PrivaCheckup

Security and data

What we keep, what we never keep, and who helps us

Only you can search you: every check starts with a one-time code to your own email or number. This page lists everything we store, how long it stays, and every company that handles part of a check.

What we store

Your email or phone number
Only a masked form (like r••••@example.com or +91•••••3210) and a keyed one-way fingerprint of it, so we can tell it is you again. Never the address or number in full.
Your checks
The score, when you ran it, and what was found: a breach's name and year, the kinds of data it held, how many public pages show your email or number. Never the leaked passwords, cards, ID numbers or files themselves.
Proof of consent
That you asked for a code and ran a check, with the time and a one-way fingerprint of the network address.
Photo searches
The site, the page address and whether the copy is exact or edited, for each match. The photo itself only if you tick the separate box to keep it, encrypted, and it is deleted when your plan ends or you cancel.
Message checks
The verdict, a one-way fingerprint of the message and which patterns matched. Never the message.
Share cards
The numbers and words on the card: a score band and the four area words, or a verdict and its confidence. Never a finding.
Alert address
Only if you opt in to alerts by email, SMS or WhatsApp: the address you type, encrypted.
Plans and payments
Your plan, its dates, amounts, invoice numbers and the payment provider's ids. No name, email, phone or card details.
Business requests
The company name, a size band and the contact email in a masked form with a one-way fingerprint.

What we never store

How long things stay

A daily clean-up deletes each kind of record after the time below.

RecordDeleted after
One-time code requests24 hours
Sign-in sessions1 hour
Checks and what they found12 months
Message checks30 days
Counts of calls to suppliers (they hold nothing about you)90 days
Proof of consent3 years
A kept photoWhen your plan ends or you cancel
Server logs (masked, never a full email or number)The host's setting; our target is 90 days
Invoices and the payment ledgerAs long as tax law requires. They hold no email, phone or name.

You do not have to wait: "Delete everything" on your account page removes your checks, findings, photos, alerts and sessions at once, after a fresh code. "Download my data" gives you the same records first.

Who helps us (our subprocessors)

Each one receives only what its part of the check needs, over an encrypted connection, from our server. Your browser never talks to them, except when you choose to pay on the payment provider's own page. Each one keeps what it receives under its own policy.

Refunds

A draft, waiting for review before launch. Prices include tax, so a refund is the whole amount paid.

Refunds go back the way you paid. Nothing about a refund needs a name, an ID or card details from you.