Skip to content

Privacy

What we collect, and what we do not.

Compromised exists to tell you where your data has leaked. Becoming another place it leaks from would defeat the point, so the product is built to hold as little as it can and to be plain about what it does hold.

Why we process anything at all

To sign you in, run the searches you ask for, enforce your allowance and stop abuse of it, show you your own history, reconcile what you have paid for, deliver the email you have asked for, answer your messages, and keep the service running and secure. Nothing is processed for a purpose outside that list.

Please do not submit passwords, credentials from a breach, sign-in links, payment card numbers or access tokens through the search or contact forms. Use the password check for a password. It is built so we never receive it.

What we hold

Account and sign-in

Your email address, an optional name and profile image, which sign-in methods you have connected, your plan and allowance state, and a record of whether you have consented to marketing email. Sign-in uses a signed session cookie. There is no password on your account, so there is none to store.

Searches you run

The identifier type you chose and the value you entered, plus your network address for abuse control. The value is sent to a breach intelligence provider to obtain a result, and is encrypted before any history record is stored. What is stored is encrypted; the searchable index over it is a keyed hash rather than the value itself.

Results and history

A record of each search: when it ran, what type it was, whether the provider response was complete, and how many matches were reported. It is kept so your own history is readable by you. History is scoped to the account that ran the search.

Password exposure checks

Nothing. A password you check is hashed in your browser, and only a short fragment of that hash is sent, a fragment shared by hundreds of thousands of passwords. The password itself never reaches our servers, is never stored, and is not recorded in your history.

Billing

Your plan, subscription status, allowance, credit balance and references needed to reconcile payments. Card details are entered on the payment provider's own pages and are never collected by our forms or seen by this application.

Contact and email

The name, address, subject and message you submit through the contact form, and, separately and only if you ask for it, your address on our newsletter list. Newsletter membership is not created by making a purchase, and running a search never changes your email preferences.

Security and operational records

Rate-limit counters, abuse-verification outcomes, delivery success or failure for emails we send, and administrative actions taken on the service. These are kept to operate and secure the product.

Who else is involved

Running the service requires a small number of external providers. Each is described by what it does and what it receives. A category only applies when that feature is configured and you use it. Nothing is sold, and nothing is shared for anyone else's advertising.

Breach intelligence
Receives the identifier type and value in order to return a point-in-time result. This is the only category that receives a search value.
Payment processing
Hosts checkout and subscription management, and holds the payment relationship. Card details go directly to it and never through this application.
Authentication
If you choose to sign in with a third-party identity, that provider confirms your identity to us. Accounts are never linked by a matching email address alone.
Email delivery
Delivers sign-in links, account notifications and messages you have asked for. Receives the recipient address and the message.
Newsletter management
Holds newsletter subscription state and sends campaigns, if you subscribe. Also holds a record of customers for segmentation, with no search or breach data attached.
Abuse protection
Verifies that a request comes from a browser rather than automation, for anonymous searches and contact submissions.
Analytics
If enabled by the operator, receives page views and product events. Every analytics property is a fixed category or a yes/no value; searched values, addresses, passwords and billing identifiers are excluded by the design of the event format, not by policy alone.
Infrastructure and content hosting
Runs the application, stores its records and serves published editorial content.

We do not publish the specific vendor behind each category. Doing so maps our infrastructure for anyone assessing how to attack it, and changes nothing about the protection you receive. If you need to know for a compliance review, ask through the contact form.

How it is protected, and the honest limits

Search values and resolved network addresses are encrypted with authenticated encryption before a record exists. Lookup runs over keyed hashes, so the index never contains the identifier itself. Seeing a stored value again requires an explicit, recorded action. A history listing never decrypts. What a response contains is decided on the server according to your plan.

This is not zero-knowledge encryption. The server necessarily handles your search value in order to validate it and query the provider. Keyed hashes reveal equality, so a system holding the keys can tell that two searches were for the same value. Encryption at rest does not protect data from a compromised running application that also holds the keys. We say so because a policy claiming otherwise would be describing a different product.

Sensitive values are excluded from application logs, and analytics events have no field capable of carrying one.

Cookies and local storage

A signed session cookie keeps you signed in. Abuse protection sets its own short-lived cookie when you complete a verification. Your light or dark theme choice is kept in your browser's local storage and is never sent to us.

If the operator has enabled analytics, that provider may set its own cookies or storage. Analytics is off unless deliberately turned on.

How long it is kept

Account, search, billing and contact records are kept while your account exists. There is no fixed retention schedule for them, and this notice does not invent one it cannot honour. Some records are deliberately short-lived: sign-in links expire in minutes, rate-limit counters expire with their window, and operational email delivery records expire after thirty days.

Self-service account deletion is not currently offered, because account records and encrypted search records cannot yet be removed together with verified transactional safety. A button that might half-delete either would be worse than no button. Deletion requests are handled through the contact form, and deleting an account removes its searches and stored results along with it.

Newsletter subscription state is held by the newsletter service, which is the authority on it. Every campaign includes an unsubscribe link, and you can change the preference from your account at any time.

Questions or requests

Access, correction, deletion and any other privacy question go through the contact form. Please do not include a password, a breached credential, a sign-in link, a card number or an access token in your message.

Contact Compromised