Privacy policy
Lethe Scan My Data
Last updated: October 8, 2026
What Lethe Is
Lethe is operated by Rudra Satani. This policy covers the anonymous scan tool and assisted-removal email waitlist. The free scan checks ten public broker surfaces and shows redacted results. Manual removal guides are available; assisted removal is a future feature.
Signed-in profiles and dashboard scan history are covered by the Lethe account and website privacy policy.
What The Scan Asks For
The scan asks for first name, last name, and city. The backend can accept an optional state if the interface adds one later. Do not enter information for someone else unless you have permission to do so.
What We Do Not Store
Anonymous scans do not durably store your name, city, state, or scan results. The scan request is handled in memory, and broker response bodies are not saved or returned to analytics.
A short-lived in-memory cache holds redacted results for up to five minutes, keyed by a salted digest of the scan input. A hashed-IP rate-limit bucket also lasts up to five minutes. Raw inputs and broker response bodies are not cached. The cache and rate-limit buckets do not survive a process restart.
Signed-in accounts work differently: profile information is encrypted by the API before persistence, and dashboard scans retain status and exposed-category flags. An account email is retained as an identifier. These account records are not part of the anonymous scan's short-lived cache.
Email Waitlist
Email is requested only if you choose to join the waitlist. The email is used for Lethe waitlist updates and early access only. The scan input is not attached to the email.
The waitlist stores the email address, a salted email hash, the aggregate number of sites that may have exposed data, the scan timestamp, and a salted source-IP hash for abuse prevention. It does not store first name, last name, city, state, broker responses, broker URLs, or raw IP address.
Lethe requires double opt-in before treating the waitlist address as confirmed. Each waitlist email includes an unsubscribe link, and repeated submissions are limited to one email per address per 24 hours.
Analytics
Lethe uses PostHog only when the public PostHog environment variables are configured. The scan tool sends direct capture requests without loading the PostHog browser SDK, without cookies or local storage, with browser credentials omitted, and with IP collection disabled on the capture URL.
Events include page visits, sanitized referral and campaign context, scan started, scan failed, completed live scans with aggregate counts, waitlist submit intent, and assisted-removal clicks. Failed scans are never counted as completed live scans. Analytics must not include names, city, state, email, IP address, raw broker responses, result payloads, or broker-level personal details.
Broker Checks
The scan makes read-only public checks. Lethe does not use broker accounts, CAPTCHA bypass, proxies, credentialed access, fingerprint spoofing, or browser evasion in this scan tool. If a broker blocks or gates access, the result is marked unavailable.
Important Limits
Unavailable does not mean not found. Not found does not guarantee that no record exists. Lethe does not sell your personal data and does not claim guaranteed data removal. Manual guide links open the broker's website, where its privacy policy applies. Lethe does not send scan inputs through those links or submit opt-outs.
Contact
Questions or deletion requests for waitlist data can be sent to support@getlethe.cloud.