The no-lookup promise

Built for protection, not surveillance.

Every company in this market says it cares about your privacy. That claim cannot be tested, so it is worth nothing. Below are five things Nullivo cannot do — each with the mechanism that stops it — and an invitation to check that we are telling the truth.

  1. We only ever scan an address you have proved you control

    Every scan starts with a one-time code sent to that address. There is no way to enter someone else's email and see their exposure — not rate-limited, not gated behind a plan. The lookup feature does not exist.

    How it is enforcedEnforced by the sign-in flow itself, not by a policy. Results are only ever rendered against a verified session.

  2. We never ask for your password

    Not for your email account, not for any breached service, not for anything. Nobody legitimate needs your password to tell you it has leaked, and any service that asks for one has built a credential collection point.

    How it is enforcedThere is no password field anywhere in Nullivo. Sign-in is a one-time code; there is nothing to steal from us.

  3. Exposed passwords are shown once and never stored

    A deep scan can tell you which of your passwords appeared in a breach. That information is displayed to you in the moment and is not written to our database, our logs, or our backups.

    How it is enforcedDeep-scan results are held in the response and discarded. We cannot show them to you a second time, which is inconvenient by design.

  4. We do not own, operate, invest in, or take referral income from any data broker or people-search site

    Not through a parent company, not through a founder's other venture, not through an affiliate arrangement. We are not on both sides of this market, and we never will be.

    How it is enforcedA structural commitment, and the one we would most want you to check. Ask us directly and we will answer in writing.

  5. We are paid by subscribers, not by data

    Our only revenue is subscriptions. We do not sell, rent, broker, or enrich your data, and we do not run advertising against it. Selling the data of people who paid us to remove their data would end the business the day it came out.

    How it is enforcedOur security page lists every category of processor that touches your data, what each one can see, and where it holds it. We name the individual suppliers in writing to any customer who asks.

How to check we are telling the truth

Do not take the first pledge on trust. Open the free scan and enter an email address that is not yours — a colleague's, a public address from a company website, anything. You will not get a result. You will get a code sent to an inbox you cannot open, and that is where it ends.

That is the whole product decision in one screen. A tool that can show you a stranger's exposure is a tool that can show a stranger yours, and there is no version of that we are willing to build.

Try it — scan an address that isn’t yours

Why this needs saying at all

In March 2024 the security journalist Brian Krebs reported that the chief executive of one of the largest personal-data removal services had founded dozens of people-search sites — the same kind of business that service charged its customers to remove them from. Mozilla, which had bundled that service into Firefox, took until November 2025 to confirm it had fully cut ties.

We are not naming that to score a point. We are naming it because it is the reason a reasonable person should refuse to believe a privacy promise from a company they have never heard of, including this one. The only useful response is to publish commitments specific enough to be broken, and then let people test them.

The full list of processors that touch your data, and where each one holds it, is on our security page. What we remove you from is published in full on our coverage page — every holder named, not a headline number.

Last reviewed 10 September 2026.

These commitments are made on behalf of Nullivo and are binding on us. If you believe we have broken one, write to privacy@nullivo.com and we will answer.

— Nullivo, on behalf of Organic Village (UK) Limited · Company No. 11783758