Security & data protection
We ask people to trust us with the fact that they are worried about their exposure. This page says exactly what we do with that, in enough detail to be checked.
There is no password to steal
Nullivo has no passwords. You sign in with a one-time code sent to your address, so there is no password database to breach, no credential to reuse, and nothing for a phishing page to capture. We will never ask you for the password to any other service, and no feature of the product has any use for one.
What we hold, and how
- Email addresses are encrypted at rest. Personal data is encrypted with AES-256-GCM before it reaches the database, so a stolen database dump is unreadable without a key that is not stored alongside it.
- Card details never touch our servers. Payments run on our payment processor’s own checkout, hosted on their domain. We store a customer reference and what plan you are on, nothing more.
- Deep-search results are never written down. On Ultimate, exposed passwords and records found in extended sources are shown to you and discarded. They are not stored, logged, or included in any backup.
- Removal profiles are minimal by design. If you use broker removal we hold a name, an optional town, and the outward half of a postcode — SW1A, never SW1A 1AA. Enough to tell you apart from someone with your name in a search box; not an address. You can delete it on its own without closing your account.
- Administrative access is an allowlist. Internal tooling is restricted to named addresses, and the same check gates every administrative endpoint.
Our analytics do not track you
Nullivo measures its own traffic without cookies and without storing anything on your device — which is why you are not asked to dismiss a banner for it. We do not store your IP address or your full user-agent. The identifier that counts visitors is a one-way hash salted with a server-side secret and the current date: at midnight the salt changes, so yesterday’s rows cannot be linked to today’s. It can count how many people visited on a day. It cannot follow anyone between days, and neither can we.
Who else processes your data
These are every category of processor we use, what each one can see, and where it holds it. We do not sell data, and we do not share it with anyone outside this list. We name the individual suppliers in writing to any customer who asks — write to privacy@nullivo.com and we will tell you exactly who they are. We do not publish the list, because who we build on is commercial information and our competitors read this page too.
| Function | What it does | What it can see |
|---|---|---|
| Hosting, application runtime and database United Kingdom | Runs the site and holds the database | Everything we store: verified email addresses, scan findings, cleanup progress, removal profiles |
| Payments and subscription billing EU / US, under the processor's own transfer safeguards | Takes and manages payments | Your email address and payment details, which you enter on the processor's own checkout — never on our servers |
| Email delivery EU / US | Sends sign-in codes, alerts and receipts | Your email address and the content of the message |
| Breach-data source Global | The breach register your scan is checked against | A query for your email address; results are not retained on our behalf |
| Website analytics EU / US | Aggregate traffic measurement and search performance | Only if you accept analytics cookies. Our own measurement is cookieless — see below |
Used only where you have opted into the feature that needs them: Extended breach-data sources — Additional breach registers behind the Ultimate deep search. Queried live for your own verified address and nothing else. Results are shown to you and are never written to our database. A data-broker removal partner — Automated removal from US brokers. Only for subscribers who explicitly enrol, and only US residents.
What we will not claim
We are a small UK company, not a certified enterprise vendor. We do not hold ISO 27001 or a SOC 2 report, and we have not had a third-party penetration test. We would rather say so than imply otherwise, and we will update this page when that changes. No service can promise it will never be breached — which is precisely why we hold as little about you as the product allows.
Reporting a vulnerability
If you think you have found a security issue, email security@nullivo.com with enough detail to reproduce it. We will acknowledge you within three working days. Please do not access, modify or retain anyone else’s data while testing, and give us a reasonable chance to fix the issue before publishing it. We will not pursue legal action against anyone who reports in good faith and follows this.
Your rights
You can export or delete your data at any time from your dashboard, or by emailing privacy@nullivo.com. Deleting your account removes your findings, cleanup progress and removal profile. The full detail of what we hold, for how long, and the legal basis for it is in the Privacy Policy; if you are unhappy with how we handle a request you can complain to the Information Commissioner’s Office at ico.org.uk.