brokers never reply. The 45-day window closes and the row stays at “request sent”. We file again; we cannot make them answer.
- No route we can file on. A small number of companies will not take a filing from us in any form, or no longer have a working address to take one at. We name every one of them below, with a link to their own removal page wherever one exists, so you can do those yourself.
Step 5 — We verify (a re-scan after the compliance window)
Removal isn’t instant. Brokers have up to 45 days to action a request.
After that compliance window we run a verification re-scan and email you proof of what came down — and flag anything a broker hasn’t honored.
The verification pass is part of your subscription. There is no separate fee for it.
Brokers also re-ingest from public-record sources, so your data can re-appear weeks after a confirmed removal.
Catching those re-lists and automatically re-filing a fresh takedown is ongoing work.
It comes with an active Protection subscription ($14.99/mo or $129/yr): continuous monitoring plus automatic relist re-strikes for as long as you subscribe.
Without it, your data may slowly re-accumulate as brokers re-ingest public records.
What “confirmed” means on your dashboard
The scanning dashboard shows three states per broker:
- Request sent · awaiting removal confirmation — we filed; the broker hasn’t replied yet (or replied with a generic acknowledgment).
- Our team is reviewing the broker’s reply — the broker responded with a non-standard request (e.g. asking for a notarized form). We’re handling it.
- Broker confirmed removal — the broker explicitly confirmed the data has been removed. This is the terminal positive state.
What we don’t cover
- Federal records: court filings, federal databases, news archives. CCPA doesn’t reach these.
- Foreign brokers without US presence: CCPA doesn’t reach them either.
- Brokers operating exclusively under B2B exemptions: some marketing data resellers serve only business buyers and are exempt from consumer-facing CCPA requests.
- Content you posted yourself on social media, forums, blogs, or your own websites. Removal requires you to take it down or use the platform’s own privacy tools.
Companies we cannot file for — every one of them
Our engine files by email, under the authorized-agent authorization you sign.
A small number of companies are outside that, for three different reasons.
We would rather you read the list than find out from a dashboard after you have paid.
We cannot file these for you.
Some route every request through their own portal or a form that needs a step only you can finish — a code to your phone, a CAPTCHA, an account in your name.
Some published a removal address that stopped accepting mail, and we have not found another route we can verify.
That one is our limit as much as theirs, and we say so rather than keep sending to an address that bounces.
One republishes what other sites publish, so a removal has to happen at the original source.
Each entry below says which it is, and links that company’s own removal page wherever one exists:
- Whitepages · TruePeopleSearch · Radaris · CheckThem
Their removal runs through a web form that needs a step only you can finish — a code to your phone, a CAPTCHA, or an account in your name. We cannot complete it for you. - FastPeopleSearch · USPhonebook · SearchPeopleFree · CyberBackgroundChecks · USA-People-Search · SmartBackgroundChecks · AdvancedBackgroundChecks · FastBackgroundCheck · PeopleSearchNow · Phonebooks.com
Mississippi Tornado Alley runs ten people-search sites. Letters to the privacy desk they registered with California are delivered and ignored, and each site has to be opted out separately, so these are yours to submit. - FamilyTreeNow
FamilyTreeNow no longer publishes an opt-out email address; their current notice handles every privacy right through this form. - Homemetry · PrivateEye · LocateFamily · Judyrecords · FreeBackgroundCheck.org · PeopleTrail · VeriPages · PeopleByName · BackgroundAlert · Arrests.org · JailBase · OpenGovUS · SignalHire · InfoFree · Near Intelligence
The removal address they publish stopped accepting mail, and we have not found another route we can verify. We would rather say that than keep sending to an address that bounces. - Epsilon
Epsilon rejects automated email submissions and requires the consumer (or authorized agent) to submit directly through their privacy portal. - Blackbaud
Blackbaud does not process opt-outs by email; all CCPA/data-subject requests must be submitted directly through their Data Subject Rights Request portal. - Oracle Data Cloud
Oracle Data Cloud routes all CCPA/privacy requests through their hosted privacy form rather than an email channel. - LiveRamp
LiveRamp’s opt-out is a self-service web form; they do not accept CCPA requests by email. - Social Mention
This one republishes what other sites publish. Removal has to happen at the original source, so filing here would achieve nothing even if they answered. - NeighborReport
NeighborReport’s domain no longer resolves — there is no website, form or mailbox behind it. Nothing can be filed with this company until it reappears. - USA-Trace
USATrace handles opt-outs through the form on their privacy page; their notice publishes no authorized-agent email route. - Skopenow
Skopenow’s mail gateway rejects our sender, so this one goes through their redaction form. Note that Skopenow suppresses your details from search results rather than deleting them — they say they hold no database of their own — so list the exact names, addresses, phone numbers and emails you want redacted. - 5x5 US, LLC
The address 5x5 registered with California no longer exists — the domain has been abandoned. The company is still trading and takes opt-outs through its own privacy portal. - Adttribution Inc (DBA Adttribution)
AdTtribution publishes no working opt-out mailbox and its notice says nothing about authorized agents, so this one has to go through their form.
Nobody keeps this list by hand.
It is built from the same rule that builds your queue, so it cannot fall behind: a company that starts accepting our requests drops off it and goes back into your sweep on its own.
Two other limits belong next to it, because they are the same kind of thing. Some brokers demand a verification step only you can finish — a code to your phone, a link in your email, an ID upload on their own site. And CCPA gives every broker up to 45 days to act, after which we can file again but cannot compel anyone. We control the filing. We do not control what the company decides. That sentence is from our refund & service guarantee, and it is the whole shape of what we sell.
Those are the ones we cannot file for. Here is the rest of it.
You have just read the whole limit, before paying anything for it.
The part we do control is the filing.
The way to see whether any of it applies to you is to look yourself up first.
It takes about 15 seconds, needs no card and no account, and the answer opens on the page.
Run my free scanAudit trail you keep forever
Every email we send is logged in your dashboard under Sent log.
Each entry includes the recipient, subject, full body, reference token, and date sent.
If a broker disputes your request, or you need to escalate to a state regulator (CA Attorney General, FTC), you have the receipts.
Run my free scan Free · no account · no card
See also: refund & service guarantee — the page that controls this one · terms of service · privacy policy