Your statement will read CCBILL.COM*LCI
Never "Leak Cleaner". Never anything adult. Published here so you can check before you pay.
You're about to hand a stranger your ID. Here's where it goes.
Two things first. There is no portal on day one, so deletion and export run by email. And nothing gets filed on a machine's say-so — a person verifies every match first.
If a line below is wrong, tell us on Telegram and we will correct it.
200,000+ leaks removed. 4,000+ creators.
Those are our own figures, counted from the notices we have filed and the accounts we have run. We publish them as totals and nothing else. There is no success rate here, no average turnaround, and no per-site breakdown, because the moment we print one we are asking you to read it as a prediction about your case.
We will not quote you a removal percentage — not ours, and not a competitor's, including as a rebuttal to one. The only removal number we put in writing is the threshold in your contract, and your own report prints the denominator it is measured against.
We build the account around the name you post under
Threads, reports, bookings and invoices carry your stage name. Your legal name sits in a separate encrypted field.
Discreet Mode is on from the moment we have your email address, not from the moment you ask. Every message comes from LCI Reports. No count in a subject line, no domain, no stage name, no thumbnail, ever. The email carries a private link, never the contents.
Where your name could surface anyway
A notice you file under your own name becomes a public record. Google forwards copyright removal notices to the Lumen Database, which is public, searchable, and Harvard-hosted. The record reads, in substance, "[legal name] asked Google to remove these URLs", with the URLs attached. That is a directory of your leaks with your real name on it.
We file under our name, never yours. How we keep your name out of public records →
What we hold, and for how long
| Data | Retention |
|---|---|
| Government ID and selfie | Never stored by us. Vendor-side only. We receive pass/fail, name match, and an over-18 boolean. The vendor deletes within 24 hours. |
| Legal name | Contract plus 30 days, encrypted. Used in notices and delisting requests only. |
| Identity check result: pass/fail, name match, over-18 boolean | Contract plus 30 days |
| Your content | We never take it. Ownership is verified from links to your own posts and the dates they went out, so there is no file here to keep or to destroy. |
| Full-file retention | Not available today. If it ever ships it will be opt-in only, never default, revocable by one email. |
| Evidence captures of infringing pages | 12 months. Seven years where the capture is attached to a notice we sent, because that notice is our §512(f) file. |
| Notices sent | 7 years. Already public record, and our §512(f) file. |
| Support messages on Telegram | Our side of the thread is deleted when the ticket closes. Telegram cloud chats are not end-to-end encrypted, so don't send documents over it. |
| Scan data, non-clients | 12 months |
| Billing and tax records | As long as tax law requires |
| Suppression list entries, if you asked us never to contact you | An email hash and nothing else, kept until you ask us to remove it |
| Records of a data request and how we answered it | 3 years |
| Social credentials | Never plaintext, never in a document. 1Password Business vault, TOTP in vault. |
| OnlyFans password | We never ask for it. Ever. |
We don't hold your content, because we never ask for it
Our detection scans public pages for copies. It never scans your files, because we never take your files. To confirm a set is yours, we work from links to your own posts and the dates they went out. That is the whole verification.
It means the worst thing anyone could take from us is a list of URLs that are already public. Nothing to leak beats a promise to protect it.
If that ever changes — if content-matching against your own files ever gets built — the pages describing it change before a single file is taken, and /legal/biometrics/ changes first.
Four roles, and the ceiling on each one
| Role | Sees | Never |
|---|---|---|
| Verification Officer | Your ID, in the vendor's session | Downloads or keeps it |
| Takedown Analyst | Infringing URLs and page captures | Sees your ID or your content |
| Account Manager | Stage name, plan, tickets | Touches content |
| Founder | Everything, break-glass, logged | Is exempt from the log |
These are access boundaries, not headcount. No single role sees everything, break-glass access is logged, and the founder is not exempt from the log.
Things you can check without asking us
| Fact | Where to check it |
|---|---|
| Registered entity | FOUNDER: entity legal name, d/b/a Leak Cleaner |
| Secretary of State filing | FOUNDER: SoS filing number, FOUNDER: state of incorporation register |
| DMCA designated agent | Registration FOUNDER: USCO registration number, US Copyright Office directory |
| E&O, cyber, media liability | FOUNDER: limits and carrier, to FOUNDER: expiry date |
That registration is a filing, not a credential. It costs $6 and qualifies nobody to do anything.
Deletion, and what survives it
There is no portal on day one. Until it ships, deletion runs by email. One line to FOUNDER: privacy email, no call and no questions, and we start it the same working day. When the portal ships it becomes one button.
Completed within 30 days, with a Certificate of Destruction listing what went and when.
What survives: notices already filed, which are public record and cannot be recalled.
A deletion promise with no exceptions listed is a promise nobody kept.
Three things we won't put on this page
We are not SOC 2 audited. No report, no Type I, no Type II.
There is no "SSL Secured" seal here. Every site has TLS.
We will not quote you a removal percentage. Not ours, and not a competitor's, including as a rebuttal to one.
No pixel, no chat widget, no session recording. Cloudflare sits in front of the site for the bot check and processes your IP address when the page loads. That one operation is named in our privacy notice.
Hours, and how to reach a person
Monday to Friday, 09:00–21:00 ET. Saturday and Sunday, 11:00–19:00 ET. Outside those hours you can still message us and we read it when we open.
Don't send documents over Telegram. Telegram cloud chats are not end-to-end encrypted, and our side of the thread is deleted when the ticket closes.
Two fields. No card, no legal name, no account. Your report lands in 48 hours.