Blog

Notes from the privacy team.

Practical writing about data brokers, breaches, and staying a little harder to find online.

January 15, 2026 · Quietline team

How people-search sites get your data

A plain-English tour of where sites like Whitepages, Spokeo, and BeenVerified actually get your name, address, and phone number.

If you've ever searched your own name and been unnerved by how much shows up, the short answer is: none of it was stolen. Almost all of it is legally scraped and resold from sources you already interacted with — often years ago.

1. Public records

County property records, court filings, marriage and divorce records, business filings, and voter registration rolls are public by design. Data brokers bulk-download these from county and state governments and index them by name.

2. Utility, magazine, and warranty forms

Every time you've filled out a form for a utility, magazine subscription, warranty registration, sweepstakes, or loyalty card, that form's fine print almost certainly allowed the vendor to share your details with "marketing partners." Those partners resell it.

3. Credit header data

Credit bureaus sell the top portion of your credit file — name, current and past addresses, phone numbers, date of birth — as "credit header" data. This is one of the richest sources people-search sites use to link addresses to names.

4. Social profiles and app permissions

Older public LinkedIn scrapes, Facebook exports, and app SDKs that harvest contact books all end up on the broker market too. If a friend uploaded their contacts to an app that resold them, your number went with it.

What removals actually do

Opting out of a broker doesn't delete the underlying source. It tells that specific site to stop displaying your record. Because brokers refresh their databases from those upstream sources on a schedule, opt-outs need to be repeated — which is why this is an ongoing service, not a one-time cleanup.

January 22, 2026 · Quietline team

What to do after a data breach

A calm, ordered checklist for the first 72 hours after you learn your data was in a breach.

Getting a "your data was involved in a security incident" email is stressful, but the actual response is short and mechanical. Here's the order to do things in.

Within the first hour

  1. Confirm the breach is real. Search the company's name plus "data breach" and look for coverage from a reputable source. Never click links inside the notification email — go to the company's site directly.
  2. Change the password on that account. If you reused that password anywhere else, change it there too. Use a password manager so you never have to reuse one again.
  3. Turn on two-factor authentication on the affected account and on your email, if you haven't already. Prefer an authenticator app over SMS.

Within 72 hours

  1. Freeze your credit at all three bureaus (Equifax, Experian, TransUnion). It's free, takes about 10 minutes total, and stops new accounts from being opened in your name. Unfreeze temporarily when you actually need new credit.
  2. Set up transaction alerts on every credit card and bank account you have. Most banks let you get an SMS or push for every charge.
  3. Check for exposed personal info at haveibeenpwned.com to see what other breaches your email has appeared in.

Ongoing

If your address and phone were in the breach, expect an uptick in spam calls, phishing texts, and physical mail scams for the next few months. This is when reducing your presence on people-search sites has the biggest impact — the fewer places your name is tied to your address, the harder it is for scammers to write a convincing phishing message.

February 5, 2026 · Quietline team

Why data broker opt-outs need to be repeated

One-time removals feel done, then your listing reappears months later. Here's why, and what to do about it.

The most common frustration with data broker opt-outs is that they don't stick. You file a removal, the listing disappears within a few weeks, and then six months later a friend Googles you and there you are again — same address, same phone number, same site.

How brokers rebuild their databases

People-search sites don't maintain a static list. They ingest fresh feeds from public records, credit header data, and marketing databases on a rolling schedule — typically monthly or quarterly. When they re-ingest, if your name and address are still in those upstream sources (and they always are, because public records don't get deleted), a new record gets created.

That new record has a new internal ID at the broker. As far as the broker's system is concerned, it's not the same record you asked them to remove — so the old opt-out doesn't apply to it.

Why an annual sweep isn't enough

A yearly opt-out gets you clean for maybe two to four months out of twelve. Monthly re-scanning and re-filing is what actually keeps you off these sites consistently, which is why services (including this one) charge on a subscription basis rather than a one-time fee.

What you can do yourself, for free

If you'd rather DIY: pick five to ten of the biggest brokers, calendar a reminder for every 60 days, and re-file your opt-out each time. It's tedious — each site has a slightly different form, some require you to email a photo of your ID, and a few will make you fax something in 2026 — but it works if you stay disciplined.

Want to see a specific topic covered? Let us know.