Self-hosted privacy workbench

Keep track of your privacy requests.

Keep request drafts, replies, and removal evidence together in a case file on your computer. Review each step yourself. The current release does not contact brokers or submit requests.

MIT licensed · runs on your laptop · your data stays in a SQLite file you own · nothing on this site is for sale

Run logExample · sample data
  1. 2026-08-05 14:22 sentinel example-broker.test/profile/example-profile → 404. removed. evidence/example-verify-0812.png
  2. 2026-08-05 09:04 operative radaris.com is phone-gated → parked before browser launch for manual completion
  3. 2026-08-04 18:40 mailroom beenverified.com confirmation email expected at +ul-beenverified → needs you
  4. 2026-08-03 12:11 sentinel familytreenow.com listing is back after 94 days. relisted.
  5. 2026-08-02 07:15 counsel drafted CCPA §1798.105 letter → privacy@mylife.com. 31 days waiting.
  6. 2026-08-01 11:02 scout truepeoplesearch.com: 2 candidates, top heuristic 0.86 → waiting for review

AI exposure

AI can connect the details you leave public.

Give it less to find.

A people-search page can publish your address, phone number, relatives, aliases, and age. Search agents and data pipelines can combine those records without opening every page by hand. UnlistFast helps you reduce that public source material and keep evidence of the steps you complete.

Source removal can reduce future exposure. It cannot prove that a model never saw the data or make a trained system forget it.

Exposure propagation ledger

One record can travel.

Illustrative path
  1. 01 / Public source

    People-search record

    • Nameredacted sample value
    • Home addressredacted sample value
    • Phoneredacted sample value
    • Relativesredacted sample value
  2. 02 / Reuse paths

    Less friction to combine

    • Search
    • Scrape
    • Retrieve
    • Collect

    Search agents and data pipelines can connect public records without opening every page by hand.

  3. 03 / Derived profile

    More than one field

    • Identity
    • Location history
    • Household
    • Contact graph

Proof boundary

UnlistFast works at the public source. Removing that source can reduce future exposure, but cannot prove what any system or operator already collected, used for training, cached, indexed, or retained. That boundary applies to OpenAI/ChatGPT, Anthropic/Claude, and open-weight or self-hosted models developed in China, the United States, and elsewhere.

Illustrative data pathway, not a live scan. Naming a provider is not a claim that it collected or trained on this record.

The standard

Submission, verification, and re-listing are different facts.

A form can accept a request while the listing stays live. A listing can disappear and return later. UnlistFast records those states separately and refuses to call an empty page, bot wall, dry run, or ambiguous browser crash a successful removal.

UnlistFast has not run against an authorized set of live broker accounts. Placeholder screenshots and hash-chained events let you inspect what a dry run recorded; they do not prove a broker action, attest to an external event, or establish an overall removal rate.

The intended loop

Five roles model the work. The current runner stays dry.

The cards below describe the original five-agent design. In this build, the CLI runs them with a dry driver: it creates plans, drafts, and clearly labeled placeholder events, but does not search, submit, or revisit a broker site. Live execution is fenced off until the newer authorization and privacy-rule gates can bind every action.

Current release: dry planning and manual evidence only. UNLISTED_DRIVER=live is rejected before the database or a browser can be opened.

  1. 01

    Scout

    Plans each reviewed broker search and contains the local matching rules for name, age, city, relatives, and phone. The current dry runner does not open those search pages; you can add an exact listing URL manually and confirm it yourself.

    → dry search plan, or a user-confirmed listing
  2. 02

    Operative

    Turns the broker recipe into a redacted, reviewable dry plan. It does not open the broker form or submit personal data. You perform the external step, then record the attempt and its exact evidence in the local case file.

    → local draft and next step; nothing submitted
  3. 03

    Sentinel

    Keeps removal and recurrence as separate evidence-backed outcomes. Automatic page checks are disabled in the current build, so dry verification stays inconclusive. You can record a point-in-time observation with the source and exact evidence.

    → user-reviewed observation + local evidence digest
relisted → human review before a new draft; still listed or inconclusive → keep the case open. Any later observation is recorded manually; no background browser check runs today.
supporting

Mailroom

Mints a per-listing plus alias. Confirmation-link parsing accepts only HTTPS links on the broker's own domain, but no inbox worker reads or clicks them. The job parks and tells you to handle the message manually.

supporting

Counsel

Drafts CCPA § 1798.105 deletion, opt-out of sale under § 1798.120, GDPR Article 17 erasure, authorized-agent requests, and neutral follow-ups. Local timers never manufacture a legal breach; drafts stay local for review.

What proof looks like

The evidence format is ready. Live proof is not.

UnlistFast’s case-file model stores a broker response, capture timestamp, source URL, and integrity hash per listing. The current dry runner writes clearly labeled placeholder captures; it does not load a broker page, so those records do not prove a removal.

The schema keeps removal, still listed, inconclusive, and re-listed as separate outcomes. When you have real evidence from a reviewed manual step, the local case file can keep the artifact and its hash together. A hash detects local mismatch; it is not a third-party timestamp or tamper-proof chain of custody.

Source: UnlistFast source — packages/agents/src/sentinel.ts
example-broker.test/profile/example-profilePage not foundHTTP 404 · no listingcaptured by sentinel · 2026-08-05T14:22:07Z
Example · sample dataRemoved
agentsentinel
captured2026-08-05T14:22:07Z
sourceexample-broker.test/profile/example-profile
filed2026-07-25 · 11 days earlier
fileevidence/example-verify-0812.png
sha2563f9c1d…a71b

Reading the marketing

A site count is not a capability statement.

Discovery is its own capability

A broker can be present in the registry without having a search recipe. The dashboard reports dormant search-recipe coverage separately, so “listed” never implies the current dry scout can discover a live profile there.

Source: UnlistFast source — apps/web/src/lib/data.ts

Shared flows count once

Intelius, TruthFinder, Instant Checkmate, US Search, ZabaSearch map to one shared PeopleConnect route. Counting that route as five implementations would be padding, so our registry marks it coveredBy and makes no promise about current brand coverage.

Source: UnlistFast source — packages/brokers/src/index.ts

Automation is not verification

Reviewed selector recipes, written routes, and human-gated requests are reported separately. Current CLI runs do not execute those selectors. A future reviewed executor still should not count a record as removed without authoritative evidence and a saved hash.

Source: UnlistFast source — packages/agents/src/sentinel.ts

Limits

What UnlistFast can’t do.

This list is on the homepage rather than buried in a support article, because a removal tool that won’t tell you where it stops is a removal tool you can’t plan around.

  • Make a model forget youRemoving or suppressing a public source can reduce future exposure. It cannot prove or reverse earlier crawling, indexing, copying, training, caching, or downstream reuse. UnlistFast does not edit model weights or memory, and it does not submit provider-specific requests.
  • Solve CAPTCHAsTruePeopleSearch, FastPeopleSearch and FamilyTreeNow all gate the removal on one. The dry plan marks those steps for manual work; any future live executor must stop there too. This project does not bypass broker bot controls.
  • Upload your IDAny broker whose flow requires a government ID is refused outright by the operative before a browser even opens. Nobody’s passport should be posted to a people-search site by a background job.
  • Take your verification callsWhitepages ends its flow with an automated call reading a four-digit code. Radaris does something similar. These flows are marked manual from the start. The current dry build does not open a browser or wait for a code handoff.
  • File California’s DROP request for youUnlistFast does not integrate with the state portal. The portal lets an eligible consumer submit for themselves, and describes submissions for another person when permission exists. Open the official portal at consumer.drop.privacy.ca.gov.
  • Stop brokers re-collecting youDeletion removes today’s copy. It does not stop tomorrow’s acquisition — that needs a separate opt-out-of-sale request, which Counsel can draft. The data model can record recurrence, but the current dry Sentinel does not revisit a live listing.
  • Run it for youThere is no hosted UnlistFast today. You clone it, you run it, you keep the database. That is the trade: nobody else holds your data, and nobody else does the work either.
Source: California Privacy Protection Agency — DROP — brokers have been required to process DROP requests since 1 Aug 2026

Self-hosting

Set up your local workbench.

The current agent runs in dry mode only. It plans scans and removals, creates local drafts, and records clearly labeled placeholder evidence without contacting broker sites. UNLISTED_DRIVER=live is rejected at startup. The older Playwright path remains dormant source code, not an activation option.

Your profile, listings, job history, and placeholder captures live in one local SQLite file and one evidence/ folder. The Anthropic extraction adapter is dormant too. Setting an API key does not enable it, and the current CLI sends no broker-page content to Anthropic.

$ git clone <repository-url> unlistfast
$ cd unlistfast
$ pnpm install
$ pnpm db:seed
$ pnpm dev

# dashboard on :3000, this site on :3100
# pnpm agent — preview the dry loop from the CLI

Requires Node 20+ and pnpm. Playwright and an Anthropic API key are not needed for the dry build and do not turn on live behavior. A public repository URL is still a launch input, so this checkout does not invent one.

The current release does not send live requests. Any future live executor must remain limited to you or someone who has validly authorized you, disclose each recipient and field before sending, and pass a new security review. Review the responsible-use terms and data-flow notice first.

Sources

Everything above, with its receipt.

We link only URLs we’ve checked. Where a claim is about our own behaviour, the citation is the file that implements it.

  • California Consumer Privacy Act as amended by the CPRA — right to delete (§ 1798.105), response deadlines (§ 1798.130(a)(2)), authorized agents (11 CCR § 7063). https://oag.ca.gov/privacy/ccpa
  • California's Delete Request and Opt-out Platform launched on 1 Jan 2026. Brokers began processing requests on 1 Aug 2026, with an initial 90-day window and recurring deletion processing every 45 days. https://privacy.ca.gov/drop/
  • Official GDPR text: Article 12 response rules, Article 17 right to erasure, and Article 21 right to object, each subject to the regulation's scope and exceptions. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
  • The claims about what UnlistFast does are checkable against the code: packages/agents/src/*.ts and packages/brokers/src/*.ts.