Privacy document / revision 2026.09
Privacy Policy
How CheckLeaked.cc handles account, search, payment, device, support, and breach-index information across the website, APIs, extensions, and official bots that link to this policy.
We use profile, authentication, settings, plan, and security data to provide and protect your account.
Search terms and monitoring entries may contain personal or sensitive information. Submit them only for a lawful, authorized purpose.
You may request access, correction, deletion, or another applicable privacy right by contacting us. Account deletion is also available in Profile.
On this page
Scope and operator
CheckLeaked.cc (“CheckLeaked,” “we,” “us,” or “our”) operates a data-breach exposure search and monitoring service. This policy applies to CheckLeaked services that display or link to it, including the website, developer APIs, browser extensions, and official Discord, Slack, and Telegram integrations.
For account, website, support, payment, and service-usage information described here, the CheckLeaked.cc service operator determines why and how that information is processed and acts as the data controller where that concept applies. Contact the operator at [email protected].
Customers independently determine whether they may lawfully search, monitor, export, or otherwise use information returned by the service. We do not act as a customer’s data processor merely because the customer uses the service; a different allocation applies only if a separate written data-processing agreement says so.
Reading this policy or visiting the site does not, by itself, constitute consent to every form of processing. We rely on the legal bases described below and request consent where applicable.
Information we collect and where it comes from
Account and identity
OAuth or platform ID, email, display name, profile image, locale, verification status, authentication and session data, account role, plan, API or bot tokens, linked integrations, notification choices, and account timestamps.
Search and monitoring
Search terms such as emails, usernames, domains, phone numbers, IP addresses, hashes, or other identifiers; selected search type; saved or monitored entries; results, exports, API usage, quotas, and request status.
Purchases and support
Purchase email, order and invoice identifiers, selected plan, license-key or fulfillment status, transaction metadata, support messages, bug reports, attachments, and correspondence. If you turn on monthly auto-renew with PayPal: the PayPal subscription ID, the payer email address and payer ID PayPal reports, the subscription status, charge amounts and dates, and a record of the terms you accepted (price, first-charge date, and the time and IP address of your consent). Payment credentials are handled by the checkout provider, not stored by us.
Device and usage
IP address, approximate location derived from IP, browser, operating system, device and language settings, page and event activity, referrer, timestamps, cookies, local-storage values, security events, and server logs.
Breach-index records
Identifiers, contact details, account attributes, credentials or hashes, and incident metadata contained in data-breach sources. These records may concern people who have never used CheckLeaked.
Derived information
Rate-limit counters, abuse and fraud signals, service-health data, risk or exposure summaries, and aggregated statistics produced from the categories above.
Referral program
If you share an invite link or join through one: your referral code, which account invited yours and when, the purchases that earned days, your day balance and redemptions, and a daily count of visits to your link. A visit is counted at most once a day per visitor, using a keyed hash of the IP address; the address itself is not stored for this. A keyed hash of the IP address used when an invite is applied is kept to detect abuse, and so is a keyed hash of each network your account views its referral details from, for 30 days, so an invite applied from your own network counts as self-referral.
Sources
We obtain information:
- directly from you when you search, create an account, configure monitoring, buy access, or contact support;
- automatically from your browser, device, and interaction with the service;
- from sign-in and integration providers such as Google, Discord, Slack, Telegram, or another provider you choose;
- from payment, reseller, fraud-prevention, infrastructure, and analytics providers;
- from licensed breach-data providers, security-research sources, and publicly accessible incident sources; and
- from another user when that user lawfully submits an identifier for search or monitoring.
Please do not submit information that is unnecessary for the intended search or that you are not legally authorized to use.
Why we use information and our legal bases
- Provide the service
- Authenticate users; run searches and monitoring; return, save, and export results; operate integrations; manage plans, keys, quotas, and support. Legal basis: contract or steps requested before a contract.
- Protect the service
- Rate-limit requests; detect abuse, fraud, unauthorized access, and technical failures; investigate incidents; enforce the Terms. Legal basis: legitimate interests in security, service integrity, and protecting users, and legal obligation where applicable.
- Process purchases
- Create and fulfill orders, deliver license keys, maintain transaction records, resolve disputes, and meet accounting obligations. If you turn on monthly auto-renew with PayPal, we check each charge with PayPal and extend your plan for it until you cancel. Legal basis: contract and legal obligation.
- Run the referral program
- Credit invites, count visits to invite links, hold and release earned days, prevent self-referral and repeat new-customer bonuses, and apply the days you redeem. Referrers see, for each person who joined through their link, only the month they joined and whether a purchase was made, plus totals; never a name, an email address, or which plan was bought. Because referral days are earned for each paid month and released after a hold, a referrer’s own day balance, release dates, and removed days can show how many months a referred person paid for, roughly when, and whether a payment was later refunded or reversed. If you earn referral days, we may email you when they become available (at most once a day), with a one-click opt-out in every such email. Legal basis: contract (the program terms) and our legitimate interest in preventing fraud.
- Improve and measure
- Understand feature use, diagnose errors, measure performance and conversions, and improve usability. Legal basis: consent where required for non-essential tracking; otherwise our legitimate interests, subject to your rights.
- Communicate
- Send service, security, purchase, monitoring, and support messages. If you start a checkout and do not complete the payment, we may send one reminder to the email address you entered, with a link to finish the purchase and a link to stop such reminders; legal basis: our legitimate interest in completing the purchase you started. If your account has a paid plan, we email you three days and one day before it expires and once a few days after, because a plan renews or charges automatically only if you turn on monthly auto-renew with PayPal (we skip these reminders while auto-renew is set to renew the plan); each email has a link to stop these reminders, and the same legal basis applies. If you turn on auto-renew, we email you when it starts, when a payment fails, when it stops or is cancelled, and once a year while it stays on; these messages are part of the subscription and have no opt-out; legal basis: contract. When you create an account, we send up to two getting-started emails in its first days (how to run a first check and what the paid plans add), each with a link to stop them; legal basis: our legitimate interest in helping you use the account you opened. Marketing is sent only on an appropriate legal basis, and you may opt out at any time.
- Comply and defend
- Respond to valid legal process, meet regulatory duties, and establish, exercise, or defend legal claims. Legal basis: legal obligation and legitimate interests.
- Breach-data search
- Help people and organizations identify exposed accounts, investigate security incidents, and reduce fraud. Where GDPR-style law applies, we rely on legitimate interests in cybersecurity and fraud prevention, balanced against affected people’s rights and the safeguards in this policy.
We do not use account or service data to make decisions that produce legal or similarly significant effects about you solely by automated means. Search results and exposure summaries are informational security signals, not eligibility decisions.
International transfers
CheckLeaked and its providers operate in multiple countries. Information may therefore be processed outside your country, including in countries whose privacy law may offer different protection.
Where transfer restrictions apply, we use an available lawful mechanism appropriate to the transfer, such as an adequacy decision, standard contractual clauses, or another legally recognized safeguard, and assess supplementary measures where required. Contact us to request information about the safeguard relevant to your data.
How long we keep information
We keep information only for the period reasonably needed for the purpose described, taking account of account status, user choices, security, provider and licensing obligations, disputes, and legal recordkeeping. The service does not use one retention period for every record.
- Account and preferences
- While the account is active. A verified account-destruction request deletes the primary account and associated saved-search stores; limited backups, security records, or legally required records may remain until their normal deletion cycle ends.
- Saved searches and monitoring
- Until you remove the entry or destroy the account, unless a shorter feature-specific period is shown.
- Temporary results and caches
- For the feature’s operational period, commonly minutes to seven days. Some API request records are configured to expire after 90 days.
- Security and service logs
- For the shortest practical debugging, rate-limit, abuse-prevention, and incident-response period, with longer retention only when an investigation or legal duty requires it.
- Purchases and support
- For fulfillment and support, then as needed for accounting, tax, fraud prevention, chargebacks, disputes, and legal claims. Auto-renew subscription records, including the record of the terms you accepted, are kept for at least three years; the PayPal payer email address and payer ID stored with them are removed when you destroy the account.
- Referral program
- While the account is active; visits to invite links are kept only as daily totals. When you destroy the account, your referral code is deleted, unredeemed days are removed, the hashes of the networks your account viewed its referral details from are deleted, and a hashed marker of the account and its email address is kept to prevent repeat new-customer bonuses. The record that an account joined through an invite is kept, hidden from the referrer, so the same account cannot be invited twice.
- Analytics
- According to our provider settings and the provider’s own retention rules; aggregated or de-identified statistics may be kept longer.
- Breach-index records
- While the source remains available and processing remains necessary and lawful for cybersecurity purposes, subject to licensing limits, source updates, suppression review, and applicable rights.
Your privacy rights
Depending on your location and the processing, you may have the right to access, correct, delete, restrict, or receive a portable copy of personal data; object to processing based on legitimate interests or direct marketing; withdraw consent without affecting earlier lawful processing; and complain to a privacy regulator.
California and certain other U.S. residents may also have rights to know the categories, sources, purposes, specific pieces, and recipients of personal information; request correction or deletion; opt out of sale, sharing, or targeted advertising where applicable; limit certain uses of sensitive personal information; and receive equal service without unlawful discrimination.
How to make a request
- Email [email protected] from the address connected to your account when possible.
- State the right you want to exercise and the information or account involved. Use “California privacy request” or “Breach record review” in the subject when relevant.
- Provide only the information reasonably needed to verify your identity and authority. Never email a password or full payment credential.
An authorized agent may submit a request where law permits. We may ask for proof of authorization and verify the request directly with you. We generally respond within one month for EEA/UK requests or 45 days for applicable U.S. state requests, subject to lawful extensions. We may deny or limit a request where an exception applies and will explain the reason unless law prevents us.
EEA residents may find their supervisory authority through the European Data Protection Board member list.
UK residents may contact the Information Commissioner’s Office.
Security
We use measures designed to protect information in proportion to its risk, including encrypted transport, access controls, authentication, request verification, rate limits, provider safeguards, logging, cache expiration, and incident investigation. Access is limited to people and providers with an operational need.
No internet service can guarantee absolute security. Protect your account, API keys, bot tokens, devices, and sign-in provider; use unique credentials; and notify us promptly if you suspect unauthorized access. Do not send passwords or unnecessary breach records through email or chat.
Breach-index information and people who are not users
The service searches information associated with third-party security incidents. CheckLeaked did not collect that information from the affected person at the time of the original incident and did not cause the incident. Results may come from licensed services—including, depending on the feature, LeakCheck.io, DeHashed, Snusbase, LeakRadar.io, or Have I Been Pwned—and from publicly accessible security sources.
Breach records can be inaccurate, duplicated, stale, attributed to the wrong person, or unlawfully used by someone else. We restrict use through access controls, quotas, paid entitlements, security monitoring, and the acceptable-use rules in our Terms.
If a result appears to concern you, email us with the minimum information needed to identify the record. We will review correction, suppression, objection, or deletion requests under applicable law, our legal basis, provider controls, evidentiary needs, and the rights and safety of others. A change may not be possible where we do not control the upstream record or a legal exception applies, but we will explain the available outcome.
Children
CheckLeaked is intended for people aged 18 or older and is not directed to children. We do not knowingly create accounts for children or knowingly collect their personal information through direct interaction with the service.
A breach source may contain information about a minor without our knowledge. A parent, guardian, or affected person may contact us for a priority review. We do not knowingly sell or share personal information of anyone under 16.
Policy updates
We may update this policy when the service, providers, or law changes. We will post the revised policy with a new effective date. If a change materially affects how we use information already collected, we will provide additional notice or request consent where required. Earlier versions remain applicable to earlier processing to the extent required by law.
Questions, rights, or breach-record review
Contact the CheckLeaked.cc service operator. Include enough context to route the request, but do not email passwords, private keys, full payment details, or unrelated breach data.
[email protected]Rules for using search results, accounts, APIs, and paid access are in the Terms.
Read the Terms →