Privacy policy
last updated July 14, 2026
chumbi exists to reduce the amount of your personal information floating around the internet. Holding your data carefully is the whole job — so this page is a plain, honest account of what we collect, why, and how you stay in control of it.
Who we are
chumbi is operated from the European Union and acts as the data controller for the personal data described here. For any privacy question or request, contact support@chumbi-app.com.
What we collect, and why
We collect only what the service needs:
- Your account email — to sign you in (with a one-time link) and to send you notices about your requests.
- The identity details you give us for protection — your name and any names you’ve used, plus the emails, phone numbers, and addresses you want removed from data brokers. We only ask for what a broker needs to find your record.
- Your signed mandate — the authorisation that lets us act for you, recorded with a timestamp, your IP address, and a signature hash.
- The history of each removal request — what we sent, what the broker replied, and the outcome, kept as an evidence trail you can read any time.
How we protect it
Your identity details are encrypted at the field level — the plaintext never sits in our database in the clear. Two-factor authentication is required before protection starts. When we contact a data broker on your behalf, we send only the minimum needed to identify your record, never more.
We run no third-party advertising or tracking inside your account, and we never sell your data. That would contradict the entire point of the service.
The legal basis
We process your data to perform the service you asked us for (Article 6(1)(b) GDPR), and to exercise your data-protection rights on your explicit instruction under your signed mandate. Requests to brokers are made under your rights of erasure (Article 17), access (Article 15), and objection (Article 21).
Who we share it with
We use a small set of processors to run the service, each handling only what their function needs:
- the hosting and database provider that runs the application;
- our email provider, to send requests and sign-in links and receive replies;
- our payment provider, to process subscriptions (they handle card details, we never see them);
- a breach-lookup service, to check whether your email appears in known data breaches;
- a search provider, to show what a search for your name returns.
Beyond these, the only parties we send your data to are the data brokers you instruct us to contact — and only the minimum needed to identify and remove your record.
How long we keep it, and deleting it
We keep your data while your account is active and for as long as we’re pursuing removals for you. You can export everything we hold as a file at any time, and you can delete your account and every trace of your data immediately — from your security settings, in one confirmation. It is not a support ticket and not a “within 30 days” promise: it happens right away, and it cannot be undone.
Your rights
Under the GDPR you can access, correct, export, and erase your data, and object to or restrict processing. The service is built to make these easy — access and export and erasure are all self-service. You may also complain to your national data-protection authority if you believe we’ve handled your data wrongly.
Changes
If we change this policy we’ll update the date above and, for material changes, tell you by email. Questions? Write to support@chumbi-app.com.