An open, fact-based benchmark
Every company you use keeps a copy of your digital life. We grade how well you can see it, get it, and delete it — the same six questions, every company, every fact sourced.


Every company answers the same six questions — Access, Portability, Friction, Deletion, Sells/shares, Trains AI — each scored Best (2) / Moderate (1) / Restrictive (0). The six add to a total out of 12 on a flat, published scale (A 11–12 · B 9–10 · C 6–8 · D 3–5 · F 0–2), and a worst score on Sells/shares or Trains AI caps the grade at C. A verified regulatory action then deducts points off the total (§). Every cell rests on a sourced, dated fact, assessed per jurisdiction.
9 REGIONS VERIFIED · MORE ADDED ON DEMAND The US, EU, UK, Brazil, India, Indonesia, Japan, Canada and Australia columns are source-verified against each company's own pages plus the local legal floor, with live links and a review date. We do not grade a single "Rest of world" column — it spans 170-plus jurisdictions, so we add new countries one at a time as we can verify them. China is shown but not scored, with an explanation. Hover any cell for the deciding fact. Contributed requests sharpen our confidence and flag cells for re-review, but won't on their own move a score.
View what the company holds on you — every major category, clearly, self-serve, free.
Export it in a structured, machine-readable form — not a scrape or PDF dump (the data-portability right).
How fast and painless the process is — and whether dark patterns block the way (the speed nuance).
Actually delete it — not just deactivate — with clear scope and timeline.
Whether it's sold, shared, or brokered — and whether the opt-out works.
Whether it trains AI on your data — and whether the opt-out is real and findable.
Can you grant your agent ongoing, revocable access to your own data.
A verified regulatory action — a real, dated, regulator- or court-confirmed order, settlement, or fine — deducts points off the /12, on top of the six scored questions. Severity 1 deducts 2 points and covers verified actions such as opt-out failures, deceptive ad-targeting, or disclosure lapses; severity 2 deducts 4 points and is reserved for the most serious records — unlawful large-scale data transfer, children's data, a breach causing demonstrable harm, or documented repeat offenses. Severity tracks the nature of the violation, not the size of the fine. The deduction sits at full weight for the first ~5 years, then ramps down to zero by ~8 years if no further verified action resets the clock — the record stays visible even after it stops moving the grade. We state only the verifiable fact (the action, its date, its source), never an inference of reform. Companies with no verified action carry no penalty. Each penalised company shows the full arithmetic — practices total, deduction, and final grade — with the dated evidence.
A grade is a documented assessment against a public rubric, as of the reviewed date — not a security audit, legal ruling, or guarantee of any outcome.
Your data never passes through us — anything you retrieve goes straight to your own device. Start with a company above, or open your own list.