# Changelog of Personal Data Exposure Report — Privacy Operations Intelligence (`ryanclinton/personal-data-exposure-report`) Actor

- **URL**: https://apify.com/ryanclinton/personal-data-exposure-report/changelog.md
- **Full Actor documentation**: https://apify.com/ryanclinton/personal-data-exposure-report.md

## Changelog

### 1.9.1 (2026-08-15) — The progress message now moves throughout the scan. During the deep pass it used to freeze on "Starting the crawler." for several minutes, which looked like the run had hung.

- The deep pass now reports how many protected sites it has rendered out of the total, plus elapsed time, updating as each one finishes and at least every ten seconds
- The first pass now counts sites as they finish rather than in groups of six, so the status no longer sits unchanged for up to a minute
- The scan no longer ends the deep pass on a raw "X succeeded, Y failed" line — a blocked broker is an expected outcome, and the status now says the report is being scored instead

### 1.9 (2026-08-08) — Every site's detection rule re-verified against a name that does not exist. Some sites were reporting a listing for anybody, and they no longer do.

- Some sites answer any name with a page of similar-sounding strangers. Their detection rules were matching that page, so they reported a listing for everyone. Every rule is now checked against both a listed person and an invented one before it ships
- **You may see fewer sites reported than before, and some listings may disappear.** Where that happens the earlier result was not real and no removal is needed — the site was never holding your data
- Four sites were dropped because no reliable way exists to tell a genuine listing from their "no results" page, and two more are paused pending re-verification
- Adds 8 more people-search sites, including three whose search is a form rather than a link
- Six sites' detection rules were rebuilt after the sites were redesigned
- A site that answers but shows nothing we recognise is now reported as unchecked instead of clear — previously it was reported as clear
- The scan waits for a site's results to finish loading before reading them, instead of reading whatever was on screen after a fixed pause
- Sites that were previously unreachable now return results, and unreachable sites are retried on a fresh connection
- Search-engine hits are now opened and checked against the live page before being reported as your listing
- Reports now state plainly when a result is inconclusive rather than clear, and say so in the headline rather than only in a field

### 1.8 (2026-07-27) — Works outside the United States. Set your country and the scan adapts: US-only sources such as voter records are skipped instead of being reported as clean, region codes are no longer forced into US-indexed searches, and the report states which sources are actually evidenced to apply to you plus the privacy right you can rely on in your country.

### 1.7 (2026-07-24) — Scan speed and accuracy: honour the browser challenge timeout (was silently 30s per challenged site), abort image/media/font subresources, and never report a non-2xx page as clean.

### 1.7.3 (2026-07-23) — More accurate matching. Results are now verified to actually name the person searched, so a search result or a redirected broker page about a different individual is no longer reported as your exposure. Dropped one broker site that is no longer active.

### 1.7 (2026-07-20) — Broader coverage and more reliable results on hard-to-reach broker sites, plus an optional faster mode for lighter scans.

### 1.6 (2026-06-07) — Adds risk scoring, prioritized removal guidance, threat scenarios, and cross-run monitoring.

### 1.0 (2026-03-26) — Clearer removal instructions and reordered output columns
