Skip to content

Demo site. Fictional data; nothing is sent to anyone. Open the guided demo

Methodology

How UltoPulto measures exposure, decides what counts as removed, and what it does when an organisation refuses. Written so that a journalist, a regulator or a sceptical customer can check our work.

Last updated · Method version 1.0 · Maintained by UltoPulto

01Principles

  • Every result is either something we observed directly or something we ask you to check. We do not infer or guess.
  • A check that could not run is reported as not checked. It never counts for or against you.
  • The score is explainable: every point traces to a finding you can open.
  • Removal is a claim that needs evidence. See verification.

02The Exposure Score

The UltoPulto Exposure Score is a number from 0 to 100. Lower is less exposed. It is the sum of points across four dimensions. Each dimension has a cap so that one noisy source cannot dominate.

Exposure Score dimensions, points and caps
DimensionPoints per findingCapNotes
People-search and broker listings535Name, address, phone. A listing found by name and area carries confidence 0.8, so it adds 4 points.
Face-search engines1530Counted only when you confirm your face is indexed by an engine.
AI dataset indexes1020A match of your face signature above the similarity threshold; scaled by confidence.
Breach records215Each known breach that includes one of your email addresses.

Points for a finding are multiplied by its confidence, between 0 and 1. The total is capped at 100. Bands: 0–19 Minimal, 20–39 Low, 40–59 Moderate, 60–79 High, 80–100 Severe.

Baseline and current. The score at your first scan is your baseline. Your current score is recalculated from your latest scan, leaving out findings whose case has reached Confirmed removed. It moves only when removal is confirmed, not when a request is sent.

Not yet measured. Impersonation, deepfakes and voice are not part of the score today because we do not yet monitor them. Address, phone and email exposure are measured together through people-search listings rather than separately. When a dimension is added, the method version changes and this page says what changed.

The weights are a product decision, not a scientific constant. They reflect our judgement that being findable by face is harder to undo than a listing, and that a listing matters more than an old breach. We will revise them with real outcome data and record the change here.

03How sources are evaluated

People-search sites
We open the public results page for your name and area once, identified honestly as UltoPulto. Text markers on the page tell us whether a listing appears. A 403, a rate limit or a bot check is recorded as “could not check”.
Breach records
Email addresses you give us are checked against Have I Been Pwned. The lookup sends the email address to that service.
Face-search engines
Their terms forbid automated queries. You run the engine’s own search and tell us the result. We never query them for you.
AI dataset indexes
A face signature computed in your browser is compared with an index of signatures built from images listed in public datasets. A match above the threshold is a lead to verify. This check is in rollout.

A source is added to the registry only with a recorded decision on its terms and robots rules, its opt-out route and a verified privacy contact. We drop a source that objects to being checked.

04What counts as confirmation

A case is marked Confirmed removed only when one of these is true:

  • The organisation says in writing that the data was removed or suppressed, and the reply is stored on the case.
  • A re-check of the source after the request no longer finds the listing.
  • You tell us it is gone, for sources only you can check.

Sending a request does not count. An acknowledgement does not count. A confirmed case is re-checked later, and if the listing is found again the case becomes Reappeared.

05When an organisation refuses or ignores a request

Each request carries the legal deadline for your jurisdiction. If it passes without a substantive reply, a follow-up is sent. If that is ignored too, UltoPulto drafts a complaint to the regulator with jurisdiction, built from the evidence on the case, for you to review and sign. Where no regulator has jurisdiction, the case goes to our team to look at other routes.

A refusal is recorded as Refused, with the organisation’s reason. We do not relabel it.

06How jurisdiction affects requests

Where you live decides the law a request relies on, the deadline and the regulator. The mapping the product uses is published in the privacy rights finder and explained in the privacy law pages. Where no privacy law gives you a right, the request relies on the organisation’s own published opt-out procedure and says so.

07How often monitoring runs

Re-scans
Weekly on Plus and Creator, monthly on Essential. You can also start one manually once a day.
Removal re-checks
14 days after a request, then every 90 days once removal is confirmed.
What a re-scan does
Compares findings with the previous scan, records what is new and what is gone, opens cases for new findings your plan covers, and sends one message if anything is new.

08False positives and wrong matches

A listing found by name and area may belong to someone else with the same name. It is shown as “likely listed”, carries a confidence below 1, and you decide whether it is you before any request goes out. A dataset match is shown with its similarity and is a lead, not proof.

If a finding is wrong, close the case. It stops counting toward your score.

09What UltoPulto cannot do

  • Remove a person from an AI model that is already trained. Why, and what can be done instead.
  • See sources that are not in its registry, private databases, or anything behind a login.
  • Make an organisation comply. It can ask correctly, track, follow up, document and help you escalate.
  • Give legal advice. UltoPulto is not a law firm.

10Change log

1.0 · 2026-10-04
First published method: four dimensions, caps of 35, 30, 20 and 15, baseline and current scores.