Efface

Privacy policy

Last updated: July 2026

1. Who we are

Efface (efface.me) is a privacy-removal service operated by Klart AI, Paris, France (the “data controller” for the data described below). Contact: privacy@efface.me.

2. What we collect, and why

We deliberately collect the minimum needed to identify your records in third-party databases and to run your account:

We do not collect government ID, and we never sell or share your data for advertising. We are in the business of less data, not more.

3. What we send to third parties

To exercise your rights, each removal request we send to a data broker includes the identifiers needed to match your record: your name, email, phone number and, if provided, LinkedIn URL — together with the statement that you have mandated us. The reply-to address is your own email, so brokers can verify the request with you directly.

4. Processors we rely on

Where these providers process data outside the EU/EEA, transfers are covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.

5. Retention

Your data is kept while your account exists. When you delete your account (one click in the dashboard), your profile, request history and events are erased immediately; we keep only what invoicing law requires (Stripe records) and a minimal proof of your past mandate if needed to defend legal claims. Requests already delivered to brokers cannot be recalled.

6. Your rights

Under the GDPR you can access, rectify, erase, restrict or port your data, and object to processing. The fastest route: the “Delete my account” button in your dashboard, or email privacy@efface.me. You may also lodge a complaint with your supervisory authority (in France, the CNIL — cnil.fr).

7. Cookies

We use only strictly necessary cookies: the session cookie that keeps you signed in. No analytics cookies, no advertising trackers, no third-party pixels — which is why you don’t see a cookie banner.

8. Security

Data is encrypted in transit, access is enforced row-by-row at the database level (you can only ever read your own records), and secrets are held server-side only. Sign-in is passwordless (magic links), so there is no password of yours to breach.

9. Changes

We will post any material change here and, if you have an account, notify you by email.