Skip to content
APPENDIX A — PRIVACY POLICY
FILE US-NCR/2026PRIVACY POLICYLAST UPDATED: JUNE 2026

Privacy receipt. Sensitive file stays out.

People come to us at their most exposed. This page gives the public handling boundary: what may enter, what stays out, who may process it, when records close, and how the client keeps control without exposing the work.

Private evidence room

We show the receipt, not the sensitive file.

A strong privacy page proves the public handling boundary: what may enter, what stays out, who may process it, and when the record closes.

Start safe review
MINCONTROL

Minimum viable evidence.

The public policy names the boundary. The AboutUs client record asks only for material needed to review and carry AboutUs work.

ACCESSCONTROL

Need-to-know handling.

Case material belongs with the case team and named processors. Public pages show control boundaries, not private case detail.

SEPARATECONTROL

Sensitive boundaries stay apart.

Adult intimate-image, AI-nude, sextortion, minor-involved, fallback, and standard reputation matters do not share the same intake posture.

CLOSECONTROL

The file has an exit.

Declined assessments, closed cases, rights requests, and supporting documents each have a visible close condition.

Privacy record lock

Enough proof. No spillover.

The public page earns trust by showing boundaries. The client record keeps the actual private answer, evidence boundary, and client-update record private.

PUBLIC

Handling boundary.

The policy names what may enter, what stays out, who may process it, and how records close.

PRIVATE

Private answer stays inside.

Private answer, evidence boundary, processor handling, and closeout notes stay inside the client record.

CLIENT

Control receipt.

The client gets the useful record: what was received, where it sits, what is retained, and how to request control.

STOP

Exposure stops early.

Intimate files, minor-involved material, passwords, full ID numbers, and card data stay out of generic intake.

Disclosure discipline

Three layers. No spillover.

The public page should create trust. The client-record check should create the boundary. The client record should carry the accepted handling record.

Public policy

Names the controller, categories, processors, rights path, retention posture, and hard stops.

Client-record check

Separates public intake, private case review, official reporting, fallback, and declined matters before work moves.

Client record

Carries the written boundary, handling record, access boundary, and client receipt.

Sensitive file handling

We reduce exposure before we review.

Privacy here is operational, not decorative. The intake should collect enough to understand the boundary without pulling exposed material into a generic form or card authorization.

18+ onlyConfidentialNo exposure-first forms

Adult intimate-image, AI-nude, and sextortion matters move to private case review from a minimal private summary. The sensitive file itself stays out of the first read.

Client-record check
01HANDLING

Start from pointers

A review can start from a minimal private summary. The exposed material itself is not needed for the first read.

02HANDLING

Stage the evidence

Supporting documents wait until they are needed for an accepted or reviewable matter. Case material stays with the small case team and named processors.

03HANDLING

Keep routes separate

Standard review, private case review, official reporting, fallback posture, stop items, and legal-referral matters stay separated before AboutUs work.

04HANDLING

Close the file

Declined assessments are deleted once communicated. Supporting documents are kept only while needed and auto-deleted no later than 120 days after receipt.

Document rule

Enough evidence to review. Nothing more exposed than needed.

FIRST READ

Minimal private summary, urgency, and enough public-safe context to understand the boundary.

ONLY IF ASKED

Identity proof, business registration, court records, or non-intimate screenshots that support the boundary.

NEVER FIRST

Intimate files, passwords, full ID or card numbers, minor-involved content, or material you do not have the right to share.

ACCESS

Small team, named tools.

Case material stays with the case team and the processors listed in this policy, each limited to its function.

ROUTE

Sensitivity stays labeled.

Adult intimate-image, AI-nude, sextortion, and minor-involved matters are separated from standard form flow.

RETAIN

Retention has an end.

Declined assessments close out after the decision. Supporting documents have a 120-day outer limit, sooner on request or when the case closes.

RIGHTS

The control path is visible.

Access, correction, deletion, and search-fallback questions go to the privacy contact instead of disappearing into chat.

Privacy control ledger

The file has a visible chain of handling.

The policy below is the legal register. This ledger is the control view: what can enter, who may touch it, where it stops, and how control requests move.

Controller: AboutUsAgency Inc.Contact: intake@aboutusagency.comU.S. state privacy law (incl. CCPA/CPRA)
Start safely
FORM
Allowed first

Contact details, selected matter type, and a minimal private summary.

Boundary

No intimate files, passwords, full ID numbers, card data, or minor-involved material in the form.

Close condition

Assessed, declined and deleted once communicated, or moved to a written boundary.

LIVE
Allowed first

Adult intimate-image, AI-nude, sextortion, or urgent exposure context from a minimal private summary.

Boundary

Human review first; generic file intake and the public card rail stay closed until the boundary is safe.

Close condition

Routed to confidential handling, official reporting, or a no-fit boundary.

DOCS
Allowed first

Supporting documents only when asked and only when they support the review.

Boundary

Private, access-controlled storage; small case team and named processors only.

Close condition

Kept while needed, auto-deleted no later than 120 days after receipt, sooner on request or close.

SIGNALS
Allowed first

IP at submission for abuse protection, plus aggregate analytics and ad measurement signals.

Boundary

Case details stay out of analytics and advertising measurement.

Close condition

Browser opt-out and privacy request paths stay visible.

Rights path

Control requests have a named door.

Email privacy desk
ACCESSREQUEST

See what we hold.

Ask for the personal information connected to your inquiry or case.

CORRECTREQUEST

Fix what is wrong.

Send a correction request if a case detail, contact field, or supporting record is inaccurate.

DELETEREQUEST

Close what is no longer needed.

Ask us to delete information that is no longer required for the assessment, case, or legal obligation.

DELISTREQUEST

Separate search fallback.

Search-fallback questions stay labeled as fallback work, never as source removal.

We verify privacy requests and respond under the timing required by U.S. state privacy law (incl. CCPA/CPRA).

01

Who is responsible

AboutUsAgency Inc., 169 Madison Ave STE 38501, New York, NY 10016, is the data controller for this website and for case intake. Privacy questions and requests go to intake@aboutusagency.com.

02

What we collect

Client-record check form: your name, email address, the content type you select, and the minimal private summary you provide. We ask for public-safe context first; the exposed material itself is not needed for the first read.

Case documents:if you submit a case, you may attach supporting documents — such as a redacted proof of identity, business registration, covered screenshots, or court records. Paid clients use a receipt-gated case room; these documents go to private, access-controlled storage that only our case team can open. Intimate or sexual originals stay on the client’s device and never belong in our forms, storage, email, chat, or card authorization.

Chat: messages you send through the on-site chat (operated by Crisp). Our chat assistant discloses that it is automated; sensitive matters are handed to a human. Crisp carries conversation and case status, not identity documents or intimate files.

Email: correspondence you send to our intake address.

Technical data: your IP address at form submission (used only for abuse and spam protection) and standard analytics signals described in section 06.

03

Why we process it

To assess your matter, respond to you, perform accepted removal work, protect the site against abuse, and measure — in aggregate — whether the site works. We do not sell personal information, and we do not use your case details for marketing.

04

Confidentiality by design

Intake is read by a small case team under a strict confidentiality agreement. We never re-expose, republish, or request intimate originals. Our process is built on private summaries, redacted identity documents, covered evidence screens, and optional client-side fingerprinting where it applies. If you choose the local fingerprint tool, your browser sends a mathematical fingerprint value, media type, and byte size, not the file, filename, or preview. We do not publish client names or identifying case details; public reporting stays aggregate or anonymized.

05

Who processes data on our behalf

We use a small set of infrastructure providers, each receiving only what their function requires: Vercel (website hosting, and private access-controlled storage for any case documents you provide), Crisp (conversation and case-status alerts, not document bytes), Resend (transactional email delivery of intake notifications, not document attachments), and Google (analytics and advertising measurement, section 06). We do not sell or rent personal information to anyone. We disclose information beyond these processors only where the law requires it — or where filing a removal notice on your behalf necessarily identifies the request to a platform.

06

Analytics & advertising cookies

We use Google Analytics 4 and Google Ads conversion measurement to understand site usage and ad performance. These set cookies and collect device and usage signals; we do not feed them your case details. You can opt out with the Google Analytics opt-out or by blocking cookies in your browser — the site works fully without them.

07

How long we keep it

Assessment submissions we decline are deleted once the declination is communicated. For engaged cases, we retain case records for the duration of the engagement and as needed for the client receipt, any watch coverage you have engaged, and our legal obligations — then delete them. Supporting documents are kept only as long as they are needed for your case and are automatically deleted no later than 120 days after receipt — sooner on request, or when your case closes. Operational email and chat history follow the same principle: kept while needed, then removed.

08

Your rights

You may request access to, correction of, or deletion of your personal information at any time by writing to intake@aboutusagency.com. Depending on where you live (including California under the CCPA/CPRA), you may have additional statutory rights — we honor access and deletion requests regardless of residence. We will verify the request and respond within 30 days.

09

Minors

This service is for adults (18+) only, and we do not knowingly collect information from anyone under 18. We work with adults (18+) only. If intimate images of someone under 18 are involved, report it immediately to the NCMEC CyberTipline at report.cybertip.org, use NCMEC's Take It Down at takeitdown.ncmec.org, and contact local law enforcement. Do not send the content to anyone — including us.

10

Changes & contact

We update this page when our practices change and revise the date above. Material changes are noted prominently. Questions: intake@aboutusagency.com · AboutUsAgency Inc., 169 Madison Ave STE 38501, New York, NY 10016.

THIS PAGE IS INFORMATION ABOUT OUR PRACTICES, NOT LEGAL ADVICE.