DATA SOURCES DIRECTORY

Data Sources

Deleteme helps customers understand where their personal information may be exposed online. When a customer requests a search, we may look across a broad range of lawful sources to identify relevant records, profiles, listings, publications, and signs of cybersecurity exposure.

The source directory below explains the main categories we may consult. The examples are illustrative, not exhaustive. A source’s inclusion does not mean that it is searched for every request, that it is currently available, or that Deleteme is affiliated with or endorses the source.

Important: Information that can be found online is not automatically free of privacy, confidentiality, copyright, contractual, or security restrictions. Deleteme applies access, purpose, minimization, and security controls according to the source and the requested service.

How searches work

  • Customer-directed. Searches are initiated in response to a customer request and the search details the customer provides.

  • Purpose-limited. Sources are consulted only as reasonably necessary to provide the requested privacy, exposure, monitoring, or removal service.

  • Source-aware. We distinguish freely accessible public sources, licensed sources, customer-provided information, archived material, and restricted cybersecurity intelligence.

  • Defensive. Cybersecurity exposure data is used to help identify and explain potential risk. It is not used to access accounts, test credentials, enable fraud, or facilitate harmful activity.

  • Human-reviewable. Source information can be incomplete, stale, duplicated, or wrong. Material findings should be independently verified before action is taken.

Our five source categories

1. Public internet, records, and directories
This category includes information that is lawfully available through public websites, government and court portals, official registers, public notices, business and professional directories, telephone directories, review sites, open publications, and similar repositories.
We may use these sources to locate records connected to the search details supplied by the customer, identify the originating publisher, assess whether a correction or removal path is available, and provide a source reference in a report.
Representative source families include: government, court, property, patent, corporate, licensing, and archival records; business, professional, telephone, address, people-search, genealogy, and obituary directories; news sites, blogs, public documents, discussion pages, review platforms, and media repositories; and public-facing e-commerce, marketplace, community, and profile pages.
Safeguard: Public availability is assessed in context. Deleteme does not treat restricted, sealed, suppressed, non-public, or access-controlled records as public merely because a copy may exist online.

2. Social media and user-contributed content
This category includes public profiles, posts, comments, media, public groups, public channels, contributor pages, and other content made available through social or community platforms. It can also include information a customer submits directly to Deleteme for an authorized request.
We may use these sources to identify exposed identifiers, impersonation or unwanted profile visibility, duplicated public information, and potential removal or privacy-setting options.
Examples include public-facing content on professional networks, social networks, video and image platforms, code-hosting services, discussion communities, creator platforms, and public messaging channels.
Safeguard: We do not characterize content from a private account, closed group, or login-only area as public. Access must be authorized and consistent with applicable law and platform rules.

3. Data brokers and commercial data sources
This category includes people-search services, marketing and identity-data providers, business-information services, credit-reference and directory providers, and other commercial sources that compile information from multiple origins. Depending on the service, a source may be publicly searchable, available under a license, or consulted only to support an opt-out or removal request.
Deleteme may use official data-broker registries and the providers’ own websites to identify relevant services, confirm request procedures, and help customers exercise applicable privacy rights.
Safeguard: A company’s appearance in a directory or historic registry does not prove that it currently operates as a data broker or holds information about a particular person. Status, ownership, jurisdiction, and request method should be verified at the time of use.

4. Search engines, web archives, and publications
This category includes general and specialized search tools, site-search tools, open indexes, cached or archived pages, document repositories, news and publication databases, and web archives. Archived material may remain discoverable even after the original page has changed or is no longer available.
We may use these sources to discover the location and history of a relevant page, confirm that a result is still accessible, identify duplicates, and locate the publisher or removal route.
Safeguard: Search results, snippets, cache entries, and archive captures may be outdated or incomplete. Deleteme identifies the underlying source where reasonably possible and does not present an archived copy as proof that information remains live on the original website.

5. Cybersecurity exposure intelligence
This category includes breach notifications, leak reporting, credential-exposure indicators, stealer-log indicators, ransomware and extortion reporting, public security-research feeds, malware and phishing intelligence, underground-forum monitoring, and relevant deep-web or dark-web intelligence obtained from lawful sources.
This material may indicate that an email address, username, password-related record, device identifier, session token, or other personal or organizational information was exposed. Dates may refer to discovery, publication, indexing, infection, upload, or collection and may not establish when the underlying compromise occurred.
For safety and legal reasons, Deleteme may identify the source category or service without publishing a direct link to a criminal forum, market, channel, credential file, malware sample, or other harmful location.
Safeguard: Deleteme does not deploy malware, buy stolen credentials, test exposed passwords, use session cookies, access a person’s account, or republish raw credential material. Exposure intelligence is handled for defensive privacy and security purposes with restricted access and appropriate retention controls.

Source directory overview

The following overview summarizes the source families found in the supplied inventories. Appendix C preserves every supplied source record. Inclusion is not a claim that every listed service is continuously monitored, lawful for every use, or currently available.

Category | Includes | Representative examples | Access class
Public records | Government, court, property, patent, licensing, corporate, archival | USPTO; U.S. National Archives; UK National Archives; state and local registries | Public / official
Directories | Business, professional, telephone, people-search, genealogy, reviews | ARIN; Avvo; 192.com; Infobel; Canada411; PagesJaunes; FamilySearch; Yelp | Public or licensed
Social & community | Profiles, posts, comments, media, public groups and channels | Facebook; LinkedIn; Instagram; TikTok; X; YouTube; Reddit; GitHub; Medium | Public-facing or authorized
Commercial data | People-search, marketing, identity, business-information providers | Provider websites and current official registries, including the California Data Broker Registry | Public, licensed, or request-only
Search & archives | Search tools, indexes, cached pages, publications, web archives | General search engines; site search; document repositories; web archives | Public / indexed
Exposure intelligence | Breach notices, leak metadata, threat research, restricted underground monitoring | Official notices; security vendors; researcher feeds; vetted intelligence providers | Public or restricted lawful access

What Deleteme does not do
We do not bypass technical access controls, defeat authentication, or use credentials obtained from a breach or stealer log.
We do not purchase stolen data, operate malware, request new intrusions, or encourage unlawful disclosure.
We do not publish direct links that would make stolen credentials, malware, or criminal services easier to obtain or misuse.
We do not certify third-party information as accurate or current, and we do not infer that a person or organization engaged in wrongdoing merely because a source mentions them.
We do not provide consumer reports. Deleteme reports may not be used to determine eligibility for employment, housing, credit, insurance, licensing, government benefits, or another purpose regulated by the Fair Credit Reporting Act or similar law.

Accuracy, availability, and source status

Internet sources change frequently. Pages may be removed, renamed, merged, blocked, archived, or taken offline. A status such as ‘online,’ ‘offline,’ ‘valid,’ or ‘expired’ is time-sensitive and should include a verification date if displayed. Deleteme may update, add, suspend, or remove sources as its services and legal obligations change.
Third-party information can be inaccurate, incomplete, misleading, duplicated, or associated with the wrong person. Reports are informational and defensive and should be independently verified before reliance.

Privacy choices and questions

For more information about the personal data Deleteme processes, the applicable purposes and legal bases, retention, international transfers, and your rights, read the Deleteme Privacy Policy and visit the Deleteme Privacy Center. Service restrictions are described in the Terms and Conditions.
Short footer version: Sources are illustrative and change over time. Inclusion does not imply affiliation, endorsement, continuous monitoring, or current availability. Cybersecurity exposure sources are used only for defensive purposes and may not be publicly linked.

Part II - Publication and compliance notes
Internal only: This section is for Deleteme’s counsel, privacy, product, security, and content owners. Do not publish it as customer-facing copy without review.

Why the taxonomy was changed
The supplied draft mixed collection methods, intelligence disciplines, platforms, and risk types. It also described breach and stealer-log material as if it were simply ‘public.’ The revised taxonomy uses five customer-readable source categories and reserves enhanced controls for cybersecurity exposure intelligence.

Original label | Recommended treatment
OSINT | Keep as a general concept only where useful; the public taxonomy describes actual source families instead of intelligence jargon.
Human Intelligence | Remove unless Deleteme truly conducts a documented, lawful human-source program. User submissions are described separately and require authority and provenance checks.
Counter Intelligence | Remove. The term is ambiguous and may imply investigative or governmental functions inconsistent with the website’s current positioning.
Internal Intelligence | Replace with ‘internal security telemetry’ only if the Privacy Policy accurately describes the data, purpose, lawful basis, retention, and recipients.
Deep/Dark Web | Retain only as a subcategory of restricted cybersecurity exposure intelligence. Do not equate it with public data or publish operational links.

Minimum publication controls
1. Confirm the page describes actual collection and product behavior. Under U.S. consumer-protection principles, privacy promises must match practice.
2. Maintain a source register with category, source name/domain, access class, purpose, data types, lawful basis, retention, owner, last verification date, and whether a direct public link is permitted.
3. For EU/EEA and UK individuals, document the lawful basis for each purpose. If relying on legitimate interests, maintain a purpose-specific assessment and a clear objection process.
4. Give Article 14-style information when data is obtained indirectly: categories of data, purposes, legal basis, recipients, retention, rights, and sufficiently precise source information. If individual notice is not provided because it is impossible or disproportionate, document that assessment and make the notice easy to find.
5. Apply additional controls to special-category data and data relating to criminal convictions or offences. Do not assume that public posting removes GDPR protection.
6. Do not scrape login-only areas, defeat CAPTCHA or other access controls, or ignore a source’s technical or contractual restrictions without specific legal approval.
7. Do not store or display usable passwords, session cookies, access tokens, financial-authentication data, malware, or other secrets. Prefer one-way matching, masking, hashing, or source-level exposure indicators where feasible.
8. Set category-specific retention periods. Raw exposure material should have the shortest justified retention and the strictest access controls.
9. Maintain suppression, correction, deletion, objection, and access workflows that propagate to relevant systems and vendors, subject to lawful exceptions.
10. Enforce product-level FCRA restrictions technically and contractually; a disclaimer alone is not sufficient if the product is actually used for regulated eligibility decisions.
11. Review state privacy, biometric, protected-address, data-broker, breach-notification, and sector laws for each relevant jurisdiction. California is an important baseline, not a complete U.S. rulebook.
12. Review intellectual-property, database-right, confidentiality, and platform-terms issues for each automated collection source.
13. Reassess international transfers and processor/vendor contracts; do not state reliance on a transfer mechanism unless the relevant entity and recipients are actually covered.

Legal-risk map
Area | Key authority | Operational implication
EU/EEA personal data | GDPR Arts. 5, 6, 12-14, 17, 21, 25, 32; Arts. 9 and 10 where applicable | Lawful basis, fairness, source transparency, minimization, rights, privacy by design, security
UK personal data | UK GDPR and Data Protection Act 2018 | Parallel UK analysis; public availability does not remove data-protection duties
California data | CCPA/CPRA; Cal. Civ. Code 1798.100 et seq.; DELETE Act where applicable | Categories of sources and purposes, proportionality, retention, rights, sensitive-data controls, broker-status review
Other U.S. states | Applicable comprehensive and sector-specific privacy laws | Jurisdiction-specific notices, rights, sensitive-data consent/limits, profiling and minors
Eligibility use | Fair Credit Reporting Act and analogous state law | Do not furnish or permit use for credit, employment, housing, insurance, licensing, or benefits unless the service is structured and operated for full compliance
System access | CFAA, state computer-crime laws, EU/UK computer-misuse rules | No unauthorized access, credential use, access-control bypass, or commissioned intrusion
Sensitive credentials | Privacy, security, identity-theft, contract, and breach laws; PADFAA may apply to covered broker transfers | No sale or operational use; strict access, masking, minimization, retention, and transfer review
Minors and vulnerable persons | COPPA where applicable; state age-appropriate/privacy laws; GDPR child protections | Age/authority checks, heightened minimization, no targeted high-risk monitoring
Content and databases | Copyright, EU database right, contract and platform terms | Source-by-source authorization and extraction limits

Recommended directory data model
For a durable website directory, publish the source taxonomy from Part I and maintain a structured register behind it. The public-facing version can expose appropriate fields while restricted fields remain internal.
Field | Visibility | Guidance
Source name | Public | Canonical service or publisher name; avoid unsupported aliases.
Domain or official page | Public when safe | Use descriptive links. Never link to credential files, malware, criminal markets, or harmful channels.
Category and source type | Public | Use one of the five categories plus a specific subtype.
Access class | Public | Freely accessible; licensed; customer-provided; archived; restricted lawful intelligence.
Region | Public | Jurisdiction or geographic coverage; do not imply comprehensive coverage.
Last verified | Public | Date availability and classification were last checked.
Purpose / product | Public summary | Explain why the source may be used; keep detailed product mapping internal.
Data categories / sensitivity | Public summary | Describe at category level; do not expose raw secrets or victim data.
Legal basis / assessment | Internal | Record controller/processor role, lawful basis, LIA/DPIA, contract, and restrictions.
Retention and safeguards | Public summary + internal detail | State the principle publicly; retain exact controls and owners internally.

Publication checklist
Legal entity/controller name and contact details confirmed.
Five-category wording matches actual source inventory and product behavior.
Privacy Policy, Terms, Privacy Center, and source-directory claims are consistent.
No unverified ‘online/offline/valid/expired’ status is published without a date.
No direct criminal-market, stealer-log, credential-file, or malware link is published.
No source is described as a data broker solely because it appeared in an old third-party list.
Article 14 source detail, rights, retention, and lawful-basis disclosures are complete for the relevant processing.
FCRA and prohibited-use controls are present in onboarding, product UI, contracts, and enforcement - not only on this page.
Accessibility, link integrity, translation, and mobile layout have been tested.
Named owner and review cadence assigned; changes are logged and archived.

Source inventories

Use the search field within each directory to narrow the available records. Tables are paginated for faster browsing.

General data-source inventory

NO.

DOMAIN / SOURCE

CATEGORY

1

facebook.com

2. Social media & user-contributed content

2

amazon.com

2. Social media & user-contributed content

3

linkedin.com

2. Social media & user-contributed content

4

instagram

2. Social media & user-contributed content

5

tiktok

2. Social media & user-contributed content

6

twitter.com

2. Social media & user-contributed content

7

groups.google.com

4. Search engines, archives & publications

8

video.google.com

2. Social media & user-contributed content

9

youtube.com

2. Social media & user-contributed content

10

home.live.com

2. Social media & user-contributed content

11

ebay.com

2. Social media & user-contributed content

12

pinterest.com

2. Social media & user-contributed content

13

imgur

2. Social media & user-contributed content

14

amazon.co.uk

1. Public internet, records & directories

15

amazon.ca

1. Public internet, records & directories

16

skype

2. Social media & user-contributed content

17

myspace.com

1. Public internet, records & directories

18

github

2. Social media & user-contributed content

19

reddit.com

2. Social media & user-contributed content

20

yelp

1. Public internet, records & directories

Data broker and commercial source inventory

NO.

COMPANY

CATEGORY

1

33 Mile Radius LLC

3. Data brokers & commercial data

2

33Across, Inc.

3. Data brokers & commercial data

3

360 Media Direct

3. Data brokers & commercial data

4

4C Insights

3. Data brokers & commercial data

5

5X5 US, LLC

3. Data brokers & commercial data

6

6Sense Insights, Inc.

3. Data brokers & commercial data

7

Accenture LLP

3. Data brokers & commercial data

8

AccuData Integrated Marketing, Inc.

3. Data brokers & commercial data

9

Accuity Inc.

3. Data brokers & commercial data

10

ACE Agents Inc.

3. Data brokers & commercial data

11

ACH, Address Clearing House

3. Data brokers & commercial data

12

Acquire Media U.S., LLC

3. Data brokers & commercial data

13

Acuant, Inc.

3. Data brokers & commercial data

14

Acxiom LLC

3. Data brokers & commercial data

15

Ad Direct Inc

3. Data brokers & commercial data

16

AdAdapted Inc.

3. Data brokers & commercial data

17

Adrea Rubin Marketing, Inc.

3. Data brokers & commercial data

18

Adrea Rubin Media (Calibrant Digital)

3. Data brokers & commercial data

19

adsquare GmbH

3. Data brokers & commercial data

20

Adstra LLC

3. Data brokers & commercial data

Search-engine inventory

ROW

NAME

SUPPLIED STATUS

1

Abiko

ONLINE

2

Ahmia

ONLINE

3

Amnesia

ONLINE

4

Bobby

ONLINE

5

DANEX

ONLINE

6

Dark Tor

OFFLINE

7

DarkSearch

ONLINE

8

DarkSide

ONLINE

9

Deep Search

ONLINE

10

Demon

ONLINE

11

Evo Search

ONLINE

12

Excavator

OFFLINE

13

FYO

ONLINE

14

FindTor

ONLINE

15

Fresh onions

ONLINE

16

GDark

ONLINE

17

Haystak

ONLINE

18

Hidden Links

ONLINE

19

Hidden Reviews

ONLINE

20

Hologram

ONLINE

Social media, researcher, market, and group inventory

ROW

SUPPLIED LINK / NAME

CATEGORY

1

https://github.com/0xDanielLopez/

2. Social media & user-contributed content

2

https://twitter.com/altoufanteam

2. Social media & user-contributed content

3

https://twitter.com/Arkbird_SOLG

2. Social media & user-contributed content

4

https://twitter.com/crep1x

2. Social media & user-contributed content

5

https://twitter.com/Cryptolaemus1

2. Social media & user-contributed content

6

https://twitter.com/Cyberknow20

2. Social media & user-contributed content

7

https://twitter.com/ecarlesi

2. Social media & user-contributed content

8

https://twitter.com/EmotetB

2. Social media & user-contributed content

9

https://twitter.com/executemalware

2. Social media & user-contributed content

10

https://twitter.com/htmalgae

2. Social media & user-contributed content

11

https://twitter.com/JAMESWT_MHT

2. Social media & user-contributed content

12

https://twitter.com/mojoesec

2. Social media & user-contributed content

13

https://twitter.com/PhishStats

2. Social media & user-contributed content

14

https://twitter.com/powershellcode

2. Social media & user-contributed content

15

https://twitter.com/pr0xylife

2. Social media & user-contributed content

16

https://twitter.com/TMRansomMonitor

2. Social media & user-contributed content

17

https://twitter.com/RdpSnitch

2. Social media & user-contributed content

18

https://twitter.com/reecdeep

2. Social media & user-contributed content

19

https://twitter.com/shadowchasing1

2. Social media & user-contributed content

20

https://twitter.com/thedfirreport

2. Social media & user-contributed content

Stealer-log and credential exposure inventory

ROW

DEFANGED SOURCE REFERENCE

STATUS

1

hxxps://t[.]me/+8DxOrHQdrzw1ZjUy

VALID

2

hxxps://t[.]me/+fcxhFl9JSRE3YTdi

VALID

3

hxxps://t[.]me/+NshXlCbUEZkxZDMy

EXPIRED

4

hxxps://t[.]me/+OZheKtZ368YxMDBl

VALID

5

hxxps://t[.]me/+V_oM-vx0YnSN7nzH

VALID

6

hxxps://t[.]me/banklogplug2

OFFLINE

7

hxxps://t[.]me/berserklogs

ONLINE

8

hxxps://t[.]me/BorwitaFreeLogs

ONLINE

9

hxxps://t[.]me/bradmax_cloud

ONLINE

10

hxxps://t[.]me/cbanke_logs

ONLINE

11

hxxps://t[.]me/CloudLogsPrivate

OFFLINE

12

hxxps://t[.]me/cloudlogs

ONLINE

13

hxxps://t[.]me/cloudmika

ONLINE

14

hxxps://t[.]me/Creditunionbanksstore

ONLINE

15

hxxps://t[.]me/CyberSecurityTechnologies

ONLINE

16

hxxps://t[.]me/database_leak

ONLINE

17

hxxps://t[.]me/eliteband

OFFLINE

18

hxxps://t[.]me/expertsa11m

ONLINE

19

hxxps://t[.]me/expertsa11m

ONLINE

20

hxxps://t[.]me/fatecloud

ONLINE

Appendix A - Review of supplied inventories

Complete preservation with publication controls: Appendix C preserves all supplied records, categories, duplicates, and status labels. Because the inventories contain stale or malformed domains, historic registry snapshots, and criminal or credential-exposure references, the appendix must be reviewed before public release. High-risk links are retained in defanged form.

File

Observed scale

Main issues

Recommended disposition

Data Sources.docx | 160 listed sources | General web, social, directories, government records, reviews, archives; several obsolete or incomplete domains | All rows preserved in Appendix C. Validate and annotate records before activating them in a production directory.

Data-Brokers-USA-Europe.docx | 468 numbered rows; document states 441 unique | U.S. registry-derived and Europe-compiled company list; duplicates and historic entries acknowledged | Do not claim all are current data brokers. Revalidate against official registries and company records before publishing a dated directory.

search engines.docx | 60 named services | Primarily specialized deep/dark-web search tools with undated online/offline status | Use category-level wording publicly. Publish a name/status only after safety and legal review and dated verification.

social media.docx | 23 public links plus 6 named market/group entries | Security researchers, monitoring feeds, social accounts, and expired underground-source names | Use platform/source-family examples publicly. Verify individual accounts; keep underground-source identifiers restricted.

Stealer Logs.docx | 676 URL rows; 655 unique URLs | Telegram channels/groups and other threat sources, many carrying credentials, logs, breach claims, malware, DDoS, or market content | All rows preserved in Appendix C with duplicates and original order retained; URLs are defanged. Restrict operational use and never expose raw secrets.

Recommended migration path
1. Preserve the original files as dated internal source material; do not overwrite them.
2. Create a normalized master register with stable identifiers and duplicate detection.
3. Separate public directory entries from restricted cyber-intelligence sources.
4. Run legal, privacy, security, and source-owner review before activation.
5. Verify public names, domains, status, jurisdiction, and request links on a documented schedule.
6. Publish the category-level page first; add searchable source-level entries only when the register is ready.

Appendix B - Authoritative references

Reviewed 17 August 2026. These are official or primary sources used to frame the draft. They are not a substitute for jurisdiction-specific legal advice.

1. EU General Data Protection Regulation (GDPR), consolidated text - Core principles, legal bases, indirect-collection transparency, special categories, rights, privacy by design, security, and transfers.
2. EDPB Guidelines 03/2026 on web scraping in the context of generative AI - AI-focused but useful on source transparency, public/non-public distinctions, source lists, minimization, access controls, and rights safeguards.
3. EDPB Guidelines 4/2019 on Article 25 data protection by design and by default - Design and default controls.
4. California Consumer Privacy Act, Civil Code 1798.100 et seq. - Notice, source categories, proportionality, retention, deletion/correction/opt-out rights, sensitive data, and the statutory meaning of publicly available.
5. California Privacy Protection Agency - Data Broker Registry - Current and prior registration information; registry status changes over time.
6. California Privacy Protection Agency - Information for Data Brokers / DROP - DELETE Act registration and deletion-platform obligations where applicable.
7. Federal Trade Commission - Credit Reporting - FCRA responsibilities and regulated eligibility uses.
8. Federal Trade Commission - Privacy and Security - Privacy promises, data security, children’s privacy, sector rules, and cross-border framework information.
9. Federal Trade Commission - Start with Security - Minimize collection and retention; restrict access; secure sensitive data.
10. U.S. Department of Justice - Computer Fraud and Abuse Act - Unauthorized computer access risk.
11. Deleteme Privacy Policy - Current public promises used for consistency review.
12. Deleteme Terms and Conditions - Current service scope, authority, prohibited uses, FCRA restriction, and customer obligations.

Final legal note: No website text can guarantee compliance. Lawfulness depends on the facts: who controls the processing, what is collected, how access occurs, the purpose and legal basis, the people affected, retention, security, recipients, transfers, user controls, and whether public statements accurately describe the service.

Appendix C - Complete supplied source register

Completeness statement: This appendix contains all 1,393 source records supplied across the five attachments. Original order, repeated entries, source labels, and status values are preserved. Categorization adds structure but does not remove or silently consolidate any record.

High-risk references: References associated with stealer logs, credentials, malware, criminal markets, or underground channels are retained but defanged (for example, hxxps and [.] notation). Defanging is a safety control, not deletion. Statuses are reproduced as supplied and were not independently verified for this appendix.

Supplied file | Records | Treatment

Data Sources.docx | 160 | Rows retained and assigned to one of the five categories.

Data-Brokers-USA-Europe.docx | 468 | Every numbered row retained, including duplicates.

search engines.docx | 60 | Every named service and supplied status retained.

social media.docx | 29 | 23 public-link rows and 6 market/group rows retained.

Stealer Logs.docx | 676 | Every URL row retained in original order; 655 are unique.

Total | 1,393 | No supplied source record removed.