Eraser

Take back your privacy. Eraser sends data removal requests to 700+ data brokers on your behalf β for free.

You know those sites like Spokeo, BeenVerified, and Whitepages that have your home address, phone number, and family members' names? They're called data brokers, and there are hundreds of them. Services like Incogni and DeleteMe charge $100+/year to send opt-out requests to these companies. Eraser does the same thing, but it's open source and completely free.
π eraser.drumandbytes.dev β broker directory, opt-out guides, and the list of EU/EEA data protection authorities.
π More Drumandbytes projects
What to Expect
The good: Eraser automatically sends removal request emails to 700+ data brokers. Many brokers process these requests automaticallyβyou send the email, they remove your data, done.
The reality: Some brokers require additional steps. They might send you a confirmation link to click, ask you to fill out a form on their website, or request identity verification. Eraser tracks these responses and shows you exactly what needs manual attention.
The bottom line: You're not paying $100+/year, and you're taking real action to protect your privacy. Even with some manual steps, Eraser handles the heavy lifting and gives you a fighting chance against the data broker industry.
The Easy Way (Web Interface)
If you're not comfortable with command-line tools, Eraser has a visual interface that runs in your web browser.
What You'll Need
- Eraser itself: install with Homebrew, or download the file for your OS from Releases. No Go needed, unless you want to build from source.
- An email account to send from: Gmail, Proton Mail (via Bridge), Fastmail, mailbox.org, Posteo, iCloud, Amazon SES, or any provider with SMTP access (setup instructions below)
Getting Started
Step 1: Get Eraser
Homebrew (macOS, and Linux where cask support is available):
brew tap drumandbytes/tap
brew install --cask drumandbytes/tap/eraser
Homebrew 6+ asks you to trust a third-party tap once β if it does, run
brew trust drumandbytes/tap and re-run the install. The cask removes macOS's
Gatekeeper quarantine from the (unsigned) binary after install, so there's no
"Open Anyway" step. If brew on your Linux setup doesn't do casks, use the
tarball below.
Prebuilt binary: grab your OS's file from the
Releases page β the broker
list is baked in, nothing to install:
-
Windows β ..._windows_amd64.exe (run it directly) or the .zip (also has
the README and config.example.yaml).
-
macOS / Linux β ..._<os>_<arch>.tar.gz; tar xzf it and run ./eraser.
-
macOS: the binary is unsigned, so Gatekeeper will block it on first run.
Either right-click it β Open β Open, or run
xattr -dr com.apple.quarantine ./eraser once.
-
Windows: the archive contains eraser.exe.
-
eraser fill and eraser confirm (browser automation for opt-out forms) need
Chrome or Chromium installed; nothing else does.
Build from source (needs Go):
git clone https://github.com/drumandbytes/eraser.git
cd eraser
go build -o eraser ./cmd/eraser
Or install straight from the module path (the broker list is baked in):
go install github.com/drumandbytes/eraser/cmd/eraser@latest
On Windows, build it as eraser.exe (go build -o eraser.exe ./cmd/eraser) β
Windows won't run a downloaded file with no extension.
Step 2: Start the Web Interface
./eraser serve
On Windows, run .\eraser.exe serve instead.
Open your browser and go to http://localhost:8080
Step 3: Complete the Setup Wizard
The wizard walks you through entering your personal information (the data brokers need this to find your records) and setting up email. Just follow the prompts.
Step 4: Send Removal Requests
From the dashboard, you can:
- Browse the list of 700+ data brokers
- Send requests one at a time or in bulk
- Track which requests have been sent and their status
- Exclude a broker from sends with one click (and bring it back later) - useful for a broker you'd rather skip, e.g. one that demands ID verification
- Mark a sent request as bounced, so it's retried on the next send
- Download an evidence report of every request and reply (History β Export evidence) for a complaint to your data protection authority
- Fetch the latest broker list (Settings β Broker List)
- Add a broker that's missing from the list (Brokers β + Add broker) - kept on your machine and never removed by a list update
That's it. The whole process takes about 10 minutes to set up, and then Eraser handles the rest.
Setting Up Your Email Account
Eraser sends removal requests from your own email account over SMTP, and can read replies over IMAP. Pick your provider in the setup wizard (or eraser init) and it fills in the servers. You only enter your address and an app password, a separate password your provider generates for apps like Eraser. Never use your main account password.
| Provider |
What you need |
Notes |
| Gmail |
App password (needs 2-Step Verification) |
~500 emails/day |
| Proton Mail (unverified) |
Proton Mail Bridge running on the same machine, paid plan |
Use the password Bridge shows. Bridge's self-signed certificate is accepted because it only listens on localhost. Not yet tested by the maintainers (no Proton account) - please report whether it works |
| Fastmail |
App password with IMAP + SMTP access |
|
| mailbox.org |
Application password |
|
| Posteo |
Your Posteo address and password |
|
| iCloud Mail |
App-specific password |
SMTP is on port 587 (STARTTLS) |
| Amazon SES |
SES SMTP credentials; the From address/domain verified in SES |
Send-only: set up reply monitoring on a separate mailbox. Change the region in the SMTP host if yours isn't eu-west-1 |
| Anything else |
Choose "Other" and enter the SMTP (and optionally IMAP) server |
|
TLS: ports 465 (SMTP) and 993 (IMAP) use TLS from the start. Any other port must support STARTTLS. Eraser never sends your password without encryption.
Outlook.com / Hotmail isn't a preset: Microsoft turned off app-password (basic) authentication for consumer accounts, and Eraser doesn't support OAuth sign-in yet. Microsoft 365 work accounts whose admin enabled SMTP AUTH can try "Other" with smtp.office365.com:587.
Your provider isn't listed or doesn't work? Open a mail provider issue, or add it yourself (see CONTRIBUTING.md).
Daily sending limits: Eraser caps itself at 450 emails per rolling 24 hours by default (options.daily_send_limit), just under Gmail's ~500/day. Other providers have different (sometimes lower) caps, so check yours and lower the limit if needed. Eraser resumes where it left off on the next run, so it's safe to just re-run eraser send until it reports nothing left to send.
Automating it: eraser schedule install has your OS run Eraser every 6 hours. Each run sends to whichever brokers are due (each broker is re-sent 25 days after its last request, within the daily cap) and checks your inbox for replies. Everything stays on your machine; eraser schedule status shows the last run, eraser schedule remove undoes it. The web UI's Settings β Automation card does all of this with buttons, including a "run while this app is open" option for systems without launchd/systemd; on the CLI, eraser auto loops in the foreground instead.
Choose "Skip β I'll send the emails myself" in the setup wizard (or options.send_mode: manual in the config, or pick option 2 in eraser init). Then Eraser never sends anything and needs no credentials:
- The Brokers page shows an Email link per broker (the ready-to-send removal request, with an "Open in mail app" button) and a Mark sent button.
- On the CLI:
eraser draft <broker-id> prints one email, eraser draft -o ./out writes one .eml per broker (open them in your mail client), and eraser send --manual walks the whole list one at a time.
- After you send one,
eraser mark-sent <broker-id> (or the web button) records it so status, pipeline and export still account for it.
For Developers: CLI Usage
If you prefer the command line, Eraser has a full CLI.
Installation
git clone https://github.com/drumandbytes/eraser.git
cd eraser
go build -o eraser ./cmd/eraser
On Windows, build it as eraser.exe instead (go build -o eraser.exe ./cmd/eraser) and run commands as .\eraser.exe <command> - see the note above.
Quick Start
# Interactive setup
./eraser init
# Preview what would be sent (no emails go out)
./eraser send --dry-run
# Send removal requests to all brokers
./eraser send
# Check your history
./eraser status
Commands
| Command |
What it does |
eraser init |
Interactive config setup |
eraser send |
Send removal requests (auto-capped at daily_send_limit/day, resumable) |
eraser send --dry-run |
Preview without sending |
eraser send --ignore-daily-limit |
Send everything in one run, ignoring the daily cap |
eraser send --resend |
Force re-send even to brokers within the cooldown window |
eraser list-brokers |
Show all 700+ brokers |
eraser status |
View history and stats |
eraser status --limit 50 |
Show more history |
eraser add-broker |
Add a custom broker interactively |
eraser mark-bounced <broker-id>... |
Correct the record for brokers whose email actually bounced |
eraser cleanup-bounces |
Find and clear bounced broker email addresses (keeps the broker entry) |
eraser audit-brokers |
Check broker websites/email domains for signs of life |
eraser validate-brokers |
Structural check of a broker list (ids, names, regions, emails, URLs) |
eraser update-brokers |
Fetch the latest broker list (the list ships inside the binary; this refreshes it) |
eraser monitor |
Monitor your inbox (IMAP) for broker responses |
eraser schedule install |
Run sends + inbox checks automatically every 6 hours (launchd on macOS, systemd on Linux) |
eraser auto |
Same cycle in the foreground, looping every 6 hours (Windows, containers) |
eraser pipeline |
Show pipeline status β which brokers need manual follow-up |
eraser export |
Write an evidence report (HTML/JSON) of every request and reply β for a DPA/noyb complaint |
eraser confirm |
Click confirmation links found in broker emails |
eraser fill |
Fill opt-out forms via browser automation |
eraser profile add / list / edit / remove |
Manage extra profiles, e.g. a household member (details) |
eraser serve |
Start web interface |
eraser serve -p 3000 |
Web interface on custom port |
Configuration File
Your config lives at ~/.eraser/config.yaml. Here's the full schema:
profiles:
- id: default
first_name: Jane
last_name: Doe
email: jane@example.com
# Optional but helps brokers find your records
address: "123 Main Street"
city: "San Francisco"
state: "CA"
zip_code: "94102"
country: "USA"
phone: "+1-555-123-4567"
date_of_birth: "1990-01-15"
# Optional: other identities/addresses brokers may have indexed you under
# additional_emails: [old-address@example.com]
# name_variants: [Jane D.]
# previous_addresses: ["456 Old Street, San Francisco, CA"]
# additional_phones: ["+1-555-987-6543"]
email:
from: jane@example.org
smtp:
host: smtp.fastmail.com # see "Setting Up Your Email Account" for other providers
port: 465 # 465 = TLS, any other port = STARTTLS
username: jane@example.org
password: your-app-password
options:
template: generic # or "gdpr" or "ccpa"
rate_limit_ms: 2000 # delay between emails
daily_send_limit: 450 # cap per rolling 24h window; keep it under your provider's daily limit
# Optional: only target specific regions
# regions:
# - us
# - global
# Optional: skip specific brokers
# excluded_brokers:
# - spokeo
# - whitepages
# Optional: skip every broker in these categories - e.g. "requires-id" to
# skip brokers that demand a government-issued ID document before they'll
# act on a request (this tool won't supply one on your behalf)
# excluded_categories:
# - requires-id
# Optional: monitor your inbox for broker replies (used by `eraser monitor`)
# inbox:
# enabled: true
# provider: fastmail # gmail, proton, fastmail, mailbox-org, posteo, icloud - or drop it and set server + port
# email: jane@example.org
# password: your-app-password
Email Templates
Eraser includes three templates:
- GDPR β Invokes Article 17 "Right to Erasure" under EU law
- CCPA β Invokes California Consumer Privacy Act rights
- Generic β References multiple privacy laws, works anywhere
The generic template is a good default if you're not sure. EU residents should pick gdpr explicitly β see EU-NOTES.md.
Adding Brokers
The broker database is at data/brokers.yaml and is compiled into the binary, so a downloaded eraser is self-contained. eraser update-brokers pulls a fresh copy from this repo into ~/.eraser/brokers.yaml (a small conditional download β the app itself isn't touched). To add one by hand:
- id: example-broker
name: Example Broker
email: privacy@example.com
website: https://example.com
opt_out_url: https://example.com/optout
region: us # us, eu, or global
category: people-search # people-search, marketing, background-check, financial-b2b, data-intermediary, device-id-only, or requires-id
Or use the interactive command:
./eraser add-broker
Choosing a broker list
The full list is broad and inherited from upstream, so it carries some noise (dead
addresses, companies that turn out not to be brokers). If you'd rather email only
companies that are confirmed data brokers with a current first-party privacy
email or rights portal β built from registries and authoritative privacy notices
across the US, EU, Latin America, New Zealand, and Kenya β use the
smaller verified list:
./eraser send --list verified # one run
./eraser send --broker spokeo,pipl # explicit broker IDs
./eraser send --region eu --category financial-b2b
./eraser send --exclude broker-id --status never
--broker, --region, --category, and --exclude can be repeated or comma-separated. --status eligible is the safe default; use never, failed, or all to select by send history. The web Brokers page exposes the same filters before bulk sending.
Or set it permanently in config.yaml:
options:
broker_list: verified # or: broker_file: /path/to/your-own-list.yaml
"Verified" means each entry is confirmed to be a real data broker with a
current, working contact we found by hand β most of the US ones are also
cross-checked against California's data-broker registry. It doesn't mean
any of them have been sent a request and confirmed to actually act on it;
no list can promise that in advance. eraser status/pipeline is how you
find out what a broker actually does once you've emailed it.
The weekly CI audit keeps the full list from rotting β it clears dead email
domains automatically and opens a PR for review.
Security Notes
- Your config file contains personal data. Don't commit it to git. The file is created with restricted permissions (readable only by you).
- Use app passwords, not your real password. Most providers require one for SMTP/IMAP access; where they don't, it's still a good idea.
- Consider using a dedicated email. This keeps your removal request activity separate from your main inbox.
Does This Actually Work?
Yes, with caveats:
- Most brokers comply. They're legally required to under GDPR (EU) and CCPA (California). Even brokers not covered by these laws often honor requests to avoid liability.
- Some require manual steps. A meaningful share of brokers will respond asking you to:
- Click a confirmation link (Eraser detects these and shows them to you)
- Fill out an opt-out form on their website (Eraser tracks these as "pending tasks")
- Verify your identity via email reply
- It's not instant. Brokers have up to 30-45 days to process requests (varies by law). Some are faster.
- You'll need to repeat this. Data brokers buy and sell data continuously. Running Eraser every 60-90 days keeps you off their lists.
The Pipeline view (eraser pipeline or the web UI) shows you exactly which brokers need manual attention. It's not fully automated, but it's freeβand it does the tedious work of sending 700+ emails and tracking responses for you.
How It Compares
| Service |
Price |
Brokers |
Open Source |
| Eraser |
Free |
700+ |
Yes |
| Incogni |
$77/year |
180+ |
No |
| DeleteMe |
$129/year |
750+ |
No |
| Privacy Duck |
$500+/year |
500+ |
No |
About This Fork
This is a maintained fork of digisamroc/eraser, which has been inactive since early 2026. It includes bug fixes, performance cleanups, and GDPR/EU-specific customizations on top of the original CCPA-focused tool.
If you're an EU resident exercising GDPR rights rather than a US CCPA use case, read EU-NOTES.md first β it covers which template to pick, safe send-volume behavior, and what to do if a broker ignores your request.
Contributing
Contributions are welcome β adding brokers, fixing bugs, improving templates or docs. See CONTRIBUTING.md for the details (dev setup, how to add a broker, commit/PR conventions).
Project Structure
eraser/
βββ cmd/eraser/ # CLI entry point - main.go has root wiring, one cmd_*.go
β # file per command (cmd_send.go, cmd_fill.go, etc.)
βββ internal/
β βββ broker/ # Broker loading and filtering
β βββ browser/ # Browser automation (form fill, confirm links, CAPTCHA handling)
β βββ config/ # Configuration handling
β βββ email/ # SMTP sending
β βββ history/ # SQLite request tracking
β βββ inbox/ # IMAP monitoring and reply classification
β βββ template/ # Email template rendering
β β βββ templates/ # gdpr.tmpl, ccpa.tmpl, generic.tmpl
β βββ web/ # Web UI - server.go has core setup, handlers_*.go files
β # hold the actual page/API handlers by resource
βββ data/brokers.yaml # 700+ broker database
βββ config.example.yaml # Example configuration
βββ EU-NOTES.md # GDPR/EU-specific setup and customization notes
See docs/architecture.md for the full breakdown, including CI/lint setup.
License
MIT β do whatever you want with it.
Disclaimer
This tool sends legitimate data removal requests based on privacy laws. It's not legal advice. Not all brokers are required to comply with all requests, and response times vary. But it works, and it's free.
Your responsibility. Eraser acts on your instructions and sends requests from your own email account. You are responsible for the accuracy of the personal data you enter, for complying with your email provider's terms and sending limits, and for anything you choose to submit to a data protection authority or other body. The templates and the export report are starting points, not a substitute for advice on your specific situation.
How it was made
Built with the help of an AI coding assistant (Claude). I review and test what gets published.