1. Who handles data
Team Take Down is the service name for this application process. Privacy questions and requests may be sent to privacy@teamtakedown.xyz. If accepted for paid work, the separate Sprint Agreement will identify the contracting operator before payment.
2. Free Scan data
The optional Free Scan collects the creator or stage name you enter. Our public host processes the request and relays a valid network address to the private application only for abuse limits; the scan record stores keyed one-way hashes derived from the network address and normalized creator name, not the raw network address.
We send name-based search queries to our search-data provider to check public web results. The provider therefore receives the name or handle inside those queries. We transiently review returned public-result details and store only the creator name, aggregate page and domain counts, up to three observed domain names, query completion and failure counts, estimated monthly exposure ranges, status, timestamps, cost metadata, and a one-way hash of the private result token. We do not publish or return exact result URLs through the Free Scan.
A short-lived encrypted, HTTP-only browser cookie keeps the private scan token out of page URLs and browser scripts while the result is processing. The cookie and scan record expire after 24 hours under the current configuration. A partial provider run is labeled as partial and shows completed versus planned query counts; any scan can miss pages or return incorrect name matches.
3. Data collected on the application form
- creator or stage name, reply email, and your own public profile or handle;
- the number and general type of pages, plus whether they appear publicly accessible;
- adult, authority, minor-safety, scope, no-guarantee, Terms, and Privacy confirmations;
- submission time, application reference, status, document versions, and bounded referral/UTM fields;
- when you continue directly from an unexpired Free Scan and use the same creator name, a reference to that scan’s aggregate count, observed domains, coverage, partial status, and timestamp;
- a keyed one-way hash derived from email and a keyed one-way hash derived from the request network address for deduplication and abuse limits. The raw network address is not stored in the application table.
4. Data this public form does not request
Do not submit leak URLs, intimate media, files, government ID, legal name, home address, passwords, account credentials, payment-card details, or a legal notice. If qualified, exact URLs and required authorization use a separate secure process with additional terms.
5. Private intake and exact-request approval
A qualified applicant may receive a private link whose credential remains after the # fragment, is removed from the address bar before the form opens, expires automatically, and is stored by us only as a one-way hash. Opening the link does not submit an intake or approve a request.
The private intake collects a legal name, authority basis and limited representative-authority description when applicable, one to five exact public HTTPS URLs, and versioned adult, authority, good-faith, public-access, safety, scope, no-guarantee, and no-filing confirmations. It does not collect media, government ID, passwords, payment-card data, subscriber data, fingerprints, OCR, or facial embeddings.
If a request is prepared, the creator sees the complete request text, route, intended destination, version, and SHA-256 hash before making a separate approve-or-request-changes decision. Any edit creates a new packet and invalidates the prior approval. We record the approval receipt, filing destination/reference, per-URL observations, final-report reference, and processor payment or refund reference as needed to deliver and document the Sprint.
6. Why we use this data
We use it to return the requested aggregate Free Scan result, optionally keep that unexpired aggregate context with your application, enforce abuse limits, review Sprint eligibility and fit, contact you about the request, maintain an audit record of what you acknowledged, measure the founder-led application funnel, comply with safety obligations, and establish or defend legitimate claims. A linked scan is not creator approval and cannot create a case, request, or filing. A founder performs the qualification review; it is not an automated eligibility decision.
We do not sell application data or use intimate-content data for advertising.
8. Retention and deletion
Free Scan records and their encrypted browser context expire after 24 hours under the current configuration. Cached aggregate results preserve the original result timestamp and cannot extend the original retention deadline. When a linked scan expires and is deleted, its optional application reference is cleared automatically.
Submitted and qualified application records are scheduled to expire after 90 days. Rejected applications are scheduled to expire after 30 days. A lawful dispute, fraud, safety, accounting, or legal hold may require longer retention. Backup copies may remain access-restricted until ordinary backup rotation; we do not promise that backup deletion completes on the same date as the active record.
An accepted Sprint case is scheduled for retention review after 180 days. Case deletion does not run while a legal, safety, fraud, accounting, payment, dispute, or counsel-review hold remains active. When the applicable hold is cleared, the encrypted intake, URLs, packet text, and related case records may be deleted under the approved retention procedure; narrowly required accounting, authorization, filing, or defense records may be retained longer where law or legitimate claims require it. The signed Sprint Agreement will control if it states a more specific lawful schedule.
9. Security boundaries
Applications travel over encrypted HTTPS, pass through a server-side authenticated proxy, and are stored in a private database table unavailable to public and creator roles. Qualified cases use an isolated creator workspace, a dedicated encryption key separate from the general application secret, encrypted URLs and request text, hash-only expiring access credentials, no-store responses, no-referrer and no-index controls, and an append-only safe-metadata event trail. The private intake and approval pages do not load analytics.
No online service can promise absolute security. If a material incident affects this process, we will respond and provide legally required notice.
10. Access, correction, and deletion requests
You may ask to access, correct, or delete your application by emailing privacy@teamtakedown.xyz from the reply email and including the application reference if available. We may need a proportionate verification step and may retain limited records where law, safety, fraud prevention, or claims require it.
11. Adult-only and minor-safety policy
The application is only for adults. Do not submit an application if you are under 18 or the material depicts, or may depict, anyone under 18. We stop review where age is uncertain and follow applicable safety and reporting obligations rather than improvising through the ordinary sprint workflow.