Transparency
What UltoPulto can do, what it cannot, what is unfinished, and the rules it follows. If something on this site reads as more than what is written here, this page is the one that is right.
Last updated · Maintained by UltoPulto
01Where the company is
UltoPulto is pre-launch. The product is built and tested, and this public site runs it as a demo: the data is fictional, requests are simulated and nothing is sent to any organisation. Checkout on the demo is simulated too.
We publish this page before launch on purpose. It will be updated as each item below changes.
02What UltoPulto can do
- Find where your identity appears across the sources in its registry and summarise it as a score with a published method.
- Write requests for the law that applies where you live and send them as your authorized agent, or prepare them for steps only you can do.
- Track every legal deadline, follow up, and draft a regulator complaint when an organisation does not answer.
- Keep the evidence for every action, and re-check sources on a schedule.
03What UltoPulto cannot do
- Remove a person from an AI model that is already trained. Nobody can. The full answer.
- Guarantee that an organisation will comply, or how fast.
- See everything. It checks the sources in its registry, not the whole internet, private databases or the dark web.
- Act where the law or a site’s terms do not allow it, such as querying face-search engines on your behalf.
- Give legal advice. UltoPulto is not a law firm.
- Respond to emergencies. If you are in danger, contact local emergency services.
04Capability labels
- Built
- Works in the product today and can be tried in the demo. At public launch this label becomes “Live”.
- In rollout
- Built, and being switched on step by step.
- Planned
- Not built. Never shown as a screenshot and never priced as included.
Find
- Exposure ScanChecks people-search sites, known breaches, face-search engines (guided) and AI dataset indexes, and produces an Exposure Score. Breach lookups use the Have I Been Pwned service and need a licensed key, which is not yet connected; until then the demo shows sample breach results.
- Identity check before resultsDetails stay hidden until you confirm a code sent to the email you entered, and the same name can only be scanned a few times a day. This makes it harder to look up someone else; it does not prove the name is yours.
- Exposure Score with baseline and currentA 0–100 score with a published method. It changes as cases are confirmed removed.
- On-device face matchingFace detection and embedding run in your browser. The models are being added to the public build.
- AI dataset index matchingCompares a face signature with an index built from public dataset URL lists. The index is being built and reviewed.
Act
- Authorized-agent signatureA one-time, versioned authorization that lets UltoPulto send requests for you. Revocable.
- People-search and data-broker requestsRemoval and suppression requests written for the law that applies where you live.
- Requests to AI model providersAccess, deletion and objection requests to AI companies, by email or as guided portal steps with the letter prepared.
- Dataset takedown requestsTakedown requests to dataset hosts. Guided do-not-train registration is paused: the registry it used (Spawning) was offline when we checked on 4 October 2026.
- Face-search engine opt-outsGuided steps for PimEyes and FaceCheck.ID. Their opt-outs ask you for your own photo, so we do not automate them: you submit; we track and re-check.
- Takedown notices for deepfakes, intimate images and impersonationFormal notices to platforms, including the 48-hour duty under the US TAKE IT DOWN Act.
- Real delivery of requestsRequests are sent only to contacts our team has verified against the organisation's current privacy policy. Until a contact is verified the request stays a draft.
- Opt-out form automationScripted form filling for sites that allow it. We never bypass CAPTCHAs; a person completes those steps.
- California DROP filing helpGuided filing on California's Delete Request and Opt-out Platform and tracking of broker compliance.
Prove
- Evidence trail on every caseThe request, recipient, legal basis, timestamps, replies, deadline and status history for each case.
- Follow-ups and regulator complaint draftsA follow-up after the legal deadline, then a complaint draft for the right regulator for you to review and sign.
- Exportable evidence dossierA single document of everything found and done, for police, courts or regulators.
Monitor
- Scheduled re-scans and alertsRe-scans on a schedule, compares with the last scan, opens cases for anything new and tells you.
- Removal re-checksSources are checked again after a request to confirm removal and to catch re-listing.
- Impersonation and deepfake monitoringWatching platforms for fake accounts and synthetic media. Today you report what you find and we send the notice.
- Voice-clone monitoringNot built.
Prevent
- Image cloakingManaged protective changes to images before you post them.
- Content credentials with a do-not-train signalNot built.
Platform
- Family accountsProtecting several people, including children, from one account.
- UltoPulto for TeamsExposure management for employees and executives, with strict privacy boundaries between employee and employer.
- Privacy Intelligence APIRequest routing, jurisdiction rules and an opt-out registry for organisations.
05Current limitations
- Real delivery of requests is off on this site. In production it is switched on per organisation, only after our team has verified that organisation’s privacy contact.
- The people-search registry has eight sites. Established removal services cover hundreds.
- Face matching in the browser and the AI dataset index are in rollout; on this demo the selfie step is switched off.
- Face signatures and other personal data are stored in the service database and sent over HTTPS. Field-level encryption of signatures is not yet in place.
- There has been no independent security audit or penetration test yet.
- Legal and guidance pages are sourced to primary texts but have not yet been reviewed by a lawyer.
- Founder and reviewer profiles and a monitored contact address are not yet published.
- No removal-rate statistics exist yet, because no real requests have been sent. We will not publish numbers we cannot back with data.
06Privacy architecture
- Photos
- Never uploaded. The scan API does not accept images at all.
- Face processing
- Detection and embedding run in your browser. Only a numeric signature can be sent, and only with a consent tick. Without consent the API rejects it.
- Scan results
- Hidden until you confirm a code sent to your email. Before that, only the score and counts are returned, even to the API caller.
- Looking up other people
- Limited by email verification and by rate limits per network address, per email and per searched name.
- Accounts
- Sign-in by one-time emailed link. No passwords are stored.
- Ownership
- Scans and cases belong to one account and are not visible to others. Staff access to cases is limited to the operations console and every staff action is written to the case.
07Data retention
- Face signatures
- Deleted after 30 days, unless you are an active subscriber using monitoring, which needs them for re-scans. Deleted with the scan or account at any time.
- Scans and cases
- Kept while your account exists. You can delete any scan, or the whole account, yourself.
- Rate-limit records
- Stored as hashes, not raw addresses or emails, and purged after 7 days.
- Sign-in tokens
- Stored as hashes. Links expire in 15 minutes and work once; sessions last 30 days.
08Request delivery rules
- Every request identifies UltoPulto as your authorized agent and names you. No request pretends to come from you directly.
- A request is sent only after you have signed the authorization, and you can read every letter.
- A request is sent only to a contact our team has verified against the organisation’s current privacy policy. Unverified contacts stay as drafts.
- We ask for the minimum the organisation needs to find and delete your records.
09Automation and CAPTCHA policy
- We never bypass CAPTCHAs or bot protection. When a site asks for a human, a person at UltoPulto or you completes that step.
- We do not automate sites whose terms forbid it. Face-search engines are handled as guided steps for that reason.
- Automated checks identify themselves with an honest user agent and are rate-limited.
- People handle refusals, ambiguous identity checks, legal edge cases, escalations and sensitive takedowns.
- When automation cannot finish something, the product says “UltoPulto needs your help with this request”, and why.
10How we use AI
- Request letters are fixed templates filled with your details and the applicable law. A language model does not write or send them.
- Face detection and embedding use small machine-learning models that run in your browser.
- Pages on this site were drafted with AI assistance and checked against the primary sources they cite. Every article lists its sources and review date.
- Your data is not used to train AI models, ours or anyone else’s.
11Legal position
UltoPulto acts as an authorized agent under laws that allow one, such as the CCPA, and under your written mandate elsewhere. It is not a law firm, does not give legal advice and does not represent you in proceedings. Complaint drafts are prepared for you to review, sign and file.
Information on this site is general. For decisions that matter, check the primary sources we link and take advice.
12Security
The controls that are implemented, and the ones that are not yet, are listed on the security page.