// ENFORCE YOUR RIGHTS

Make them delete your data.

Getting spammed means a company has your email address and is doing something with it. If you're based in the EU or UK, data protection law gives you the right to find out what they hold on you, or to make them delete it — and to complain to your own country's data protection authority if they ignore you, no matter where they're based. Exercising that right usually means knowing who to contact, writing a correctly worded request, and then tracking a deadline they're not exactly motivated to meet.

The first time you open a request, we'll ask you to confirm your own country of residence (you can also set it anytime from "Your data" in your portal) — that's what determines eligibility here, not where the sender happens to be registered.

That's the part we automate. From any message you've reported, you can open a request and we take care of finding the right contact, drafting the letter, and watching the clock — you just decide when to hit send.

You can start this straight from the extension's danger banner, right after reporting a sender — no need to open your portal first. Everything past "open a request" (reviewing the draft, authorizing it to send, choosing what happens next) still happens in your portal, where there's room to show it properly; the extension just links you straight there once a request is open.

1

Open a request

From a message you've already reported as spam, pick Access (get a copy of what they hold on you) or Erasure (make them delete it). This currently works for reporters based in the EU or UK — it's your own residence that matters here, not where the sender is, since data protection law lets you complain to your own country's authority regardless of where they're based.

2

Confirm it's really you

If the spam landed in the same inbox you're signed in with, you're already confirmed. If you're acting for a different address, we send a one-click confirmation link there first — nobody can open a request on an inbox they don't control.

3

Review, then send

We draft the formal request for you, in plain legal language, citing the right law. You read it, and only you decide when it actually goes out — one click authorizes us to send it on your instruction.

4

We watch the clock

The law gives them a set number of days to respond. We track it for you and nudge you as the deadline nears, so you never have to keep a calendar for this yourself.

5

If they go quiet

Missed the deadline? You can escalate to a settlement demand or a complaint to the relevant data protection authority. Either way, a certified reviewer checks it before it ever gets sent — we don't let anything adversarial go out on autopilot.

What we are, and what we're not: we draft and send the request at your instruction — we're not acting as your lawyer, and we don't represent you in front of any regulator. Every request we send says this plainly, and anything that could turn adversarial always passes a certified reviewer first.

This works alongside reporting spam — you need to have reported the message first — and requires being signed in; see Your account for how that works.

For organizations

If you run security for a company, you can go further than an individual can: from your organization's console, challenge a sender your team has reported to substantiate the lawful basis and origin of any employee data it holds — not a request on one person's behalf, but your organization raising the question in its own capacity. Every challenge is reviewed by a certified reviewer before it's sent, the same as an individual's escalation above. This capability is rolling out gradually as we complete legal review in each jurisdiction — if it's not yet available for a sender's country, you'll see a clear message saying so rather than a silent failure.