Is Unroll.Me Safe? The Data-Selling History, Explained
Unroll.me is safe in the narrow sense: it is a real, functioning service, not malware, and it will unsubscribe you from emails as advertised. The reason people keep asking the question is the business model. Its then-parent company sold anonymized purchase data mined from user inboxes — most famously Lyft ride receipts, bought by Uber — and in 2019 the FTC settled charges that Unroll.me had deceived users about how it accessed their email. Whether it is "safe" for you comes down to whether you accept that trade, now that it is out in the open.
Here is the one-sentence version worth remembering: Unroll.me is a free inbox-cleanup tool that funds itself by extracting purchase data from users' emails and supplying it, in anonymized and aggregated form, to market-research buyers.
Everything below is the documented history, with a citation on every claim, and — because this question is bigger than one brand — a framework for judging any tool that asks for access to your inbox.
What is Unroll.me, and how does it make money?
Unroll.me is a free service that, in the FTC's own description, "helps users unsubscribe from unwanted emails or consolidate their email subscriptions." You connect your mailbox, it finds your subscriptions, and you unsubscribe from or roll up what you don't want.
It has never charged users. The funding has always come from the other side of the business: the company scans commercial email — order confirmations, shipping notices, ride receipts — extracts purchase signals, and sells the anonymized output as market research. Per third-party reporting, the asset has passed through three owners: Slice Intelligence from 2014, Rakuten Intelligence from 2019, and NielsenIQ, which completed its acquisition in September 2021.
None of that is a secret today. It was, functionally, a secret to most users in 2017.
Did Unroll.me sell user data? What actually happened in 2017?
Yes — this part is documented, not rumor. In April 2017, a New York Times profile of Uber's then-CEO revealed, almost in passing, that Uber had been buying anonymized Lyft receipt data from Slice Intelligence, Unroll.me's parent. As The Intercept summarized the reporting: "Slice collected its customers' emailed Lyft receipts from their inboxes and sold the anonymized data to Uber. Uber used the data as a proxy for the health of Lyft's business."
The backlash was immediate. CBS News reported users demanding their records be destroyed, and Privacy International catalogued the episode as a case study in consent that exists on paper but not in anyone's head. Unroll.me's co-founder Jojo Hedaya published an apology saying the company "weren't explicit enough" about its terms; Slice's CEO called it "heartbreaking to see that some of our users were upset to learn about how we monetize our free service" — a line that did not land the way he hoped.
Two things can be true at once, and fairness requires saying both. The data sales were disclosed in the terms of service, and the data was anonymized before sale — no one at Uber was reading your individual emails. And: essentially nobody understood that "free unsubscribe tool" meant "my receipts are a market-research product." That gap between legal consent and actual understanding is what the FTC went after next.
What did the FTC do in 2019?
On August 8, 2019, the FTC filed a complaint alleging that Unrollme Inc. "falsely told consumers that it would not 'touch' their personal emails" while sharing users' e-receipts with parent company Slice Technologies. The FTC noted that e-receipts can include "the user's name, billing and shipping addresses, and information about products or services purchased." According to a summary of the complaint, the specific signup messages at issue — "Don't worry, we won't touch your personal stuff" and later "we'll never touch your personal stuff" — ran from January 2015 through October 2016.
The settlement, finalized in December 2019, required Unroll.me to:
- stop misrepresenting how it collects, uses, stores, shares, or discloses consumer information — permanently;
- notify the consumers who signed up after seeing the deceptive messages;
- delete stored e-receipts collected from those consumers, unless it obtained their affirmative, express consent to keep them.
To be fair to Unroll.me: this was a settlement, not a court finding of guilt, and it carried no monetary fine — though per the same complaint summary, future violations could trigger civil penalties of up to $42,530 each. The Commission approved it on a 4-0-1 vote, with one commissioner abstaining, and declined advocacy groups' requests for tougher terms.
The timeline in one table
| Date | Event | Source |
|---|---|---|
| 2014 | Slice Intelligence acquires Unroll.me | Leave Me Alone |
| April 2017 | NYT reporting reveals Slice sold anonymized Lyft receipt data to Uber | The Intercept |
| 2018 | Unroll.me suspends service for EU/EEA users rather than comply with GDPR | Unroll.me GDPR notice |
| August 2019 | FTC complaint: Unroll.me deceived users about "touching" their email | FTC complaint |
| December 2019 | Settlement finalized: no fine; deletion, notification, and misrepresentation ban | FTC |
| September 2021 | NielsenIQ completes acquisition of Rakuten Intelligence assets, including Unroll.me | Leave Me Alone |
Is Unroll.me safe to use in 2026?
As of July 2026, here is what we can state fairly. The service still operates on the same basic model: per current third-party reporting, commercial emails are scanned, parsed for purchase signals, anonymized, and contributed to NielsenIQ's measurement products, with the company's stated position being that "personal identifiers are stripped before any purchase data reaches NielsenIQ's clients." The same reporting notes an opt-out now exists in settings. The service remains unavailable in the EU and EEA, where it suspended operations when the GDPR took effect rather than adapt the model — a decision you can read either as candor or as an answer to the question of whether the model survives strict consent rules.
We could not load Unroll.me's current US-facing privacy policy from our location — the site redirects European visitors to its GDPR suspension notice — so we won't characterize its exact current wording. Read it yourself before connecting; that is the whole lesson of this story.
So: is Unroll.me legit? Yes — a real company, owned by a large market-research firm, operating under a standing FTC order. Is it dangerous? Not in the malware sense. Is it private? Its model is the opposite of private by design: the product is free because your commercial email is the inventory. Reviews that call it "safe" and reviews that call it "spyware" are usually both describing this same arrangement, just with different tolerance for it.
What can any inbox tool read once you grant OAuth access?
This is the part that outlasts any one brand verdict. When you connect a tool to Gmail via OAuth with a full read scope, it can read every message: receipts, bank alerts, medical appointments, password resets, the message from your lawyer. Not just newsletters. The scope is the scope.
Google does police this. Its API Services User Data Policy imposes "Limited Use" rules on Gmail data: apps are barred from "transferring or selling user data to third parties like advertising platforms, data brokers, or any information resellers," from using it for ad targeting or creditworthiness decisions, and from letting humans read your mail without specific consent. Those rules postdate the Unroll.me episode, and they are meaningfully stricter than what existed in 2017. But a policy is a promise backed by audits and revocations, not a physical impossibility. The capability to read your mail is granted the moment you click consent.
So the durable safety question is never "is this app malware?" It is: what happens to what the app reads? Before connecting anything — including us — ask:
| Question | Why it matters |
|---|---|
| How is a free product funded? | If you can't find the revenue, you may be it |
| Who is the parent company, and what do they sell? | A market-research parent measures markets with something |
| Does the privacy policy mention "measurement," "market research," or "commercial data"? | That is the disclosure, in its natural habitat |
| Can you opt out, delete your data, and revoke access easily? | Exit rights are the test of good faith |
| What OAuth scopes does it actually request? | Read-only vs. modify vs. full access are different grants |
Revoking access is always available to you: both Google and Apple let you review and disconnect third-party apps from your account settings at any time. Unsubscribing itself, done right, doesn't even require a third party to hold your data long-term — the one-click unsubscribe standard exists precisely so that opting out is a single authenticated request, and we've written separately about whether unsubscribing actually works and when it's safe.
If the data model bothers you
We'll state our position and then undercut it, in that order. Flick (flicked.email) is a swipe-to-triage email client, and we build List-Unsubscribe parsing for a living: one-swipe unsubscribe uses the RFC 8058 List-Unsubscribe-Post mechanism — the same standard behind Gmail's native unsubscribe button. Flick's deck is finite: you reach the end, and the product wants you to finish and leave — anti-engagement by design. How we charge is on our features page, where you can see the revenue model in the open — the thing this whole article argues you should demand from any inbox tool.
And the caveat we owe you: scrutinize us exactly the way this article scrutinized Unroll.me. Read our OAuth consent screen. Check what scopes we request. Ask how we're funded, and don't accept "trust us" from anyone — including the people who just spent an entire article telling you not to. If you want the fuller side-by-side, we keep one at Unroll.me alternatives.
Stop reading your inbox. Start flicking it.
Flick turns every inbox into a finite swipe deck — archive, "no reply needed," or AI-draft → approve, one card at a time. Inbox flicked.
Try the live demo — no signup →FAQ
Is Unroll.me safe to use?
Unroll.me is safe in the sense that it is a legitimate service, not malware, and it performs its advertised unsubscribe function. The open question is its data model: the free service is funded by anonymized purchase data extracted from users' inboxes, a practice with a documented history of poor disclosure. If you understand and accept that trade, it works as described.
Did Unroll.me sell my data?
Unroll.me's parent company, Slice Intelligence, sold anonymized purchase data derived from user inboxes — including Lyft receipts purchased by Uber, per 2017 reporting. Individual emails were not sold as raw messages; the data was anonymized and aggregated before sale. The controversy was about consent and disclosure, not a breach.
Is Unroll.me legit?
Unroll.me is a legitimate company — as of September 2021 part of NielsenIQ, per third-party reporting — operating under a 2019 FTC consent order that permanently bars it from misrepresenting its data practices. Legitimacy and privacy are separate questions, though. The service is real; the trade is data for cleanup.
Why is Unroll.me not available in Europe?
Unroll.me suspended service for EU and EEA users when the GDPR took effect in 2018, rather than adapting its data model to the regulation's consent requirements. The suspension remains in place as of July 2026. Most competing unsubscribe tools continued operating in Europe.
What should I check before connecting any app to my inbox?
Check how the product is funded, who owns it, and whether its privacy policy mentions market research or commercial data — before you grant access, not after. Google's Limited Use policy bans Gmail-connected apps from selling data to brokers or advertisers, but a policy is an enforcement promise, not a technical barrier. Assume any full-read scope can see everything, and only connect tools whose business model you can explain in one sentence.