your data · their servers · one request away

They have your data. Open a pull request.

DoorDash knows your address history. Uber has every trip. Spotify logs your 2 a.m. spirals. Under California law they have to hand it over when you ask — most people just never ask. We ask. Formally, legally, on your behalf. Then we pull what comes back out of their silos and into a file you own.

Open my pull request → See the demo

CAL. CIV. CODE §1798.110 · 11 C.C.R. §7063 (AUTHORIZED AGENT) · 45-DAY STATUTORY RESPONSE

privacy desk — session 001
$ pr open --all --right-to-know # acting as your authorized agent (11 CCR §7063) → doordash request sent · day 0 → uber request sent · day 0 → spotify request sent · day 0 ⏱ statutory clock started — response due day 45 # we chase. you get the file. $

How it works

Like a pull request, but the repo is you.

You could send these requests yourself — the law lets anyone, and our templates are public. It also lets you appoint an authorized agent to run the whole thing. That's the service.

git config
1

Sign once

E-sign a single designation. Under 11 C.C.R. §7063 that makes us your agent — no notary, no power of attorney, no lawyers. Companies can verify your signature themselves at a public link we include in every request. Revoke anytime.

pr open --all
2

Pick a bundle

One click queues a whole set — the five companies that actually answer, your shadow files, your government file, the brokers. No hunting for privacy pages.

merge
3

We send, you watch

Legal letters go out automatically where a letter works, and you get a guided walkthrough where the company's own export tool is faster. We track every 10- and 45-day deadline and flag the ones who blow it.

What we pull

Your data lives in five different places.

Most privacy tools only touch the first one. Your rights are different at every layer — and the deepest files are the ones nobody thinks to ask for.

LAYER 1 · CCPA §1798.110

The apps you use

DoorDash, Netflix, Uber, your grocery app. Order history, precise location at every purchase, the segments they sold about you. We send these as legal letters.

LAYER 2 · FCRA §1681g

Your shadow files

The dossiers you never signed up for: your payroll history at The Work Number, your prescription history at Milliman, insurance claims at LexisNexis, your banking record, even your retail returns. Federal law, all 50 states, usually free.

LAYER 3 · PRIVACY ACT / FOIA

Your government file

Every border crossing, every dollar ever reported under your SSN, your FBI file. Mostly free — and a few come back instantly.

LAYER 4 · THE BROKERS

Who sells you

Acxiom, LiveRamp, Epsilon and the bureaus' marketing arms. This is where the inferences live — the income band, the health guesses, the identity graph tying your devices together.

LAYER 5 · THE PLATFORMS

Big tech's archive

Apple, Google, Meta, Amazon hold the most by volume — recordings of your voice, your location timeline, every site that reported you back to Facebook. Their own export tools beat a legal letter, so we walk you through them click by click.

THE HONEST PART

What we can't reach

Data plumbers like Tealium and Palantir are processors — the law routes your rights through the company you actually dealt with, so our Layer 1 letters reach into their pipes. Anyone promising to "delete you from Palantir" is selling something.

$10
per pull · no subscription
  • One pull = requests to every company you pick
  • 45 days of deadline-chasing included
  • Responses parsed into your file — yours to export
  • Escalation letter drafted free if they stonewall

Why so cheap

Because it's your data.
We're just the crowbar.

The privacy industry loves a $15/month forever-subscription. We think that's backwards — the law does the heavy lifting here, and we're honest about it. Ten bucks covers the desk: sending clean requests, chasing the clock, parsing the mess that comes back. Run one pull out of curiosity or run one a year as hygiene. No lock-in, no upsell, and everything we learn about how companies respond goes back into the public playbooks.

Open source

The playbooks are public. PRs welcome — obviously.

Every company's privacy contact, request template, verification quirks, and actual response behavior — maintained in the open like an awesome-list. Self-hosters: take the templates and send your own requests, genuinely. Pay us only if you want the desk, the tracking, and the parsing.

playbooks/doordash.md
# DoorDash — Right-to-Know playbook method: email contact: [email protected] subject: "Authorized Agent Request" requires: signed authorization attached, consumer status (User/Dasher), right being exercised verify: emails the consumer directly sla: ack day ~3 · response day ~31 last-conf: 2026-07-19 ← PRs keep this fresh

The law is on your side

This isn't a loophole. It's a right — written into statute.

CAL. CIV. CODE §1798.110

The Right to Know

California residents can demand any covered business disclose the categories and specific pieces of personal information collected, its sources, the purpose, and every third party it was shared with.

11 C.C.R. §7063

The Authorized Agent

The regulations expressly let a consumer appoint a business to submit requests on their behalf with simple signed permission. Companies may not demand a power of attorney.

§1798.130 · §1798.145

The Deadline

Acknowledgment within 10 days. A full response within 45. Companies that stall or stonewall face enforcement by the California AG and the Privacy Protection Agency.

600+

data brokers registered in California alone — companies whose entire business is your information.

45 days

the statutory clock a company is on from the moment our request lands in its privacy inbox.

19 states

now grant access rights like California's — and most national brands honor requests from anyone, anywhere.

merge when ready

Your data has been
upstream long enough.

Sign the designation, pick a bundle, and we start sending. Ten dollars, no subscription, and the playbooks stay free either way.

Open my pull request →