Questions · 14 answered
Frequently asked questions
Answers about breach scans, data-broker removal, plans, and privacy. New here? See how Nullivo works.
Trust and legality
Yes. Nullivo only scans an email address whose owner has just verified they control it. It’s a self-protection tool, like checking your own credit report. It has no feature for looking up other people.
Never. Nullivo only needs your email address (and a one-time code to confirm it’s yours). We will never ask for an account password.
As little as we can while still being able to monitor you. We keep your verified email address, your latest scan findings and which broker opt-outs you’ve completed. We do not store passwords, and the deep-search results (which can include exposed passwords) are shown to you and never written to our database. Analytics are first-party and cookieless, with the visitor identifier rotating daily so it cannot follow you between days. If you close your account we delete your data; you can also delete it at any time from your dashboard, and analytics rows are trimmed automatically. See the Privacy Policy for the full detail.
Nullivo runs on major cloud infrastructure in the United Kingdom behind TLS, with personal data encrypted at rest in the database. Sign-in is a one-time code sent to your address — there is no password to steal, and we never ask for the password to any other service. Card details are entered on our payment processor’s own checkout and never touch our servers. Access to the admin systems is restricted to a named allowlist. No service can promise it will never be breached, which is exactly why we hold as little about you as the product allows.
No. Selling user data would be the opposite of the product’s purpose. Nullivo makes money from subscriptions, not from your information.
The UK
Nullivo checks your address against the industry-standard global breach register via its official API. Breach data is global, so it works wherever you live.
Yes. Your breach scan is global. For data-broker removal, choose your region in the cleanup tool: UK users should start with the Open Electoral Register (the source most UK brokers buy from) and 192.com; EU users can send a GDPR erasure request to any site listing them. Note that most US people-search sites only list US residents, so UK/EU users often won’t appear on them.
There are two routes, and each broker card tells you which it is. ‘Find your listing’ brokers (most US people-search sites): search your name, copy your profile’s URL, and submit that URL on their opt-out page. ‘Email request’ brokers: copy the ready-made deletion letter and email it to them. Tap ‘How to do this’ on any broker for exact steps, and remember to click the confirmation link they email you.
Plans and money
The free scan shows your exposure score and a risk breakdown, and it stays free. Essential (£49 a year) covers the 22 UK holders in our published registry — 192.com, LexisNexis Tracesmart, the credit-bureau marketing files, the electoral roll at source — with every request dated and the one-month legal deadline counted for you. Complete (£99) adds US and EU brokers, weekly re-checks, the deep breach search that shows the actual data exposed including leaked passwords, and an ICO complaint drafted when a broker lets the month lapse. Household (£189) is Complete for up to 5 people, with the correspondence handled end to end.
Yes, and it depends on whether we have started. Cancel before we run your scan or send your first removal request and it is a full refund, no questions. After that we may keep a fair share of what has already been done — a removal request is a legally binding notice sent to a named company and it cannot be un-sent — and we will tell you what that amount is and why. Beyond that, if we simply have not delivered for you, email support@nullivo.com within 30 days of your first payment and we will put it right. Cancelling at any time stops future renewals and your access runs to the end of the period you have paid for. Full detail is on the Terms page.
The product
On Complete and Household, yes, for your own verified email only. The deep breach search shows the real data found in breaches of your account, including exposed passwords, masked by default and revealed only when you choose to. Nullivo never stores these results. You cannot look up anyone else, only an address you have verified you control.
Every month, on all paid plans. We re-run your breach scan and re-check your data-broker listings, and we email you only when something has actually changed — a new breach, or a broker that has re-listed you. On top of that, new breaches added to our sources trigger an alert as soon as they appear rather than waiting for the monthly cycle. Brokers routinely re-list people every few months, which is why removal is an ongoing process rather than a one-time job.
No service can. Once a website is breached and its database leaks, that data exists permanently across many copies and cannot be recalled by anyone. What you can do is change any exposed password everywhere you used it and turn on two-factor authentication. Data-broker listings are different: those companies actively republish your details and do have opt-out processes, which Nullivo helps you complete.
It’s a plain-language summary of the risks your exposed data creates (credential stuffing, impersonation, SIM-swap, targeted phishing), based on exactly what your breaches exposed, so you know what to fix first.