Privacy Policy
Delister, operated by Bitbox SIA. Last updated 21 July 2026.
This policy explains what information we collect, how we use it, who we disclose it to and how, and how we protect it. It covers the service provided by Bitbox SIA (registration 40203098731), trading as Delister. Bitbox SIA is the data controller. For any question about your data, write to [email protected].
Information we collect
- Contact details you give us: your name and email address.
- Details of the works you ask us to protect, and the copies we find, which may include URLs and file information.
- If you run a free scan, the course name you enter and basic technical data about the request, such as the approximate time and a hashed identifier.
- Payment information is handled by Stripe. We receive confirmation that a payment succeeded; we never receive or store your card number.
How we use it
We use your information only to provide the service you asked for: to identify pirated copies, to file removal requests on your behalf, to report the results back to you, to take payment, and to answer your messages. We do not sell it, and we do not use it for advertising or profiling.
Who we disclose it to, and how
We disclose only what is necessary to run the service, and only to these parties:
- Hosts, file hosts, and search engines, when we file a removal request for you. We transmit the specific infringing URLs and a description of the work through each provider's abuse or copyright reporting channel, usually a web form or a dedicated email address. The takedown notice names our accountable signer, not you.
- Stripe, our payment processor, which receives the information needed to take payment, sent through Stripe's secure connection.
- Our infrastructure providers (Cloudflare, which serves the site, and Google, which carries our email), which process data on our behalf under their own agreements.
We do not disclose your information to anyone else unless the law requires it.
How we protect it
We limit access to your information to the people running the service. It is transmitted over encrypted connections (HTTPS/TLS), and it is held in access-controlled systems operated by the providers named above. Payment data is handled entirely by Stripe, which is certified to the PCI DSS standard, so card details never reach our systems. We keep only what we need, which reduces what is at risk.
How long we keep it
We keep records of the work we did and the removals we filed for as long as we need them to run the service, to bill, and to meet legal and accounting obligations. You can ask us to delete data we are not required to keep.
Your rights
Under the GDPR you can ask us for a copy of your data, ask us to correct or delete it, or object to how we use it. Write to [email protected] and we will respond. You also have the right to complain to the Latvian Data State Inspectorate (Datu valsts inspekcija).