DATA SOURCES DIRECTORY
Data Sources
Deleteme helps customers understand where their personal information may be exposed online. When a customer requests a search, we may look across a broad range of lawful sources to identify relevant records, profiles, listings, publications, and signs of cybersecurity exposure.
The source directory below explains the main categories we may consult. The examples are illustrative, not exhaustive. A source’s inclusion does not mean that it is searched for every request, that it is currently available, or that Deleteme is affiliated with or endorses the source.
Important: Information that can be found online is not automatically free of privacy, confidentiality, copyright, contractual, or security restrictions. Deleteme applies access, purpose, minimization, and security controls according to the source and the requested service.
How searches work
Customer-directed. Searches are initiated in response to a customer request and the search details the customer provides.
Purpose-limited. Sources are consulted only as reasonably necessary to provide the requested privacy, exposure, monitoring, or removal service.
Source-aware. We distinguish freely accessible public sources, licensed sources, customer-provided information, archived material, and restricted cybersecurity intelligence.
Defensive. Cybersecurity exposure data is used to help identify and explain potential risk. It is not used to access accounts, test credentials, enable fraud, or facilitate harmful activity.
Human-reviewable. Source information can be incomplete, stale, duplicated, or wrong. Material findings should be independently verified before action is taken.
Our five source categories
1. Public internet, records, and directories
This category includes information that is lawfully available through public websites, government and court portals, official registers, public notices, business and professional directories, telephone directories, review sites, open publications, and similar repositories.
We may use these sources to locate records connected to the search details supplied by the customer, identify the originating publisher, assess whether a correction or removal path is available, and provide a source reference in a report.
Representative source families include: government, court, property, patent, corporate, licensing, and archival records; business, professional, telephone, address, people-search, genealogy, and obituary directories; news sites, blogs, public documents, discussion pages, review platforms, and media repositories; and public-facing e-commerce, marketplace, community, and profile pages.
Safeguard: Public availability is assessed in context. Deleteme does not treat restricted, sealed, suppressed, non-public, or access-controlled records as public merely because a copy may exist online.
2. Social media and user-contributed content
This category includes public profiles, posts, comments, media, public groups, public channels, contributor pages, and other content made available through social or community platforms. It can also include information a customer submits directly to Deleteme for an authorized request.
We may use these sources to identify exposed identifiers, impersonation or unwanted profile visibility, duplicated public information, and potential removal or privacy-setting options.
Examples include public-facing content on professional networks, social networks, video and image platforms, code-hosting services, discussion communities, creator platforms, and public messaging channels.
Safeguard: We do not characterize content from a private account, closed group, or login-only area as public. Access must be authorized and consistent with applicable law and platform rules.
3. Data brokers and commercial data sources
This category includes people-search services, marketing and identity-data providers, business-information services, credit-reference and directory providers, and other commercial sources that compile information from multiple origins. Depending on the service, a source may be publicly searchable, available under a license, or consulted only to support an opt-out or removal request.
Deleteme may use official data-broker registries and the providers’ own websites to identify relevant services, confirm request procedures, and help customers exercise applicable privacy rights.
Safeguard: A company’s appearance in a directory or historic registry does not prove that it currently operates as a data broker or holds information about a particular person. Status, ownership, jurisdiction, and request method should be verified at the time of use.
4. Search engines, web archives, and publications
This category includes general and specialized search tools, site-search tools, open indexes, cached or archived pages, document repositories, news and publication databases, and web archives. Archived material may remain discoverable even after the original page has changed or is no longer available.
We may use these sources to discover the location and history of a relevant page, confirm that a result is still accessible, identify duplicates, and locate the publisher or removal route.
Safeguard: Search results, snippets, cache entries, and archive captures may be outdated or incomplete. Deleteme identifies the underlying source where reasonably possible and does not present an archived copy as proof that information remains live on the original website.
5. Cybersecurity exposure intelligence
This category includes breach notifications, leak reporting, credential-exposure indicators, stealer-log indicators, ransomware and extortion reporting, public security-research feeds, malware and phishing intelligence, underground-forum monitoring, and relevant deep-web or dark-web intelligence obtained from lawful sources.
This material may indicate that an email address, username, password-related record, device identifier, session token, or other personal or organizational information was exposed. Dates may refer to discovery, publication, indexing, infection, upload, or collection and may not establish when the underlying compromise occurred.
For safety and legal reasons, Deleteme may identify the source category or service without publishing a direct link to a criminal forum, market, channel, credential file, malware sample, or other harmful location.
Safeguard: Deleteme does not deploy malware, buy stolen credentials, test exposed passwords, use session cookies, access a person’s account, or republish raw credential material. Exposure intelligence is handled for defensive privacy and security purposes with restricted access and appropriate retention controls.
Source directory overview
The following overview summarizes the source families found in the supplied inventories. Appendix C preserves every supplied source record. Inclusion is not a claim that every listed service is continuously monitored, lawful for every use, or currently available.
Category | Includes | Representative examples | Access class
Public records | Government, court, property, patent, licensing, corporate, archival | USPTO; U.S. National Archives; UK National Archives; state and local registries | Public / official
Directories | Business, professional, telephone, people-search, genealogy, reviews | ARIN; Avvo; 192.com; Infobel; Canada411; PagesJaunes; FamilySearch; Yelp | Public or licensed
Social & community | Profiles, posts, comments, media, public groups and channels | Facebook; LinkedIn; Instagram; TikTok; X; YouTube; Reddit; GitHub; Medium | Public-facing or authorized
Commercial data | People-search, marketing, identity, business-information providers | Provider websites and current official registries, including the California Data Broker Registry | Public, licensed, or request-only
Search & archives | Search tools, indexes, cached pages, publications, web archives | General search engines; site search; document repositories; web archives | Public / indexed
Exposure intelligence | Breach notices, leak metadata, threat research, restricted underground monitoring | Official notices; security vendors; researcher feeds; vetted intelligence providers | Public or restricted lawful access
What Deleteme does not do
We do not bypass technical access controls, defeat authentication, or use credentials obtained from a breach or stealer log.
We do not purchase stolen data, operate malware, request new intrusions, or encourage unlawful disclosure.
We do not publish direct links that would make stolen credentials, malware, or criminal services easier to obtain or misuse.
We do not certify third-party information as accurate or current, and we do not infer that a person or organization engaged in wrongdoing merely because a source mentions them.
We do not provide consumer reports. Deleteme reports may not be used to determine eligibility for employment, housing, credit, insurance, licensing, government benefits, or another purpose regulated by the Fair Credit Reporting Act or similar law.
Accuracy, availability, and source status
Internet sources change frequently. Pages may be removed, renamed, merged, blocked, archived, or taken offline. A status such as ‘online,’ ‘offline,’ ‘valid,’ or ‘expired’ is time-sensitive and should include a verification date if displayed. Deleteme may update, add, suspend, or remove sources as its services and legal obligations change.
Third-party information can be inaccurate, incomplete, misleading, duplicated, or associated with the wrong person. Reports are informational and defensive and should be independently verified before reliance.
Privacy choices and questions
For more information about the personal data Deleteme processes, the applicable purposes and legal bases, retention, international transfers, and your rights, read the Deleteme Privacy Policy and visit the Deleteme Privacy Center. Service restrictions are described in the Terms and Conditions.
Short footer version: Sources are illustrative and change over time. Inclusion does not imply affiliation, endorsement, continuous monitoring, or current availability. Cybersecurity exposure sources are used only for defensive purposes and may not be publicly linked.
Part II - Publication and compliance notes
Internal only: This section is for Deleteme’s counsel, privacy, product, security, and content owners. Do not publish it as customer-facing copy without review.
Why the taxonomy was changed
The supplied draft mixed collection methods, intelligence disciplines, platforms, and risk types. It also described breach and stealer-log material as if it were simply ‘public.’ The revised taxonomy uses five customer-readable source categories and reserves enhanced controls for cybersecurity exposure intelligence.
Original label | Recommended treatment
OSINT | Keep as a general concept only where useful; the public taxonomy describes actual source families instead of intelligence jargon.
Human Intelligence | Remove unless Deleteme truly conducts a documented, lawful human-source program. User submissions are described separately and require authority and provenance checks.
Counter Intelligence | Remove. The term is ambiguous and may imply investigative or governmental functions inconsistent with the website’s current positioning.
Internal Intelligence | Replace with ‘internal security telemetry’ only if the Privacy Policy accurately describes the data, purpose, lawful basis, retention, and recipients.
Deep/Dark Web | Retain only as a subcategory of restricted cybersecurity exposure intelligence. Do not equate it with public data or publish operational links.
Minimum publication controls
1. Confirm the page describes actual collection and product behavior. Under U.S. consumer-protection principles, privacy promises must match practice.
2. Maintain a source register with category, source name/domain, access class, purpose, data types, lawful basis, retention, owner, last verification date, and whether a direct public link is permitted.
3. For EU/EEA and UK individuals, document the lawful basis for each purpose. If relying on legitimate interests, maintain a purpose-specific assessment and a clear objection process.
4. Give Article 14-style information when data is obtained indirectly: categories of data, purposes, legal basis, recipients, retention, rights, and sufficiently precise source information. If individual notice is not provided because it is impossible or disproportionate, document that assessment and make the notice easy to find.
5. Apply additional controls to special-category data and data relating to criminal convictions or offences. Do not assume that public posting removes GDPR protection.
6. Do not scrape login-only areas, defeat CAPTCHA or other access controls, or ignore a source’s technical or contractual restrictions without specific legal approval.
7. Do not store or display usable passwords, session cookies, access tokens, financial-authentication data, malware, or other secrets. Prefer one-way matching, masking, hashing, or source-level exposure indicators where feasible.
8. Set category-specific retention periods. Raw exposure material should have the shortest justified retention and the strictest access controls.
9. Maintain suppression, correction, deletion, objection, and access workflows that propagate to relevant systems and vendors, subject to lawful exceptions.
10. Enforce product-level FCRA restrictions technically and contractually; a disclaimer alone is not sufficient if the product is actually used for regulated eligibility decisions.
11. Review state privacy, biometric, protected-address, data-broker, breach-notification, and sector laws for each relevant jurisdiction. California is an important baseline, not a complete U.S. rulebook.
12. Review intellectual-property, database-right, confidentiality, and platform-terms issues for each automated collection source.
13. Reassess international transfers and processor/vendor contracts; do not state reliance on a transfer mechanism unless the relevant entity and recipients are actually covered.
Legal-risk map
Area | Key authority | Operational implication
EU/EEA personal data | GDPR Arts. 5, 6, 12-14, 17, 21, 25, 32; Arts. 9 and 10 where applicable | Lawful basis, fairness, source transparency, minimization, rights, privacy by design, security
UK personal data | UK GDPR and Data Protection Act 2018 | Parallel UK analysis; public availability does not remove data-protection duties
California data | CCPA/CPRA; Cal. Civ. Code 1798.100 et seq.; DELETE Act where applicable | Categories of sources and purposes, proportionality, retention, rights, sensitive-data controls, broker-status review
Other U.S. states | Applicable comprehensive and sector-specific privacy laws | Jurisdiction-specific notices, rights, sensitive-data consent/limits, profiling and minors
Eligibility use | Fair Credit Reporting Act and analogous state law | Do not furnish or permit use for credit, employment, housing, insurance, licensing, or benefits unless the service is structured and operated for full compliance
System access | CFAA, state computer-crime laws, EU/UK computer-misuse rules | No unauthorized access, credential use, access-control bypass, or commissioned intrusion
Sensitive credentials | Privacy, security, identity-theft, contract, and breach laws; PADFAA may apply to covered broker transfers | No sale or operational use; strict access, masking, minimization, retention, and transfer review
Minors and vulnerable persons | COPPA where applicable; state age-appropriate/privacy laws; GDPR child protections | Age/authority checks, heightened minimization, no targeted high-risk monitoring
Content and databases | Copyright, EU database right, contract and platform terms | Source-by-source authorization and extraction limits
Recommended directory data model
For a durable website directory, publish the source taxonomy from Part I and maintain a structured register behind it. The public-facing version can expose appropriate fields while restricted fields remain internal.
Field | Visibility | Guidance
Source name | Public | Canonical service or publisher name; avoid unsupported aliases.
Domain or official page | Public when safe | Use descriptive links. Never link to credential files, malware, criminal markets, or harmful channels.
Category and source type | Public | Use one of the five categories plus a specific subtype.
Access class | Public | Freely accessible; licensed; customer-provided; archived; restricted lawful intelligence.
Region | Public | Jurisdiction or geographic coverage; do not imply comprehensive coverage.
Last verified | Public | Date availability and classification were last checked.
Purpose / product | Public summary | Explain why the source may be used; keep detailed product mapping internal.
Data categories / sensitivity | Public summary | Describe at category level; do not expose raw secrets or victim data.
Legal basis / assessment | Internal | Record controller/processor role, lawful basis, LIA/DPIA, contract, and restrictions.
Retention and safeguards | Public summary + internal detail | State the principle publicly; retain exact controls and owners internally.
Publication checklist
Legal entity/controller name and contact details confirmed.
Five-category wording matches actual source inventory and product behavior.
Privacy Policy, Terms, Privacy Center, and source-directory claims are consistent.
No unverified ‘online/offline/valid/expired’ status is published without a date.
No direct criminal-market, stealer-log, credential-file, or malware link is published.
No source is described as a data broker solely because it appeared in an old third-party list.
Article 14 source detail, rights, retention, and lawful-basis disclosures are complete for the relevant processing.
FCRA and prohibited-use controls are present in onboarding, product UI, contracts, and enforcement - not only on this page.
Accessibility, link integrity, translation, and mobile layout have been tested.
Named owner and review cadence assigned; changes are logged and archived.
Source inventories
Use the search field within each directory to narrow the available records. Tables are paginated for faster browsing.
General data-source inventory
NO.
DOMAIN / SOURCE
CATEGORY
1
facebook.com
2. Social media & user-contributed content
2
amazon.com
2. Social media & user-contributed content
3
linkedin.com
2. Social media & user-contributed content
4
2. Social media & user-contributed content
5
tiktok
2. Social media & user-contributed content
6
twitter.com
2. Social media & user-contributed content
7
groups.google.com
4. Search engines, archives & publications
8
video.google.com
2. Social media & user-contributed content
9
youtube.com
2. Social media & user-contributed content
10
home.live.com
2. Social media & user-contributed content
11
ebay.com
2. Social media & user-contributed content
12
pinterest.com
2. Social media & user-contributed content
13
imgur
2. Social media & user-contributed content
14
amazon.co.uk
1. Public internet, records & directories
15
amazon.ca
1. Public internet, records & directories
16
skype
2. Social media & user-contributed content
17
myspace.com
1. Public internet, records & directories
18
github
2. Social media & user-contributed content
19
reddit.com
2. Social media & user-contributed content
20
yelp
1. Public internet, records & directories
Data broker and commercial source inventory
NO.
COMPANY
CATEGORY
1
33 Mile Radius LLC
3. Data brokers & commercial data
2
33Across, Inc.
3. Data brokers & commercial data
3
360 Media Direct
3. Data brokers & commercial data
4
4C Insights
3. Data brokers & commercial data
5
5X5 US, LLC
3. Data brokers & commercial data
6
6Sense Insights, Inc.
3. Data brokers & commercial data
7
Accenture LLP
3. Data brokers & commercial data
8
AccuData Integrated Marketing, Inc.
3. Data brokers & commercial data
9
Accuity Inc.
3. Data brokers & commercial data
10
ACE Agents Inc.
3. Data brokers & commercial data
11
ACH, Address Clearing House
3. Data brokers & commercial data
12
Acquire Media U.S., LLC
3. Data brokers & commercial data
13
Acuant, Inc.
3. Data brokers & commercial data
14
Acxiom LLC
3. Data brokers & commercial data
15
Ad Direct Inc
3. Data brokers & commercial data
16
AdAdapted Inc.
3. Data brokers & commercial data
17
Adrea Rubin Marketing, Inc.
3. Data brokers & commercial data
18
Adrea Rubin Media (Calibrant Digital)
3. Data brokers & commercial data
19
adsquare GmbH
3. Data brokers & commercial data
20
Adstra LLC
3. Data brokers & commercial data
Search-engine inventory
ROW
NAME
SUPPLIED STATUS
1
Abiko
ONLINE
2
Ahmia
ONLINE
3
Amnesia
ONLINE
4
Bobby
ONLINE
5
DANEX
ONLINE
6
Dark Tor
OFFLINE
7
DarkSearch
ONLINE
8
DarkSide
ONLINE
9
Deep Search
ONLINE
10
Demon
ONLINE
11
Evo Search
ONLINE
12
Excavator
OFFLINE
13
FYO
ONLINE
14
FindTor
ONLINE
15
Fresh onions
ONLINE
16
GDark
ONLINE
17
Haystak
ONLINE
18
Hidden Links
ONLINE
19
Hidden Reviews
ONLINE
20
Hologram
ONLINE
Social media, researcher, market, and group inventory
ROW
SUPPLIED LINK / NAME
CATEGORY
1
https://github.com/0xDanielLopez/
2. Social media & user-contributed content
2
https://twitter.com/altoufanteam
2. Social media & user-contributed content
3
https://twitter.com/Arkbird_SOLG
2. Social media & user-contributed content
4
https://twitter.com/crep1x
2. Social media & user-contributed content
5
https://twitter.com/Cryptolaemus1
2. Social media & user-contributed content
6
https://twitter.com/Cyberknow20
2. Social media & user-contributed content
7
https://twitter.com/ecarlesi
2. Social media & user-contributed content
8
https://twitter.com/EmotetB
2. Social media & user-contributed content
9
https://twitter.com/executemalware
2. Social media & user-contributed content
10
https://twitter.com/htmalgae
2. Social media & user-contributed content
11
https://twitter.com/JAMESWT_MHT
2. Social media & user-contributed content
12
https://twitter.com/mojoesec
2. Social media & user-contributed content
13
https://twitter.com/PhishStats
2. Social media & user-contributed content
14
https://twitter.com/powershellcode
2. Social media & user-contributed content
15
https://twitter.com/pr0xylife
2. Social media & user-contributed content
16
https://twitter.com/TMRansomMonitor
2. Social media & user-contributed content
17
https://twitter.com/RdpSnitch
2. Social media & user-contributed content
18
https://twitter.com/reecdeep
2. Social media & user-contributed content
19
https://twitter.com/shadowchasing1
2. Social media & user-contributed content
20
https://twitter.com/thedfirreport
2. Social media & user-contributed content
Stealer-log and credential exposure inventory
ROW
DEFANGED SOURCE REFERENCE
STATUS
1
hxxps://t[.]me/+8DxOrHQdrzw1ZjUy
VALID
2
hxxps://t[.]me/+fcxhFl9JSRE3YTdi
VALID
3
hxxps://t[.]me/+NshXlCbUEZkxZDMy
EXPIRED
4
hxxps://t[.]me/+OZheKtZ368YxMDBl
VALID
5
hxxps://t[.]me/+V_oM-vx0YnSN7nzH
VALID
6
hxxps://t[.]me/banklogplug2
OFFLINE
7
hxxps://t[.]me/berserklogs
ONLINE
8
hxxps://t[.]me/BorwitaFreeLogs
ONLINE
9
hxxps://t[.]me/bradmax_cloud
ONLINE
10
hxxps://t[.]me/cbanke_logs
ONLINE
11
hxxps://t[.]me/CloudLogsPrivate
OFFLINE
12
hxxps://t[.]me/cloudlogs
ONLINE
13
hxxps://t[.]me/cloudmika
ONLINE
14
hxxps://t[.]me/Creditunionbanksstore
ONLINE
15
hxxps://t[.]me/CyberSecurityTechnologies
ONLINE
16
hxxps://t[.]me/database_leak
ONLINE
17
hxxps://t[.]me/eliteband
OFFLINE
18
hxxps://t[.]me/expertsa11m
ONLINE
19
hxxps://t[.]me/expertsa11m
ONLINE
20
hxxps://t[.]me/fatecloud
ONLINE
Appendix A - Review of supplied inventories
Complete preservation with publication controls: Appendix C preserves all supplied records, categories, duplicates, and status labels. Because the inventories contain stale or malformed domains, historic registry snapshots, and criminal or credential-exposure references, the appendix must be reviewed before public release. High-risk links are retained in defanged form.
File
Observed scale
Main issues
Recommended disposition
Data Sources.docx | 160 listed sources | General web, social, directories, government records, reviews, archives; several obsolete or incomplete domains | All rows preserved in Appendix C. Validate and annotate records before activating them in a production directory.
Data-Brokers-USA-Europe.docx | 468 numbered rows; document states 441 unique | U.S. registry-derived and Europe-compiled company list; duplicates and historic entries acknowledged | Do not claim all are current data brokers. Revalidate against official registries and company records before publishing a dated directory.
search engines.docx | 60 named services | Primarily specialized deep/dark-web search tools with undated online/offline status | Use category-level wording publicly. Publish a name/status only after safety and legal review and dated verification.
social media.docx | 23 public links plus 6 named market/group entries | Security researchers, monitoring feeds, social accounts, and expired underground-source names | Use platform/source-family examples publicly. Verify individual accounts; keep underground-source identifiers restricted.
Stealer Logs.docx | 676 URL rows; 655 unique URLs | Telegram channels/groups and other threat sources, many carrying credentials, logs, breach claims, malware, DDoS, or market content | All rows preserved in Appendix C with duplicates and original order retained; URLs are defanged. Restrict operational use and never expose raw secrets.
Recommended migration path
1. Preserve the original files as dated internal source material; do not overwrite them.
2. Create a normalized master register with stable identifiers and duplicate detection.
3. Separate public directory entries from restricted cyber-intelligence sources.
4. Run legal, privacy, security, and source-owner review before activation.
5. Verify public names, domains, status, jurisdiction, and request links on a documented schedule.
6. Publish the category-level page first; add searchable source-level entries only when the register is ready.
Appendix B - Authoritative references
Reviewed 17 August 2026. These are official or primary sources used to frame the draft. They are not a substitute for jurisdiction-specific legal advice.
1. EU General Data Protection Regulation (GDPR), consolidated text - Core principles, legal bases, indirect-collection transparency, special categories, rights, privacy by design, security, and transfers.
2. EDPB Guidelines 03/2026 on web scraping in the context of generative AI - AI-focused but useful on source transparency, public/non-public distinctions, source lists, minimization, access controls, and rights safeguards.
3. EDPB Guidelines 4/2019 on Article 25 data protection by design and by default - Design and default controls.
4. California Consumer Privacy Act, Civil Code 1798.100 et seq. - Notice, source categories, proportionality, retention, deletion/correction/opt-out rights, sensitive data, and the statutory meaning of publicly available.
5. California Privacy Protection Agency - Data Broker Registry - Current and prior registration information; registry status changes over time.
6. California Privacy Protection Agency - Information for Data Brokers / DROP - DELETE Act registration and deletion-platform obligations where applicable.
7. Federal Trade Commission - Credit Reporting - FCRA responsibilities and regulated eligibility uses.
8. Federal Trade Commission - Privacy and Security - Privacy promises, data security, children’s privacy, sector rules, and cross-border framework information.
9. Federal Trade Commission - Start with Security - Minimize collection and retention; restrict access; secure sensitive data.
10. U.S. Department of Justice - Computer Fraud and Abuse Act - Unauthorized computer access risk.
11. Deleteme Privacy Policy - Current public promises used for consistency review.
12. Deleteme Terms and Conditions - Current service scope, authority, prohibited uses, FCRA restriction, and customer obligations.
Final legal note: No website text can guarantee compliance. Lawfulness depends on the facts: who controls the processing, what is collected, how access occurs, the purpose and legal basis, the people affected, retention, security, recipients, transfers, user controls, and whether public statements accurately describe the service.
Appendix C - Complete supplied source register
Completeness statement: This appendix contains all 1,393 source records supplied across the five attachments. Original order, repeated entries, source labels, and status values are preserved. Categorization adds structure but does not remove or silently consolidate any record.
High-risk references: References associated with stealer logs, credentials, malware, criminal markets, or underground channels are retained but defanged (for example, hxxps and [.] notation). Defanging is a safety control, not deletion. Statuses are reproduced as supplied and were not independently verified for this appendix.
Supplied file | Records | Treatment
Data Sources.docx | 160 | Rows retained and assigned to one of the five categories.
Data-Brokers-USA-Europe.docx | 468 | Every numbered row retained, including duplicates.
search engines.docx | 60 | Every named service and supplied status retained.
social media.docx | 29 | 23 public-link rows and 6 market/group rows retained.
Stealer Logs.docx | 676 | Every URL row retained in original order; 655 are unique.
Total | 1,393 | No supplied source record removed.