Privacy Rights Request
How to ask this editorial site what it holds about you, have it deleted or corrected, or opt out — under the California Consumer Privacy Act, other US state laws, and the GDPR. Updated: September 3, 2026.
Summary
Clothoff AI is a static review site with no accounts, no uploads, and no image processing, so the personal information it can hold about a visitor is limited to server logs, pseudonymous Google Analytics data, and emails you have sent. This page explains which rights apply, how to send a request, how identity is checked, and how fast we answer. It is informational, not legal advice; the data inventory itself is in the Privacy Policy.
- Channel: privacy@clothoff.ai. As a business that operates exclusively online, the site may offer email as the request method under Cal. Civ. Code §1798.130(a)(1)(A).
- Deadlines: confirmation within 10 business days, answer within 45 calendar days (CCPA); answer within 1 month (GDPR).
- Cost: free.
- Opt-out of sale or sharing: also available instantly through Global Privacy Control, see Do Not Sell or Share My Personal Information.
Your Rights
The table maps each right to its legal source and to what it means on this site. US rights are stated for the CCPA/CPRA; comprehensive laws in 18 other states grant similar rights, and we apply the same procedure to every visitor regardless of residence.
| Right | CCPA/CPRA | GDPR (EU, EEA, UK) | What it means here |
|---|---|---|---|
| Know / access | §1798.110, §1798.115 | Article 15 | A copy of emails you sent us and, with your _ga cookie ID, the analytics events linked to it. Categories and purposes are already published in the Privacy Policy. |
| Delete | §1798.105 | Article 17 | Deletion of your emails and of analytics data for your cookie ID via Google’s user-deletion tool. Server logs expire on their own within 30 days. |
| Correct | §1798.106 | Article 16 | Correction of inaccurate personal information — in practice, the contents of correspondence, since analytics data holds no facts about you. |
| Opt out of sale or sharing | §1798.120 | Article 21 (object), Article 7(3) (withdraw consent) | Stop the potential sharing of analytics cookie data; also instant via Global Privacy Control. |
| Portability | §1798.130(a)(3)(B) | Article 20 | Your data in a portable, machine-readable format — a plain-text or CSV export of correspondence and analytics events. |
| Restrict / limit sensitive data | §1798.121 | Article 18 | Not applicable: the site collects no sensitive personal information. |
| Non-discrimination | §1798.125 | — | Nothing changes after a request; the site is free and identical for everyone. |
The California Attorney General summarizes the core right: “You have the right to request that businesses disclose what personal information they have collected, used, shared, or sold about you, and why” (California Attorney General, CCPA). Under the CCPA, disclosures cover the 12 months preceding your request; you may ask for information beyond 12 months for data collected on or after January 1, 2022, unless that proves impossible or disproportionate (§1798.130(a)(2)(B)). Our retention periods are shorter than 12 months for everything except correspondence, so the lookback rarely matters.
How to Submit a Request
Send an email to privacy@clothoff.ai, or use the pre-filled button below, which opens your email client with a template. There is no web form because the site has no server-side code that could receive one; email keeps the request under your control and gives you a timestamped copy. Include the items in the table. Missing items delay a request but do not invalidate it — we will ask for what is needed.
| Field | Required? | Why we need it |
|---|---|---|
| Type of request | Yes | Access, delete, correct, opt out, portability, or several at once. |
| Email address | Yes | To answer you and to locate correspondence. Writing from the address in question is the simplest verification. |
_ga cookie value | Only for analytics data | The only key that links a browser to Google Analytics events. Find it in browser developer tools under Storage → Cookies → clothoff.ai. |
| Approximate dates and pages | Optional | Narrows the search in server logs, which are kept for 30 days at most. |
| State or country of residence | Optional | Lets us apply the correct deadline (45 days CCPA, 1 month GDPR). Not verified for opt-out requests. |
| Authorized-agent proof | If an agent submits | Signed permission from you; we may also confirm the request with you directly (CCPA Regulations §7063). |
Do not attach photos or identity documents. The site never processes images, and identity documents are neither needed nor wanted; the California Privacy Protection Agency’s regulations require businesses to avoid collecting new personal information for verification where the request can be verified with data already held (CCPA Regulations §7060, cppa.ca.gov).
Verification and Authorized Agents
The CCPA lets a business “require authentication of the consumer that is reasonable in light of the nature of the personal information requested, but shall not require the consumer to create an account” (§1798.130(a)(2)(A)). Because the site holds so little, verification is proportionate and simple:
- Correspondence. A request sent from the same email address as the correspondence is treated as verified. A request about another address gets a confirmation email to that address.
- Analytics data. The
_gacookie value you provide is matched against the Google Analytics client ID. Nobody else can plausibly know that value, so no further proof is asked. - Server logs. Log lines contain only an IP address and user-agent; we can search them for an IP address you provide but cannot confirm that an address belonged to you. Where verification is impossible, we say so and delete the logs on schedule instead.
Authorized agents may submit requests to know, delete, or correct. Under CCPA Regulations §7063 we may require “proof that the consumer gave the agent signed permission” and may ask you to verify your identity or confirm the authorization directly with us. Requests to opt out of sale or sharing need no verification at all and may be sent by an agent or via a browser signal (§1798.135(c)).
Response Times and Appeals
CCPA/CPRA. We confirm receipt within 10 business days (CCPA Regulations §7021(a)) and respond within 45 calendar days of receiving a verifiable request; where reasonably necessary, that period may be extended once by a further 45 days with notice to you (§1798.130(a)(2)(A)). Opt-out requests are completed within 15 business days (Regulations §7026). If we do not act on a request, we tell you the reasons “without delay and at the latest within the time period permitted of response,” together with any right to appeal (§1798.145). You may make two free requests to know in any 12-month period.
GDPR and UK GDPR. Requests from EU, EEA, or UK residents are answered “without undue delay and in any event within one month of receipt of the request,” extendable by two further months where necessary given the complexity and number of requests (Regulation (EU) 2016/679, Article 12(3)). The ICO’s guidance mirrors this for the UK (ICO, A guide to subject access). If we refuse, we state the reasons and your right to complain to a supervisory authority (Article 77) or seek a judicial remedy.
Appeal. Reply to our decision with “Appeal” in the subject line. A different member of the editorial team reviews the case and answers within 45 days, explaining the outcome and, if it stands, how to complain to the California Privacy Protection Agency, the California Attorney General, your state’s attorney general, or your EU or UK supervisory authority. Several state laws — Virginia, Colorado, Connecticut, and others — require such an appeal route; we offer it to everyone.
Related Pages and Contact
What is collected and for how long: Privacy Policy. Cookie names and how to block them: Cookie Policy. Instant opt-out and Global Privacy Control: Do Not Sell or Share My Personal Information. Reports of non-consensual imagery involving a reviewed tool follow a separate, faster path: NCII report. General inquiries: Contact. Rules for the tools we review — your own photos or those of consenting adults 18+ only: Responsible AI.
Privacy Rights Request FAQ
What personal information can this website actually find about me?
Very little. The site has no accounts, uploads, or image processing. The only records are server logs (IP address, kept up to 30 days), Google Analytics data tied to a random cookie ID (kept up to 14 months), and any email you sent us (kept up to 24 months). A request can therefore return your emails and, if you send the cookie ID, the pseudonymous analytics events.
How is my identity verified without an account?
By matching the information you provide to what we hold. For emails, writing from the same address is sufficient. For analytics data, the _ga cookie value from your browser is the only link and is treated as the verification key. We never ask for government ID, and CCPA Regulations §7060 forbid collecting more data than needed to verify a request.
How long does a response take?
Under the CCPA, receipt is confirmed within 10 business days and a substantive answer follows within 45 calendar days, extendable once by a further 45 days with notice (§1798.130(a)(2)(A)). Under the GDPR, the answer comes within 1 month, extendable by 2 months for complex requests (Article 12(3)). Most requests here are simpler and finish sooner.
Can someone else submit a request for me?
Yes. An authorized agent may submit a request on your behalf. Following CCPA Regulations §7063, we may ask the agent for proof of your signed permission and may ask you to confirm the request directly. Parents or guardians may act for a person under 18, although the site is for adults only and knowingly holds no data about minors.
Can a request be refused?
Only in narrow cases: when identity cannot be verified, when the request is manifestly excessive or repeated, or when the data is needed to meet a legal obligation such as responding to a takedown notice. If we decline, we explain why in writing within the deadline, as §1798.145 requires, and tell you how to appeal or complain to a regulator.
What if I disagree with the outcome?
Reply to the decision email with “Appeal” in the subject; a different member of the editorial team reviews it and answers within 45 days. California residents may also contact the California Privacy Protection Agency or the Attorney General, and EU, EEA, and UK residents may lodge a complaint with their supervisory authority under GDPR Article 77.
Is there a fee?
No. Requests are free, up to two per 12-month period under the CCPA, and free under the GDPR unless manifestly unfounded or excessive. Should the same person send an unreasonable number of duplicate requests, we may decline further ones and will say so in writing; we will never charge for access, deletion, correction, or opt-out.