• First and last name, email address, hashed password (bcrypt cost 12).
• Postal address, phone number, country, VAT number (for invoices).
• Technical and security data: IP addresses at sign-up and login, your account identifier, the type of searches you perform (for example email search, domain search or raw search) and audit logs of unlock operations (timestamp, account identifier and internal leak identifier).
• Contact form messages: the content of your message, your email address, the topic you pick, the optional reference you add, your IP address, your user agent, your locale and the status we give the message while we handle it, processed to answer your request on the basis of our legitimate interest in replying to people who write to us (GDPR art. 6(1)(f)) and kept for 12 months.
• Breach and leak datasets: personal data contained in breaches and stealer logs that were accessible on the internet without our involvement in the original incident. Depending on the source this may include email addresses, usernames, passwords or password hashes and other profile or technical data that were present in the leaked file.
• Special categories of data: we do not seek to index special categories of personal data (such as data revealing health, political opinions, religious beliefs, trade-union membership, sexual orientation or sex life) or data relating to criminal convictions and offences. Where we become aware that such data is present in a dataset, we filter, restrict or remove it.
Cookies and providers: We use necessary storage to run LeakRadar. With your permission, we also measure usage and campaigns, personalize advertising and enable support chat. You can refuse optional tracking and change your choice at any time.