Security and data
What we keep, what we never keep, and who helps us
Only you can search you: every check starts with a one-time code to your own email or number. This page lists everything we store, how long it stays, and every company that handles part of a check.
What we store
- Your email or phone number
- Only a masked form (like r••••@example.com or +91•••••3210) and a keyed one-way fingerprint of it, so we can tell it is you again. Never the address or number in full.
- Your checks
- The score, when you ran it, and what was found: a breach's name and year, the kinds of data it held, how many public pages show your email or number. Never the leaked passwords, cards, ID numbers or files themselves.
- Proof of consent
- That you asked for a code and ran a check, with the time and a one-way fingerprint of the network address.
- Photo searches
- The site, the page address and whether the copy is exact or edited, for each match. The photo itself only if you tick the separate box to keep it, encrypted, and it is deleted when your plan ends or you cancel.
- Message checks
- The verdict, a one-way fingerprint of the message and which patterns matched. Never the message.
- Share cards
- The numbers and words on the card: a score band and the four area words, or a verdict and its confidence. Never a finding.
- Alert address
- Only if you opt in to alerts by email, SMS or WhatsApp: the address you type, encrypted.
- Plans and payments
- Your plan, its dates, amounts, invoice numbers and the payment provider's ids. No name, email, phone or card details.
- Business requests
- The company name, a size band and the contact email in a masked form with a one-way fingerprint.
What we never store
- Your email or phone number in plain form (the one exception is an alert address you opt in to, and it is encrypted).
- A password, or the full fingerprint of one. The password check runs in your browser.
- Card or bank details, or government ID numbers (national, tax or residence IDs, passports). We never ask for them.
- A face template or any measurement of a face.
- The text of a message you check, or the links and numbers in it.
- Anything from a web search result: no page titles, addresses or snippets.
- What you type on a payment page. That stays with the payment provider.
- One-time codes on a real channel, and session tokens in plain form.
How long things stay
A daily clean-up deletes each kind of record after the time below.
| Record | Deleted after |
|---|---|
| One-time code requests | 24 hours |
| Sign-in sessions | 1 hour |
| Checks and what they found | 12 months |
| Message checks | 30 days |
| Counts of calls to suppliers (they hold nothing about you) | 90 days |
| Proof of consent | 3 years |
| A kept photo | When your plan ends or you cancel |
| Server logs (masked, never a full email or number) | The host's setting; our target is 90 days |
| Invoices and the payment ledger | As long as tax law requires. They hold no email, phone or name. |
You do not have to wait: "Delete everything" on your account page removes your checks, findings, photos, alerts and sessions at once, after a fresh code. "Download my data" gives you the same records first.
Who helps us (our subprocessors)
Each one receives only what its part of the check needs, over an encrypted connection, from our server. Your browser never talks to them, except when you choose to pay on the payment provider's own page. Each one keeps what it receives under its own policy.
- Have I Been PwnedBreach, paste and stolen-password-log lookups; the password check's list.Receives: Your email or phone number for a lookup. For the password check, only the first 5 characters of the password's SHA-1 hash, with no key and no cookie.Every live check; the password check when you use it.
- TwilioOne-time codes by SMS and WhatsApp; the phone line-type check.Receives: Your phone numberWhen you ask for a code by phone, and on a phone check.
- Resend or SendGridSending one-time codes and alerts by email.Receives: Your email address and the messageWhen you ask for a code by email, or opt in to email alerts.
- Brave SearchPublic pages, the UPI check and the profile check.Receives: Your email or phone number as a search query. Brave may keep queries for up to 90 days for billing.Live checks, when switched on.
- Google Cloud VisionThe photo search.Receives: Your photo, once, with its hidden data removedWhen you run a photo search.
- Google Safe BrowsingThe link check in the message checker.Receives: The links in a message you checkWhen you check a message with a link, when switched on.
- Amazon Web Services (Rekognition)Matching your selfie to the photo you search, so only your own photo is searched.Receives: Your selfie and your photo, onceOnly when switched on.
- Reality DefenderThe deepfake check.Receives: The picture you ask about, onceOnly when switched on.
- AnthropicReading a message you check, and drafting fix letters.Receives: The message with your own email and number and every link and number taken out; for a letter, the kind of finding, the platform and the letter's template, never your detailsOnly when switched on.
- StripeCard payments (UAE).Receives: The plan or item, the amount and our reference. Never your email or phone from us.When you pay.
- RazorpayCard and UPI payments (India).Receives: The plan or item, the amount and our reference. Never your email or phone from us.When you pay.
Refunds
A draft, waiting for review before launch. Prices include tax, so a refund is the whole amount paid.
- A check that failed: the credit or item comes back by itself, with no need to ask.
- A one-time item or credit pack you did not use: ask within 7 days and it is refunded in full.
- A plan: cancel any time and it runs to the end of what you paid; nothing renews after that. Money back on a plan is decided case by case.
- A gift nobody claimed: when the link runs out, the giver is refunded in full.
- A wrong charge (the wrong amount, twice, or after you cancelled): refunded in full as soon as we see it.
- Not refunded: a check that ran and gave an answer (also "nothing found"), credits that were spent, a plan month that already ran.
Refunds go back the way you paid. Nothing about a refund needs a name, an ID or card details from you.