ScrublScrubl

Privacy Policy

Effective date: July 23, 2026

This Privacy Policy explains how TaterTapps LLC (“TaterTapps,” “we,” “us,” or “our”) collects, uses, shares, and safeguards information when you use Scrubl (the “Service”) — our data-broker removal and exposure-monitoring service — through our website or mobile apps. Scrubl exists to reduce the amount of your personal information available online, so this policy is written to be specific about exactly what we collect and who we send it to. By using the Service, you agree to this policy.

1. Information We Collect

a. Account information

Your email address and authentication identifiers when you create an account. You may sign in with an email and password, with Google, or with Apple. We never see or store your Google or Apple password.

b. Profile information for the people you protect

To search for and remove your records, you provide identifying details about yourself and, on multi-person plans, about other people you are authorized to represent. This includes:

  • First and last name
  • Age
  • City and state
  • Email addresses (one or more)
  • Phone numbers (one or more)

Depending on your plan, you may create profiles for up to four people.

c. Information we discover about you

When we scan data-broker sites, the records we find may contain additional personal information that those brokers already published. We store these results so you can review them and so we can verify removal. Discovered records may include:

  • Full name, age, and gender
  • Current and past street addresses
  • Email addresses and phone numbers
  • Names of relatives and associates
  • Employment, occupation, and education history
  • Property records
  • Links to the broker pages where the record appeared

We did not create this information and we do not sell it. We collect it in order to get it taken down.

d. Breach and leaked-password data

If you use our leaked-password monitoring, we check your email addresses against known breach datasets. Results may include the names and dates of breaches, the categories of data exposed, and passwords that appeared in those breaches. Any leaked password we store is encoded at rest and is only decoded in your browser or app when you explicitly choose to reveal it.

e. Device and usage information

Device type, operating system, general (city-level) location, app and site interactions, crash reports, and performance data.

f. Payment information

We do not collect or store your card number. Web payments are processed by Paddle, which acts as the merchant of record; purchases made in our mobile apps are processed by Apple or Google. We receive only a subscription status and a customer identifier.

2. How We Use Your Information

  • To search data-broker sites for records that match the people on your account
  • To submit removal and opt-out requests to those brokers on your behalf
  • To re-scan on an ongoing basis and re-submit removals when your data reappears
  • To check your email addresses against known breach datasets and alert you
  • To create, secure, and support your account
  • To process subscriptions, billing, and refunds
  • To detect abuse and protect the Service
  • To analyze aggregate usage so we can improve the product

We do not use your personal information to train artificial intelligence models, and we do not sell it.

3. How Removal Works — and What It Requires

This is the most important disclosure in this policy, so we want it to be unambiguous.

Data brokers will only remove a record if they can match it to a specific person. To get your information deleted, we (through our removal partner) must submit identifying details — such as your name, age, city and state, email addresses, and phone numbers — to those brokers and their opt-out systems. In other words, removing your data requires disclosing enough information to identify the records as yours.

We limit these submissions to what a broker requires to process an opt-out request. By using the Service, you authorize us and our removal partner to act as your agent for the purpose of submitting these requests.

4. Who We Share Information With

We do not sell your personal data. We share it only with the service providers below, and only for the purposes described.

  • Array (BrandYourself) — our data-removal partner. Receives the profile information for the people on your account in order to search data brokers and submit removal and opt-out requests on your behalf. This sharing is essential to the Service.
  • Enzoic — receives email addresses to check them against known breach and leaked-password datasets.
  • Google Firebase (Google LLC) — provides authentication, database storage, and abuse prevention (App Check / reCAPTCHA) for the Service.
  • Paddle — merchant of record for web purchases. Handles payment details, tax, and refunds.
  • RevenueCat — manages subscription entitlements across web and mobile.
  • Amplitude — product analytics, used to understand feature usage and improve the Service.
  • Apple and Google — process purchases made through their app stores.
  • Law enforcement or other parties where required by law, or to protect our rights, our users, or the public.

5. Cookies, Storage, and Analytics

We use browser storage and similar technologies to keep you signed in, remember your preferences, secure the Service against automated abuse, and measure how the product is used. Specifically:

  • Strictly necessary — authentication sessions, and Google reCAPTCHA / Firebase App Check to verify that requests come from the genuine app rather than a bot.
  • Analytics — Amplitude, to understand which features are used so we can improve them.
  • Payments — Paddle sets storage necessary to process a checkout and prevent fraud.
  • Advertising — with your consent, the Meta (Facebook) Pixel and Google Ads tag, so we can measure the effectiveness of our advertising and reach more people who need privacy protection. To match your activity and purchases to an advertising click, we may share hashed (irreversibly encoded) versions of contact details you provide — such as your name, email, city, and state — plus your purchase amount, with Meta and Google. This data is hashed on your device before it is sent and cannot be reversed by us or by them into readable form; it is used only to measure advertising, never to build a public profile of you. We never share the personal data we find and remove on your behalf.

Advertising cookies are set only if you accept them in the cookie banner shown on your first visit. If you decline, or in regions where consent is required and not given, the advertising tags stay off and only the strictly necessary, analytics, and payment technologies above are used. You can change your choice at any time by clearing this site’s storage in your browser settings. We do not sell your personal information.

6. Data Retention

We retain your account and profile information for as long as your account is active, and retain records of removal requests for as long as needed to prove a removal was requested and to detect when your data reappears. When you delete your account, we delete your stored data and instruct our removal partner to scrub the personal information associated with your enrollment, except where we are required to keep records by law.

7. Your Choices and Rights

  • You can review, edit, or delete the profiles of people on your account at any time.
  • You can delete your account from within the app, which also requests removal of your personal information from our removal partner.
  • You can cancel your subscription at any time; cancelling stops future removal work but does not by itself delete your account.
  • You can opt out of marketing communications at any time.
  • You can control device permissions through your device settings.
  • Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to appeal a decision about such a request. To exercise any of these rights, contact us at support@scrubl.co.

8. Children’s Privacy

The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children. If you believe we have collected such information, please contact us so we can remove it. If you add a minor to a family plan, you represent that you are their parent or legal guardian.

9. Security

We use reasonable security measures to protect your information. Data in transit is sent over encrypted connections (HTTPS). Access to your data requires authentication, and our backend verifies both your identity and the integrity of the app making the request before returning any personal information. Leaked passwords are encoded at rest and decoded only on your device when you choose to view them.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date. Continued use of the Service means you accept the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

TaterTapps LLC
Email: support@scrubl.co