Privacy Policy

Effective date: 2026-08-28

This Privacy Policy describes how LetMeCreep, LLC (organizing in Delaware) (“LetMeCreep,” “we,” “us”) collects, uses, retains, and discloses personal information in connection with letmecreep.app (the “Service”). It is written in plain English on purpose. If a term of art like “GDPR” or “CCPA” is needed, we use it and explain what it means for you.

1. What We Collect

We collect three categories of information:

  • Account data. Email address, an argon2-hashed password, OAuth identifiers if you sign in with a third-party provider, WebAuthn passkey public keys, display name, and account preferences.
  • Usage data. The phone numbers you look up, the timestamps and content of resulting snapshots, credit balance and consumption history, API keys and API-call metadata, IP addresses, user-agent strings, request headers used for abuse mitigation, and Cloudflare Turnstile challenge results.
  • Payment data. Payment-processor tokens, transaction identifiers, purchase amount, currency, and last-four digits of the card or a truncated PayPal identifier as returned by the processor. We do not receive or store your full card number, CVV, bank account number, or PayPal password.

2. How We Use It

  • To operate the Service, run lookups, and deliver snapshots.
  • To authenticate you, meter credits, and reconcile payments.
  • To detect, investigate, and prevent fraud, abuse, and AUP violations.
  • To comply with legal obligations and respond to lawful requests.
  • To generate aggregated, non-identifying analytics about how the Service is used.
  • To communicate with you about account, security, and material policy changes.

3. The Snapshot Archive Doctrine

Every lookup produces a permanent, timestamped snapshot that we retain indefinitely. This is a deliberate product feature: snapshots are meant to be an evidentiary record of what a set of public sources said about a phone number at a specific moment in time. Investigators, journalists, and security teams rely on that immutability.

By using the Service you consent to the creation and indefinite retention of snapshots derived from your queries. Snapshots are attributed to the account that created them and are visible to that account, our operations personnel with a need to know, and (where required) to law enforcement responding to lawful process.

The relationship between this archive and your right to erasure is described in Section 6.

4. Third-Party Processors and Sources

We share limited data with the following third parties, each for a specific purpose:

  • Stripe. Payment processing. Receives your name, email, card details entered on the payment form, IP, and transaction metadata.
  • PayPal. Alternate payment processing. Receives the transaction request and returns a completion status and identifier.
  • Cloudflare Turnstile. Bot-mitigation challenge. Receives your IP, user-agent, and challenge-solution data.
  • Data providers. A curated set of licensed and public data providers receive the phone number you queried (or a derived search string) so we can return carrier metadata, breach-exposure information, and public web/social/code references. We do not disclose the identities of these providers publicly. Each operates under its own privacy terms and is subject to a data-processing agreement with us where required.
  • Hosting and email infrastructure providers. Process account and log data solely to deliver the Service.

Each third party is a separate controller or processor as defined by applicable law and operates under its own privacy terms. We do not sell your personal information to any of them.

5. Cookies

We use a single first-party session cookie required to keep you signed in. We do not use third-party advertising cookies, cross-site tracking pixels, or behavioral-advertising trackers.

6. Your Data-Subject Rights

Depending on where you live, you may have some or all of the following rights with respect to your personal information. Requests can be made to support@letmecreep.appand are processed within 30 days. We will verify the requester before acting on any request.

  • Access. A copy of the personal information we hold about you.
  • Rectification. Correction of inaccurate personal information.
  • Portability. Your account data in a structured, machine-readable format.
  • Erasure. Deletion of your account and your personal information. Because snapshots are part of our archival record and are relied on by others, an erasure request soft-deletes your account and rewrites all snapshot attribution to a “deleted user” tombstone. Anonymized snapshot content itself may be retained as a legitimate business and evidentiary record. This is disclosed prominently so you can decide whether the Service’s archive model is compatible with your privacy preferences before you use it.
  • Opt-out of sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). There is nothing for you to opt out of.
  • Non-discrimination. We will not deny service, charge a different price, or provide a different quality of service because you exercised a data-subject right.

7. Data Retention

  • Account data: retained until you delete your account.
  • Snapshots: retained indefinitely as an archival record (see Section 3).
  • Payment records and audit logs: retained for seven (7) years to satisfy tax, accounting, and fraud-investigation obligations.
  • Erasure requests: processed within 30 days of verification.
  • Abuse-related records: retained as long as necessary to protect the Service and other users, and to respond to lawful process.

8. International Transfers

We are organizing in Delaware and process data in the United States. If you access the Service from outside the United States, your personal information will be transferred to, stored, and processed in the U.S. Where transfers of European Economic Area, United Kingdom, or Swiss personal data are involved, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) as the transfer mechanism.

9. Children

The Service is for adults. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it and terminate the account. Underage account holders forfeit any remaining credits without refund.

10. California Residents (CCPA / CPRA)

California residents have the rights described in Section 6, including the right to know, right to delete, right to correct, right to opt out of sale or sharing, and right to limit the use of sensitive personal information. As noted, we do not sell or share personal information as those terms are defined by CCPA/CPRA. We do not process sensitive personal information for the purpose of inferring characteristics about you. To exercise a California right, email support@letmecreep.app. You may also designate an authorized agent to submit a request on your behalf, subject to verification.

11. EU / UK Residents (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, LetMeCreep is the controller of your personal information for purposes of the General Data Protection Regulation and the UK GDPR. Our lawful bases are: (i) performance of a contract, to provide the Service you signed up for; (ii) legitimate interests, in operating, securing, and improving the Service, and in maintaining an archival record consistent with our stated product model; (iii) legal obligation, where applicable; and (iv) consent, where required.

You have the rights of access, rectification, erasure (subject to the archive doctrine in Section 6), restriction of processing, objection to processing based on legitimate interests, and data portability. You also have the right to lodge a complaint with your local supervisory authority. Our Data Protection Officer can be reached via support@letmecreep.appwith the subject line “DPO”.

12. Security

We take reasonable and appropriate technical and organizational measures to protect personal information, including AES-256-GCM encryption of sensitive fields at rest, TLS/HTTPS in transit, argon2id password hashing, WebAuthn passkey support for phishing-resistant sign-in, least-privilege access controls for operations personnel, and audit logging of privileged actions. No system is perfectly secure, and we cannot guarantee absolute security.

13. Breach Notification

If a personal-data breach is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the affected individuals and, where required, the relevant supervisory authority without undue delay and in any event within 72 hours of becoming aware of the breach, consistent with GDPR Article 33 and applicable state breach-notification laws.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be announced by email to the address on your account at least 30 days before they take effect and will update the effective date at the top of this page.

15. Contact

Privacy questions, data-subject requests, and DPO inquiries: support@letmecreep.app.