Privacy policy
Last updated: July 2026
1. Who we are
Efface (efface.me) is a privacy-removal service operated by Klart AI, Paris, France (the “data controller” for the data described below). Contact: privacy@efface.me.
2. What we collect, and why
We deliberately collect the minimum needed to identify your records in third-party databases and to run your account:
- Identity data you give us at signup — full name, email address, phone number, LinkedIn URL (optional), country of residence, preferred language. Purpose: composing and sending data removal/erasure requests to data brokers on your behalf (performance of our contract with you).
- Your authorization mandate — the checkbox you tick at signup, with its timestamp. Purpose: proving to third parties that you authorized us to act on your behalf (legal obligation / contract).
- Request records — which databases we contacted for you, when, and each request’s status. Purpose: providing your dashboard and reports.
- Billing data — handled by Stripe; we store only your Stripe customer reference and subscription status. We never see your card number.
We do not collect government ID, and we never sell or share your data for advertising. We are in the business of less data, not more.
3. What we send to third parties
To exercise your rights, each removal request we send to a data broker includes the identifiers needed to match your record: your name, email, phone number and, if provided, LinkedIn URL — together with the statement that you have mandated us. The reply-to address is your own email, so brokers can verify the request with you directly.
4. Processors we rely on
- Supabase — database and authentication hosting
- Vercel — application hosting
- Stripe — payment processing
- Resend — email delivery
Where these providers process data outside the EU/EEA, transfers are covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.
5. Retention
Your data is kept while your account exists. When you delete your account (one click in the dashboard), your profile, request history and events are erased immediately; we keep only what invoicing law requires (Stripe records) and a minimal proof of your past mandate if needed to defend legal claims. Requests already delivered to brokers cannot be recalled.
6. Your rights
Under the GDPR you can access, rectify, erase, restrict or port your data, and object to processing. The fastest route: the “Delete my account” button in your dashboard, or email privacy@efface.me. You may also lodge a complaint with your supervisory authority (in France, the CNIL — cnil.fr).
7. Cookies
We use only strictly necessary cookies: the session cookie that keeps you signed in. No analytics cookies, no advertising trackers, no third-party pixels — which is why you don’t see a cookie banner.
8. Security
Data is encrypted in transit, access is enforced row-by-row at the database level (you can only ever read your own records), and secrets are held server-side only. Sign-in is passwordless (magic links), so there is no password of yours to breach.
9. Changes
We will post any material change here and, if you have an account, notify you by email.