Skip to content

Transparency report

Q2 2026: 1 April to 30 June 2026
Figures as of 25 August 2026

This page is the public account of how LeakRadar is operated: where the data comes from, what is filtered out before any result is returned, who is allowed to query it, what happens when someone asks to be removed, and how we answer an authority. A safeguard nobody can inspect is indistinguishable from one that does not exist, so the controls described here are published alongside the figures that show them working.

The figures are read directly from our production systems and cover the last completed quarter. They are refreshed automatically, so this page moves to the next quarter on its own. Every counter carries its exact definition in the methodology section, including two figures we deliberately do not publish, and why. The identity of the publisher, its registered office and its legal contact details are set out in our Terms of Service.

2,603

Active exclusion rules

264 created on a data subject request

84

Accounts suspended

All causes, since launch

150

Removal requests received

During the period

0

Legal demands from authorities

During the period

Exclusion rules

An exclusion rule removes a value from every result set before results are returned. The lists cover banking and payment institutions, cryptocurrency exchanges and wallet services, and any value blocked following a request from the person concerned. They are evaluated on the email, domain, advanced and raw search surfaces, and on export and unlock as well, so a value that cannot be searched cannot be exported or revealed either.

A rule is not a domain. Rules are counted here because that is what the engine actually evaluates, and counting domains would mean guessing how many values each rule covers.

Field evaluatedActive rulesOn a data subject request
Website domain1,98466
Website TLD90
Username546197
Email domain631
Email TLD10
Total2,603264

Of those, 1 match by pattern rather than by exact value. A single pattern rule covers an indeterminate number of values, so the totals above should be read as a count of rules, never as a count of blocked domains.

Removal requests

Anyone can ask for their data to be removed, free of charge, with or without an account. Requests filed from the public site are confirmed by a link sent to the address concerned, so that nobody can file on behalf of someone else.

Received during the period150
Approved143
Rejected7
Still under review0
Filed without an account, never confirmed by the requester0
Filed from the public site rather than from an account0

Requests are counted in the quarter they were received, with their status as observed on 25 August 2026. A request received late in a quarter and decided afterwards stays in that quarter.

Other operational figures

Active data quality rules290
Corrupted batches deleted from the index0
Administrator accesses to a customer account, during the period34

Data quality rules discard records whose parsing produced something that is not a usable credential. Corrupted batches are whole source batches removed from the index because parsing destroyed the identifiers they contained. Both remove data from the index rather than add to it.

Where the data comes from

LeakRadar indexes credential files that are already in circulation: stealer logs, combolists, breach dumps and posts published on dark web forums. What matters is what we do not do to obtain them.

  • We do not intrude into anyone’s system. We do not exploit vulnerabilities, we do not compromise accounts, and we do not access data held on someone else’s infrastructure.
  • We do not commission, fund or solicit the collection of data. We are not the origin of any breach we index, and we do not ask anyone to produce one.
  • We do not sell, license or transmit the datasets in bulk to any third party.
  • Provenance is kept per record. Every record carries an identifier linking it to the source file it came from, so the origin of any single record can be stated to the person concerned or to an authority.
  • Datasets and source files are hosted exclusively within the European Union.

Who is allowed to query, and how we know who they are

There is no anonymous access and no free tier over the credential datasets. Every account is bound to a confirmed email address, to accepted contractual terms and to a billing identity. The paywall is an identification gate as much as a price: we would rather serve fewer people than serve people we cannot name.

Every search and every unlock is recorded with the account, the timestamp and the originating IP address. Customers warrant a lawful basis for each query, and misuse ends the relationship without refund. The count of suspended accounts above is what that rule looks like when it is applied rather than merely written down.

What we will not build

Refusals describe a service more precisely than intentions do. These are products we could sell and do not.

  • No search by identity attribute. There is no search by name, date of birth, national identification number, postal address or telephone number. The index is queried by email address, domain or credential, never by who someone is.
  • No identity enrichment and no people search. We do not build a profile of a person across sources, and we do not offer an interface that answers the question “who is this person”.
  • No bulk plaintext. Secrets are masked by default. Revealing one is an explicit, metered and logged action on an individual record. No interface returns a bulk plaintext dump in response to a broad query.
  • No advertising or resale use of the data. The datasets are not used for profiling, advertising, scoring or any purpose other than letting someone find their own exposure or the exposure of a perimeter they are responsible for.

Requests from authorities

During the period we received 0 binding legal demands from any authority, and complied with 0. Lawful process should be addressed to contact@leakradar.io and is answered without undue delay. The publisher’s identity and registered office are in our Terms of Service.

What we can produce on a valid legal request

  • the declared identity of an account, its confirmed email address and its billing identity
  • the search and unlock history of an account, with timestamps and originating IP addresses
  • the provenance of a specific record, up to the source file it was extracted from

What no authority gets

No authority has direct, automated, bulk or privileged access to our systems. There is no administrative interface reserved for public bodies and no back door. We answer lawful process, and we do not grant access outside it.

Separately from any legal demand, eligible law enforcement, government and military teams in the EU or US can get free access for their official work by emailing contact@leakradar.io. That access carries no technical privilege: the same interface, the same limits and the same per-record metering as any paying customer. The only difference is that there is no invoice. It is a pricing decision, not a legal channel, and it is not counted in the figure above.

Accountability documentation

The following documents are held and are provided in full to the competent supervisory authority on request. They are internal accountability records and are not published, because they describe the security architecture of the service.

  • Record of Processing Activities, Article 30 (reference RF-PRIV-ROPA-001)
  • Legitimate Interest Assessment supporting the Article 6(1)(f) basis (RF-PRIV-LIA-001)
  • Data Protection Impact Assessment, Article 35 (RF-PRIV-DPIA-001)

Business customers can obtain an extract of the Record of Processing Activities under the confidentiality terms of our Data Processing Agreement. Our security measures, our sub-processors and our retention schedule are public.

Having your data removed

You do not need an account, and it costs nothing. Use the removal request form. For an email address, we send a confirmation link to that address, because approving an unverified request would let anyone erase someone else’s record. Domain requests are reviewed by hand.

An approved request deletes the matching records from the credential index and blocks the value permanently, so it cannot reappear from a later source. Where the same value also appears inside a verbatim source archive that we index as full text, the value is blocked from every search rather than excised from the file itself, because editing a source archive would destroy the integrity of the evidence it constitutes.

You can also object to the processing, or ask what we hold about you, by writing to contact@leakradar.io.

Methodology

Each counter is stated here as the exact question it answers, so that the number can be read without trusting us about what it means.

  • Active exclusion rules. Rules the engine actually evaluates at query time. A rule that exists but is not enabled is not counted. This is a running total, not a figure for the period, stated as of the date the figures were read.
  • On a data subject request. Among those rules, the ones created because a person asked to be removed, as opposed to the ones we apply as a matter of policy.
  • Accounts suspended. Accounts closed by us, all causes combined: payment fraud, breach of the terms, and abuse. This is a running total since launch, not a figure for the period.
  • Removal requests. Requests received during the period, with their status as observed on the date the figures were read.
  • Legal demands from authorities. Binding legal demands only. Free access granted to public bodies is excluded, as explained above.
  • Administrator accesses. Sessions during the period in which a member of staff opened a customer account. A reason is mandatory and is retained with each one.

Related documents