# Data sources and coverage

Tomba compiles business contact data from public web sources, generates likely addresses from each company's email format, and checks addresses against their mail servers. This page covers where the data comes from, how results are checked and scored, what Tomba leaves out, and how people remove their data. The [Privacy Policy](https://tomba.io/legal/privacy-policy) is the legal statement of these practices.

## Sources

- **Public web pages.** Tomba collects business contact details from company websites, public professional profiles, published articles, press releases, public directories, job postings, and similar public sources. It records each address with the page it was found on, which you get in [`sources`](/attributes/sources).
- **Generated addresses.** When Tomba has no stored address for a person, the [email finder](/api/finder#email-finder) builds candidates from the domain's most common email formats, checks them against the domain's mail server, and returns the most likely one with its verification status. If no candidate passes, Tomba doesn't search for the same name at the same domain again for 30 days.
- **Company records.** Company fields come from the company's website, public company profiles, and the domain's DNS and WHOIS records. Some fields, such as revenue, are estimates; see [Company response](/attributes/company).

## Checks and scores

- Each person result has a `score` from 0 to 100, based on the address's verification status and the number of public sources that list it.
- Domain search also returns addresses that Tomba's last check found invalid or couldn't confirm. Filter on `verification.status` if you only want valid addresses.
- Tomba derives each domain's email formats from the addresses it has found there, and reports them with their share in [`GET /email-format`](/api/finder#email-format).

## What Tomba excludes

- Personal email addresses, home addresses, personal phone numbers, and any data behind a login or paywall. Tomba doesn't collect them.
- Webmail and disposable domains. Domain search returns no addresses for them, and the email finder rejects them.
- Data whose owner asked for removal. See [Data removal](#data-removal).

## Freshness

Tomba keeps public contact data while its source page is live, re-verifies it regularly, and removes it when the source disappears. Each source's `last_seen_on` and `still_on_page` show when Tomba last found the address there. Tomba lists its data updates by month in [Data updates](/data/updates).

The [API Terms](https://tomba.io/legal/api-terms) require you to refresh or purge the contact data you store at least every 12 months.

## Data removal

Anyone can remove their email address, phone number, or LinkedIn profile from Tomba with the [Claim](https://app.tomba.io/claim) tool, or by emailing [privacy@tomba.io](mailto:privacy@tomba.io). Removal is free and doesn't need a Tomba account.

1. The person enters the address, phone number, or profile URL in the Claim tool. The tool can also correct their details instead of removing them.
2. Tomba emails a confirmation link.
3. When the person follows the link, Tomba stops returning the data: it's left out of results, and requests that name it directly return status `451`. Tomba also adds it to a suppression list so it isn't collected again.

Removal doesn't reach copies that customers exported before the request. A `451` response means the person asked Tomba to stop processing their data; don't process it yourself. See [Errors](/error-handling#error-types).
