Internet & Culture

The People Selling You Data Removal Are Cousins With the Scrapers

The loudest names in paid data removal share a family tree with the internet's scraping infrastructure. I spent time checking the receipts, and the same holding company gets paid on both sides of the fence.

You know the sponsorship read. Your favorite YouTuber leans into the camera and explains that for somewhere between $16 and $46 a month, a service called Incogni will scrub your name, address, and phone number from the data brokers who trade in them. A recent video essay from the channel NeuroEverything pulled on that thread until a whole corporate family tree came out with it[1]. I have spent time since checking its receipts. Most of them hold up, a couple needed correcting, and the picture they add up to is stranger, and a good deal more systemic, than the pitch.

Start with the mechanics, because they contain the first problem. Before Incogni can ask a broker to delete your file, you give Incogni your full name, date of birth, home address, and phone number, and Incogni sends that bundle to hundreds of brokers to ask whether they have you. If a broker already had your file, fine, the request might work. If it did not, it has one now: accurate, current, and attached to a person demonstrably willing to pay monthly for privacy. Outside California and a handful of registry states, no American law compels the broker to do anything with the request except keep it. And handing over raw personal data is not even technically necessary. The proof shows up later in this story, from the company you would least expect.

Incogni's terms say it does not sell your personal data, and there is no evidence it does. The same terms permit sharing within its family of companies. Which raises the only question that matters: who is the family?

The illusion of independence

Incogni launched in early 2022 as a product of Surfshark, the VPN company. For years Surfshark and Nord Security, maker of NordVPN, denied persistent claims that they were connected, then in February 2022 they merged[2], becoming Lithuania's second unicorn at a $1.6 billion valuation, a figure that doubled to $3 billion in 2023 after a $100 million injection from the growth investor Warburg Pincus[3]. Both companies trace back to Tesonet, a Vilnius holding company founded in 2008, whose portfolio also touches the hosting company Hostinger, the eSIM brand Saily, and a stack of other consumer internet services[4]. It does not hurt that 'European tech' still carries an ethics halo in these conversations, or that a Baltic holding company draws far less scrutiny from the Western tech press than the same org chart would in Delaware.

The architecture of extraction

This family tree matters because Tesonet also operates the other side of the house. When scrapers want to harvest the web at industrial speed, ordinary datacenter IP addresses get blocked by anti-bot systems almost immediately, so the workaround is the residential proxy: routing the scraper's traffic through IP addresses belonging to ordinary homes and phones, which makes automated harvesting look like somebody's household browsing. Tesonet's Oxylabs advertises more than 175 million such residential IPs across 195 countries. Decodo, formerly Smartproxy, adds a claimed 125 million more, and Oxylabs acquired the budget provider Webshare on top[5]. By the essay's math, companies under this one roof control somewhere around 40 to 50 percent of the world's proxy market[1].

Collecting hundreds of millions of household IPs takes more than volunteers. The method the industry has historically leaned on is the covert SDK: a chunk of code embedded in free utility apps and mobile games that quietly turns the device into a proxy node and resells its bandwidth, and the person who installed the app, not the proxy firm, wears the risk when their home IP gets banned for whatever the scraper did with it[1]. Oxylabs says it sources its network ethically, pointing to an exclusive partnership with Honeygain, an app where users volunteer their unused bandwidth for pocket change. The arithmetic has a hole in it: community estimates put Honeygain's entire network at roughly 10 million devices. That leaves Oxylabs' other 165 million household IPs unexplained. And the partnership itself has been traced, executive by executive, to being an arrangement between Oxylabs and itself, with personnel moving between identical roles at the two companies under the same Tesonet umbrella[6].

Put the two halves of the portfolio next to each other and the business model reads plainly enough: one family of companies charges you a monthly fee to petition data brokers on your behalf, while operating a large share of the infrastructure the brokers' suppliers use to gather data at scale. Nothing about that is illegal. Everything about it is worth knowing before you type your birth date into the form.

A conflict of interest with a face on it

Tesonet's conflict is structural, spread across holding companies and corporate registries, which makes it easy to file away as an abstraction and move on. For the personal version, look at OneRep, another big removal brand, which sells privacy services to individuals, medical professionals, and police departments. A 2024 investigation by Brian Krebs found that OneRep's founder and CEO, Dimitri Shelest, had founded dozens of people-search sites, and domain records tied him to Nuwber, a broker OneRep charges to remove people from[7]. Shelest admitted founding Nuwber in 2015, around the same time he launched OneRep, and defended the ongoing stake by arguing that insider knowledge of the people-search business is what makes OneRep's removal technology good. Mozilla, which had bundled OneRep into Firefox Monitor, announced it would walk away[8], and still took until late 2025 to finish walking[9].

And here is the proof I promised earlier, from the direction I did not expect. OneRep, of all companies, gets this part of the engineering right. It interacts with brokers through email aliases and virtual phone numbers, as do competitors like Optery, so the opt-out process never hands a broker a fresh, verified copy of your real details. The removal service with the compromised founder never leaks your identity to the brokers, while the one owned by a privacy conglomerate demands it up front. That answers the question from the mechanics: transmitting your real name, address, and birth date is a design choice, not a requirement. The people best positioned to sell you the antidote keep turning out to be the people who bottled the poison.

The regulators aren't coming

The essay's grimmest claim is about Europe, and it is the one that needed the most correcting, so let me do that in public. The claim was that EU regulators received 10,000 complaints and acted on seven. The reality is more bureaucratic. Under GDPR's one-stop-shop rule, a multinational answers to the regulator where it is headquartered, and because tech companies flock to Dublin for the tax treatment, the under-resourced Irish Data Protection Commission is the de facto lead regulator for most of Big Tech. Its 2020 annual report shows it handled 10,151 cases that year, received 4,660 formal GDPR complaints and concluded 4,476 of them, mostly through amicable resolution, and served punitive enforcement notices over cookies and tracking technologies on precisely seven organizations[10]. So no, not seven actions out of ten thousand. Seven punitive actions, though, is the accurate number, complex cross-border cases have queued for years at a time, and I am not sure the corrected version is more comforting.

The United States does not need correcting because there is barely anything to correct. There is no federal removal right. A few states run broker registries, and Texas caps annual fines at ten thousand dollars, a number a data broker can lose in a couch cushion. A broker weighing that fine against opening its database to deletion mandates does not need a calculator. The EFF found hundreds of known brokers simply declining to register at all[11]. This is the same regulatory vacuum that lets a sports arena run facial recognition against its owner's enemies list[13]; the data market is what that vacuum looks like at wholesale.

What actually works

One genuinely new thing arrives next month. California's Delete Act requires the state's privacy agency to run DROP, the Delete Request and Opt-Out Platform, slated for August: a resident files one free request and every registered broker in the state, more than 600 of them, must delete their data within 45 days and not reacquire it[12]. It covers Californians and registered brokers only, which is two asterisks wide enough to drive a scraper through, but it is the first removal mechanism in America with actual teeth, and it costs nothing.

For everyone else, the boring advice remains undefeated. Data you never hand out does not need removing: aliases and virtual numbers by default, real details only for people with a legal reason to have them. And hold a permanent, healthy skepticism toward anyone charging a monthly fee to erase you from the internet, because as far as I can tell, the only party in this whole economy guaranteed to end up with your data is the one you paid to make it disappear.

Sources

  1. The Incogni / Tesonet video essayYouTube (NeuroEverything)
  2. Surfshark and Nord Security are getting aboard to secure people's digital livesSurfshark
  3. Surfshark and Nord Security double valuation to $3BSurfshark
  4. TesonetWikipedia
  5. Oxylabs Acquires Webshare Software CompanyOxylabs
  6. Connecting HoneyGain to NordVPN and Parent Company OxyLabsHacker News
  7. CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search FirmsKrebs on Security
  8. Mozilla Drops Onerep After CEO Admits to Running People-Search NetworksKrebs on Security
  9. Mozilla Says It's Finally Done With Two-Faced OnerepKrebs on Security
  10. Data Protection Commission publishes 2020 Annual ReportIrish Data Protection Commission
  11. Why Are Hundreds of Data Brokers Not Registering with States?EFF
  12. About DROP and the Delete ActCalifornia Privacy Protection Agency
  13. The Arena That Uses Face Scanning to Ban Its Owner's Enemiescasually.onl