Privacy document / revision 2026.07
Privacy Policy
How CheckLeaked.cc handles account, search, payment, device, support, and breach-index information across the website, APIs, extensions, and official bots that link to this policy.
We use profile, authentication, settings, plan, and security data to provide and protect your account.
Search terms and monitoring entries may contain personal or sensitive information. Submit them only for a lawful, authorized purpose.
You may request access, correction, deletion, or another applicable privacy right by contacting us. Account deletion is also available in Profile.
On this page
Scope and operator
CheckLeaked.cc (“CheckLeaked,” “we,” “us,” or “our”) operates a data-breach exposure search and monitoring service. This policy applies to CheckLeaked services that display or link to it, including the website, developer APIs, browser extensions, and official Discord, Slack, and Telegram integrations.
For account, website, support, payment, and service-usage information described here, the CheckLeaked.cc service operator determines why and how that information is processed and acts as the data controller where that concept applies. Contact the operator at [email protected].
Customers independently determine whether they may lawfully search, monitor, export, or otherwise use information returned by the service. We do not act as a customer’s data processor merely because the customer uses the service; a different allocation applies only if a separate written data-processing agreement says so.
Reading this policy or visiting the site does not, by itself, constitute consent to every form of processing. We rely on the legal bases described below and request consent where applicable.
Information we collect and where it comes from
Account and identity
OAuth or platform ID, email, display name, profile image, locale, verification status, authentication and session data, account role, plan, API or bot tokens, linked integrations, notification choices, and account timestamps.
Search and monitoring
Search terms such as emails, usernames, domains, phone numbers, IP addresses, hashes, or other identifiers; selected search type; saved or monitored entries; results, exports, API usage, quotas, and request status.
Purchases and support
Purchase email, order and invoice identifiers, selected plan, license-key or fulfillment status, transaction metadata, support messages, bug reports, attachments, and correspondence. Payment credentials are handled by the checkout provider, not stored by us.
Device and usage
IP address, approximate location derived from IP, browser, operating system, device and language settings, page and event activity, referrer, timestamps, cookies, local-storage values, security events, and server logs.
Breach-index records
Identifiers, contact details, account attributes, credentials or hashes, and incident metadata contained in data-breach sources. These records may concern people who have never used CheckLeaked.
Derived information
Rate-limit counters, abuse and fraud signals, service-health data, risk or exposure summaries, and aggregated statistics produced from the categories above.
Sources
We obtain information:
- directly from you when you search, create an account, configure monitoring, buy access, or contact support;
- automatically from your browser, device, and interaction with the service;
- from sign-in and integration providers such as Google, Discord, Slack, Telegram, or another provider you choose;
- from payment, reseller, fraud-prevention, infrastructure, and analytics providers;
- from licensed breach-data providers, security-research sources, and publicly accessible incident sources; and
- from another user when that user lawfully submits an identifier for search or monitoring.
Please do not submit information that is unnecessary for the intended search or that you are not legally authorized to use.
Why we use information and our legal bases
- Provide the service
- Authenticate users; run searches and monitoring; return, save, and export results; operate integrations; manage plans, keys, quotas, and support. Legal basis: contract or steps requested before a contract.
- Protect the service
- Rate-limit requests; detect abuse, fraud, unauthorized access, and technical failures; investigate incidents; enforce the Terms. Legal basis: legitimate interests in security, service integrity, and protecting users, and legal obligation where applicable.
- Process purchases
- Create and fulfill orders, deliver license keys, maintain transaction records, resolve disputes, and meet accounting obligations. Legal basis: contract and legal obligation.
- Improve and measure
- Understand feature use, diagnose errors, measure performance and conversions, and improve usability. Legal basis: consent where required for non-essential tracking; otherwise our legitimate interests, subject to your rights.
- Communicate
- Send service, security, purchase, monitoring, and support messages. Marketing is sent only on an appropriate legal basis, and you may opt out at any time.
- Comply and defend
- Respond to valid legal process, meet regulatory duties, and establish, exercise, or defend legal claims. Legal basis: legal obligation and legitimate interests.
- Breach-data search
- Help people and organizations identify exposed accounts, investigate security incidents, and reduce fraud. Where GDPR-style law applies, we rely on legitimate interests in cybersecurity and fraud prevention, balanced against affected people’s rights and the safeguards in this policy.
We do not use account or service data to make decisions that produce legal or similarly significant effects about you solely by automated means. Search results and exposure summaries are informational security signals, not eligibility decisions.
International transfers
CheckLeaked and its providers operate in multiple countries. Information may therefore be processed outside your country, including in countries whose privacy law may offer different protection.
Where transfer restrictions apply, we use an available lawful mechanism appropriate to the transfer, such as an adequacy decision, standard contractual clauses, or another legally recognized safeguard, and assess supplementary measures where required. Contact us to request information about the safeguard relevant to your data.
How long we keep information
We keep information only for the period reasonably needed for the purpose described, taking account of account status, user choices, security, provider and licensing obligations, disputes, and legal recordkeeping. The service does not use one retention period for every record.
- Account and preferences
- While the account is active. A verified account-destruction request deletes the primary account and associated saved-search stores; limited backups, security records, or legally required records may remain until their normal deletion cycle ends.
- Saved searches and monitoring
- Until you remove the entry or destroy the account, unless a shorter feature-specific period is shown.
- Temporary results and caches
- For the feature’s operational period, commonly minutes to seven days. Some API request records are configured to expire after 90 days.
- Security and service logs
- For the shortest practical debugging, rate-limit, abuse-prevention, and incident-response period, with longer retention only when an investigation or legal duty requires it.
- Purchases and support
- For fulfillment and support, then as needed for accounting, tax, fraud prevention, chargebacks, disputes, and legal claims.
- Analytics
- According to our provider settings and the provider’s own retention rules; aggregated or de-identified statistics may be kept longer.
- Breach-index records
- While the source remains available and processing remains necessary and lawful for cybersecurity purposes, subject to licensing limits, source updates, suppression review, and applicable rights.
Your privacy rights
Depending on your location and the processing, you may have the right to access, correct, delete, restrict, or receive a portable copy of personal data; object to processing based on legitimate interests or direct marketing; withdraw consent without affecting earlier lawful processing; and complain to a privacy regulator.
California and certain other U.S. residents may also have rights to know the categories, sources, purposes, specific pieces, and recipients of personal information; request correction or deletion; opt out of sale, sharing, or targeted advertising where applicable; limit certain uses of sensitive personal information; and receive equal service without unlawful discrimination.
How to make a request
- Email [email protected] from the address connected to your account when possible.
- State the right you want to exercise and the information or account involved. Use “California privacy request” or “Breach record review” in the subject when relevant.
- Provide only the information reasonably needed to verify your identity and authority. Never email a password or full payment credential.
An authorized agent may submit a request where law permits. We may ask for proof of authorization and verify the request directly with you. We generally respond within one month for EEA/UK requests or 45 days for applicable U.S. state requests, subject to lawful extensions. We may deny or limit a request where an exception applies and will explain the reason unless law prevents us.
EEA residents may find their supervisory authority through the European Data Protection Board member list.
UK residents may contact the Information Commissioner’s Office.
Security
We use measures designed to protect information in proportion to its risk, including encrypted transport, access controls, authentication, request verification, rate limits, provider safeguards, logging, cache expiration, and incident investigation. Access is limited to people and providers with an operational need.
No internet service can guarantee absolute security. Protect your account, API keys, bot tokens, devices, and sign-in provider; use unique credentials; and notify us promptly if you suspect unauthorized access. Do not send passwords or unnecessary breach records through email or chat.
Breach-index information and people who are not users
The service searches information associated with third-party security incidents. CheckLeaked did not collect that information from the affected person at the time of the original incident and did not cause the incident. Results may come from licensed services—including, depending on the feature, LeakCheck.io, DeHashed, Snusbase, LeakRadar.io, or Have I Been Pwned—and from publicly accessible security sources.
Breach records can be inaccurate, duplicated, stale, attributed to the wrong person, or unlawfully used by someone else. We restrict use through access controls, quotas, paid entitlements, security monitoring, and the acceptable-use rules in our Terms.
If a result appears to concern you, email us with the minimum information needed to identify the record. We will review correction, suppression, objection, or deletion requests under applicable law, our legal basis, provider controls, evidentiary needs, and the rights and safety of others. A change may not be possible where we do not control the upstream record or a legal exception applies, but we will explain the available outcome.
Children
CheckLeaked is intended for people aged 18 or older and is not directed to children. We do not knowingly create accounts for children or knowingly collect their personal information through direct interaction with the service.
A breach source may contain information about a minor without our knowledge. A parent, guardian, or affected person may contact us for a priority review. We do not knowingly sell or share personal information of anyone under 16.
Policy updates
We may update this policy when the service, providers, or law changes. We will post the revised policy with a new effective date. If a change materially affects how we use information already collected, we will provide additional notice or request consent where required. Earlier versions remain applicable to earlier processing to the extent required by law.
Questions, rights, or breach-record review
Contact the CheckLeaked.cc service operator. Include enough context to route the request, but do not email passwords, private keys, full payment details, or unrelated breach data.
[email protected]Rules for using search results, accounts, APIs, and paid access are in the Terms.
Read the Terms →