● DROP is live — the first cycle is running now

Never miss a DROP cycle. Never hand us your data.

California's Delete Act put every registered data broker on a mandatory 45-day deletion cycle on August 1 — with fines of $200 per request, per day. Your first access is due within 45 days of go-live. PrivacyClock runs the cycle, proves the deletion, and keeps the audit trail. Your customer records are hashed in your browser and never reach our servers.

Run a cycle in the appAm I a data broker?

Published pricing from $299/mo — the only transparent price in the category.

Time left on the first cycle

Brokers must access DROP within 45 days of the August 1 go-live and every 45 days after — then report a status for every request, forever. The clock never stops.


475,000+deletion requests already filed by Californians
70%of registered brokers hadn't started processing in week one
$9,500California's registration fee in 2027, up from $6,000
Built for the brokers without a privacy team

If you sell leads, contact data, or marketing lists, this is now your problem.

Lead-gen, people-search, B2B enrichment, adtech — most SMB brokers have no privacy engineer, and the state sends no reminder. In August alone the CPPA fined two brokers $110,490 and $52,400; fourteen have now been penalized. Processing enforcement starts when the first 45-day windows close.

Am I even a data broker?

Registration is self-identifying and Texas just widened its definition. We tell you exactly where you qualify — before an enforcement letter does.

The 45-day treadmill

Pull the hashed deletion list, match it against your records, delete, report a status for every request, and prove it — every 45 days, forever.

Prove it later

Independent audits begin in 2028. Every match, decision, and filing is logged to an append-only evidence trail from day one.

How a cycle works

Three steps. Your data never leaves your browser.

01

Load

Drop in the deletion-list ZIP from the state portal. Upload your customer file — it's hashed locally, in your browser, before anything is sent.

02

Match

We compare the state's hashes against yours using the exact CPPA specification — validated against all 14 official test vectors. You get the exact rows to delete.

03

File

Review matches, record exemptions, and export the correctly-formatted Id,Status response files the state accepts.

04

Prove

Re-upload your data after deleting and we verify the records are actually gone — then screen every future list against the suppression set.

Try it on sample data
Why PrivacyClock

The layer the state portal refuses to build.

Hash-only architecture

DROP publishes only SHA-256 hashes — so do we. Your raw customer data is never uploaded, never stored. It's the whole security model.

Deletion you can prove

Most tools stop at 'here's a list.' We re-scan your data afterward and confirm the records are gone — the thing an auditor will actually ask for.

The suppression obligation, handled

Every unmatched request must be kept and screened against data you collect later, indefinitely. We keep that list and check new files against it automatically.

A published price

Every competitor hides pricing behind a sales call. We don't. $299–$499/mo, on the page, today.

What we store
# your upload, in your browser
maria.lee@example.com
↓ SHA-256 (local)
KA18MT/ph6IHYjzT9zwETySDQyvSh87…=
# what reaches our servers
just the hash + a match/no-match flag
Read the security model →

Your first cycle is already running.

Design partners get founding pricing locked at $199/mo and a concierge first cycle run alongside them — before the deadline, not after.

Founding price locked at $199/mo for the first ten. No card, no sales call required.

Or try the app on sample data →