SpyCloud Opt Out: Request Deletion and Understand Exceptions
Use SpyCloud’s official privacy portal to request deletion. See required fields, identity checks, cybersecurity exceptions, and practical follow-up steps.

To request a SpyCloud opt out or deletion, start at its official Data Rights Request page and follow the Osano portal. Choose the relevant request, enter the identifying details and complete any verification the company requires. SpyCloud warns that breached or illicit-source information used for cybersecurity may be retained under applicable exceptions.
That limitation matters: filing a request is not a promise to erase leaked credentials from threat-intelligence systems or from the internet. We inspected the current privacy notice and blank deletion form on October 1, 2026. No request was submitted, and no removal result was tested.

Understand which information you are addressing
SpyCloud's privacy policy describes business and website information as well as threat-intelligence processing. Your request might concern a business contact record, an account relationship or information associated with a breach. Identify the context before deciding what to ask the company to do.
The notice says some licensing of threat intelligence can qualify as a sale under certain state privacy laws. It also describes separate advertising-related disclosures. Those are different activities, so changing a browser cookie preference does not demonstrate deletion from a security dataset.
| Objective | Route or action | What it cannot establish alone |
|---|---|---|
| Ask for deletion | Official Data Rights Request portal | That every retained security record must be erased |
| Ask what is held | Relevant information-rights request | That an access response also performs deletion |
| Limit website advertising disclosures | Your Privacy Choices control | Removal from threat-intelligence processing |
| Protect a compromised account | Change affected credentials and security settings | Deletion of copies already held by unrelated parties |
Submit the request through the official portal
1. Follow the provider-owned starting page
Open the SpyCloud Data Rights Request page from the company's site. The public route leads to an Osano-hosted interface. Using the official link helps distinguish the intended portal from unrelated pages or messages that happen to use the company name.
In our browser check, choosing Delete my personal information opened a form for the individual's email, first name, last name and requestor type. A separate checkbox covered submitting on someone else's behalf. We did not enter consumer details or proceed through the final submission.
2. Select the right relationship
The requestor-type choices observed were Current or former employee, Individual and Other. Choose the one that honestly describes your relationship. An employment request can have different records and responsibilities from a request about personal information in a security dataset.
Use an email address you control and can monitor. If you believe a different address is associated with the relevant record, ask how to identify it securely. Do not send passwords, authentication codes or a dump of breached information as an unsolicited attachment.
3. Keep a useful request record
Record the date, the request type and the portal used. Save any case reference returned after you submit your own request. If SpyCloud asks for verification, respond through the verified channel and retain the request history so you can distinguish acknowledgment from a final decision.
- Start from the current official privacy notice or rights page.
- Select deletion only if deletion is the action you want reviewed.
- Enter the individual's details and the correct requestor relationship.
- Mark representation only when you are authorized to act for that person.
- Keep the acknowledgment and read any follow-up before assuming completion.
These steps describe the inspected public controls and a practical recordkeeping approach. No email challenge, CAPTCHA, identity check or completed deletion was tested. Later steps can depend on the request and the person making it.
Why might SpyCloud retain information?
The policy explicitly describes exceptions for personal information collected from breached or illicit sources for cybersecurity, fraud prevention and public-interest purposes. It also identifies legal and compliance retention. Therefore, a refusal to delete a particular security record cannot be evaluated from the presence of a request form alone.
Ask for a clear response identifying the request outcome and any relevant exception. That helps distinguish a matching failure, a verification problem and a substantive retention decision. These are different problems and may call for different follow-up information.
An access request and a deletion request should also be tracked separately. Learning that an email appears in a dataset is not proof that an account is currently compromised. Conversely, a successful deletion response would not restore the secrecy of a password that was already exposed elsewhere.
For another provider with a fraud-prevention context, see the Telesign privacy-request guide. Its phone-data workflow differs from SpyCloud's portal. Neither guide should be read as a guarantee that all security processing is subject to unconditional deletion.
Verification, timing and contact limitations
SpyCloud says it will request information needed to reasonably verify identity and respond within the period required by applicable law. The reviewed notice does not give a single completion promise for every person, dataset and request type. Avoid turning a legal response period into a measured removal time.
The general rights section directs requests to the portal and says email or phone requests are not processed. A California-specific section separately lists a telephone option. Because those statements differ in scope, this guide recommends the portal consistently linked from the current notice instead of promising that an email or call will work universally.
Authorized-agent requests may require signed permission or a valid power of attorney, and the company can still verify the individual. Do not check the representative box merely because you are helping someone understand the instructions. The person submitting should follow the applicable authorization process.
Where an appeal is available, use the instructions applicable to your location and the decision received. A reasoned follow-up with the case reference is more useful than submitting the same request repeatedly without addressing a verification question.
What to do about exposure that remains
If your concern began with a breach alert, treat account protection as a separate task. Change reused or exposed passwords at the affected services, review recovery settings and enable stronger authentication where offered. Do not wait for a privacy-request decision before securing an account you believe is at risk.
For public contact information, the data-broker opt-out directory helps identify other companies to address individually. The general removal walkthrough explains why source records, broker copies and search results can require different actions.
Reappearance risk depends on what remains available and whether new data is collected. An old case response is valuable evidence for a later follow-up, but it cannot guarantee that unrelated parties never obtain another copy. Preserve the outcome and the identifiers covered without storing sensitive breach contents unnecessarily.
The opt-out guides hub organizes additional provider routes. A free privacy scan can help find supported public exposure; it is not a search of SpyCloud's private threat-intelligence holdings and cannot certify their deletion.
If your concern also involves phone-based identity signals, the LexisNexis guide provides another distinct request route.
Frequently asked questions
Will a request delete my leaked password everywhere?
No. A request to one company does not erase copies held by unrelated parties or reverse a disclosure. Secure the affected account separately. The company's own notice also describes security-related retention exceptions that may affect its response.
Can I use email instead of the portal?
The general information-rights instructions point to the dedicated portal and say email and phone requests are not processed. A separate California section includes a phone option. Starting with the current provider-linked portal avoids relying on an email route the general notice rejects.
Is an acknowledgment evidence of removal?
An acknowledgment means the request has reached a stage in the process, not necessarily that the requested action is complete. Read the final response for the scope, any retained categories and the reason for an exception. Keep that response with the original case reference.
Is there a guaranteed number of days?
The inspected notice refers to the time period required by applicable law rather than one universal completion deadline. Your acknowledgment or response may provide more specific timing. If the stated date passes, follow up on the existing case with the date and request type.
Should I submit passwords to help matching?
No. The observed initial form asks for basic identifying details, not account passwords. Ask the privacy team how to supply any additional identifier securely. Sharing live credentials introduces a separate risk and is not justified by a general verification statement.
Sources and inspection notes
The current SpyCloud privacy policy and Data Rights Request page were checked on October 1, 2026. Browser evidence records the provider-linked Osano deletion form. We observed required fields and the representation option but did not submit personal information, complete verification or measure a response.
Continue reading
Related privacy guides
DuckDuckGo vs Privacy Bee: Data Removal Compared in 2026
Compare DuckDuckGo and Privacy Bee data removal: current prices, local processing, coverage definitions, managed support, and which approach fits you.
Read articleWarmly Opt Out: Remove Your Profile and Limit Data Sharing
Use Warmly’s privacy form to request profile removal or a sale opt-out. Learn the fields, verification steps, retained email preference, and follow-up.
Read articleWindfall Opt Out: Request Deletion and Stop Data Sales
Use Windfall’s privacy choices and request portal to opt out or ask for deletion. Understand address matching, identity checks, and customer-data limits.
Read article