Glossary
Terms used on this site and in privacy law, defined so each definition stands on its own.
- AI training data
AI training data is the collection of text, images, audio or other material that a machine-learning model learns from. When training ends, what the model learned is held in its weights, and the model no longer needs the original files to run.
Large image datasets are often built from material that is publicly reachable on the web, and some consist of links and captions instead of the images themselves. Removing a source image or a dataset entry affects future training, not models that were already trained.
Related: Dataset, Model weights, Objection, Image cloaking. See also: ai training data, can ultopulto remove me from an ai model, eu.
- Biometric data
Biometric data is information derived from a person's body or behaviour, such as a face scan, fingerprint, iris scan or voiceprint, that can be used to identify that person.
The GDPR defines it as personal data resulting from specific technical processing of physical, physiological or behavioural characteristics that allows or confirms unique identification. Illinois law lists a scan of face geometry as a biometric identifier but excludes ordinary photographs, so the legal line usually falls at the point where a photo is processed into a signature.
Related: Face embedding, Face search, Privacy right. See also: illinois, eu, face search.
- Content Credentials
Content Credentials are cryptographically signed metadata attached to an image, video or audio file that record where it came from and how it has been edited. They are based on the open C2PA standard.
A related specification lets a creator state inside the credentials whether a file may be used for data mining or AI training. That statement is a signal that others can read and choose to respect; it does not technically prevent copying or training.
Related: Deepfake, Image cloaking, AI training data. See also: deepfakes, ai training data.
- Data broker
A data broker is a business that collects personal information about people it has no direct relationship with and sells or shares that information with others.
People-search sites are one type of data broker. California requires data brokers to register with the state each year and to process deletion requests sent through its DROP platform.
Related: People-search site, Opt-out, Deletion request, Authorized agent. See also: data brokers, california, us federal.
- Data minimization
Data minimization is the principle that an organisation should collect and keep only the personal information it needs for a stated purpose, and no more.
It is one of the core principles of the GDPR. For an individual, the same idea applies in reverse: the fewer places that hold your details, the fewer places they can leak or be resold from.
Related: Privacy right, Data broker, Deletion request. See also: eu, uk, data breaches.
- Dataset
A dataset is an organised collection of data. In AI, the word usually means the set of examples, such as images paired with captions, that is assembled to train or test a model.
Some large image datasets hold only web links and captions, not the images. In that case the image stays wherever it is hosted, and the dataset entry and the hosted image have to be dealt with separately.
Related: AI training data, Model weights, Deletion request. See also: ai training data, can ultopulto remove me from an ai model.
- Deepfake
A deepfake is an image, video or audio recording created or altered with AI so that it realistically shows a real person saying or doing something they did not say or do.
The US TAKE IT DOWN Act uses the term "digital forgery" for intimate images created or altered with software or AI, and requires covered platforms to remove them within 48 hours of a valid request.
Related: Impersonation, Content Credentials, AI training data. See also: deepfakes, impersonation, us federal.
- Deletion request
A deletion request is a formal request asking an organisation to erase the personal information it holds about you, made under a law such as the GDPR's right to erasure or California's CCPA.
The law sets a response time, generally one month under the GDPR and 45 calendar days under the CCPA, each of which can be extended. Organisations can refuse in listed circumstances, for example when they must keep the data to meet a legal obligation.
Related: Privacy right, Objection, Opt-out, Evidence record. See also: california, eu, uk, transparency.
- Doxxing
Doxxing is publishing someone's private or identifying information, such as a home address, phone number or workplace, without their consent, usually to harass, threaten or intimidate them.
The information is often gathered from sources that are individually public, such as people-search listings and old social posts. Reducing those listings makes a person harder to locate.
Related: People-search site, Data broker, Face search, Impersonation. See also: doxxing, data brokers, face search.
- Evidence record
An evidence record is the record UltoPulto keeps for every action it takes: the request, the recipient, the legal basis, the timestamps, the response and the current status.
The record exists so that a person can check what was done for them and, if needed, show it to a regulator. A case is marked as confirmed removed only after the removal has been verified.
Related: Exposure Score, Personal Exposure Management, Deletion request, Authorized agent. See also: transparency, methodology.
- Exposure Score
Exposure Score is UltoPulto's 0 to 100 measure of how exposed a person's identity is across the sources UltoPulto checks. The method used to calculate it is published at ultopulto.com/methodology.
It is UltoPulto's own measure, not an industry standard, and it covers only the sources UltoPulto checks. The score changes as cases are confirmed removed or as new exposures are found.
Related: Personal Exposure Management, Evidence record, Data broker, Face search. See also: methodology, transparency.
- Face embedding
A face embedding is a list of numbers that a face-recognition model computes from a photo of a face, so that photos of the same person produce similar lists. Comparing two embeddings lets software estimate whether two photos show the same person.
It is also called a face template, face signature or face fingerprint. An embedding is not a picture and cannot be viewed as one, but because it can identify a person it is generally treated as biometric data.
Related: Biometric data, Face search, Model weights. See also: face search, methodology, illinois.
- Face search
Face search is looking up a person by uploading a photo of their face instead of typing their name. A face-search engine compares the uploaded face with an index built from photos collected from public web pages and returns links to pages where similar faces appear.
Opting out of a face-search engine removes or blocks its index entries for your face. It does not remove the photos from the websites that host them.
Related: Face embedding, Biometric data, Opt-out, Doxxing. See also: face search, illinois, eu.
- Image cloaking
Image cloaking is making small changes to an image, designed to be hard for people to notice, that interfere with how AI systems interpret it.
Glaze, from the University of Chicago, is a well-known example built to protect artists against style mimicry, and its authors state that it is not a permanent solution. Cloaking only affects copies published after it is applied, not images already collected.
Related: AI training data, Content Credentials, Face embedding. See also: ai training data, face search.
- Impersonation
Impersonation is pretending to be another real person, for example with a fake account, copied photos or a cloned voice, in a way that could mislead other people.
Most large platforms prohibit it and accept reports from the person being impersonated. Synthetic media has made convincing impersonation easier to produce.
Related: Deepfake, Doxxing, Privacy right. See also: impersonation, deepfakes.
- Model weights
Model weights are the numbers inside a trained AI model that are adjusted during training and that determine how the model responds to input. They are the stored result of training.
Weights are not a database with one entry per person. Each training example nudges a very large number of weights slightly, and those effects are blended with the effects of everything else the model saw, so there is no single record to find and erase. Reliably removing one person's influence without retraining the model is still a research problem, which is why no service can honestly promise to remove you from a model that has already been trained.
Related: AI training data, Dataset, Objection, Face embedding. See also: can ultopulto remove me from an ai model, ai training data, transparency.
- Objection
An objection is a formal request asking an organisation to stop using your personal information for a particular purpose. Under the GDPR and UK GDPR, the right to object applies when the organisation relies on legitimate interests or a public task, and it must stop unless it can show compelling grounds to continue.
People use it to object to their data being used for future AI training. An objection does not by itself delete data, and it does not change a model that has already been trained.
Related: Privacy right, Deletion request, AI training data, Model weights. See also: eu, uk, ai training data, can ultopulto remove me from an ai model.
- Opt-out
An opt-out is an instruction telling an organisation to stop a specific use of your information, such as selling it, sharing it or showing it in search results.
An opt-out often hides or suppresses a listing without erasing the underlying record, and a listing can return when the organisation receives new data. That is why opt-outs need to be re-checked.
Related: Deletion request, People-search site, Data broker, Face search. See also: data brokers, face search, california.
- People-search site
A people-search site is a type of data broker that compiles information from public records, social media and other brokers into a report about a named person, and sells or displays those reports.
A report can include current and past addresses, phone numbers, age and the names of relatives. Most sites offer an opt-out, which has to be made separately on each site.
Related: Data broker, Opt-out, Doxxing. See also: data brokers, doxxing, california.
- Personal Exposure Management
Personal Exposure Management is the practice of continuously finding, acting on, verifying and monitoring the places where a person's identity can be exposed or misused. UltoPulto uses the term to describe its approach.
It treats exposure as something that changes over time, because listings reappear and new sources emerge, so a single round of removals is not the end of the work.
Related: Exposure Score, Evidence record, Opt-out, Deletion request. See also: methodology, transparency, data brokers.
- Privacy right
A privacy right is a legal entitlement a person has over personal information that organisations hold about them, such as the right to see it, correct it, have it deleted, or object to how it is used. Which rights apply depends on where the person lives and which law covers the organisation.
Examples include the rights of access, erasure and objection under the GDPR and UK GDPR, and the rights to know, delete and opt out of sale under California's CCPA.
Related: Deletion request, Objection, Opt-out, Authorized agent. See also: california, eu, uk, illinois, us federal.