This page is the public account of how LeakRadar is operated: where the data comes from, what is filtered out before any result is returned, who is allowed to query it, what happens when someone asks to be removed, and how we answer an authority. A safeguard nobody can inspect is indistinguishable from one that does not exist, so the controls described here are published alongside the figures that show them working.
The figures are read directly from our production systems and cover the last completed quarter. They are refreshed automatically, so this page moves to the next quarter on its own. Every counter carries its exact definition in the methodology section, including two figures we deliberately do not publish, and why. The identity of the publisher, its registered office and its legal contact details are set out in our Terms of Service.
2,603
Active exclusion rules
264 created on a data subject request
84
Accounts suspended
All causes, since launch
150
Removal requests received
During the period
0
Legal demands from authorities
During the period
An exclusion rule removes a value from every result set before results are returned. The lists cover banking and payment institutions, cryptocurrency exchanges and wallet services, and any value blocked following a request from the person concerned. They are evaluated on the email, domain, advanced and raw search surfaces, and on export and unlock as well, so a value that cannot be searched cannot be exported or revealed either.
A rule is not a domain. Rules are counted here because that is what the engine actually evaluates, and counting domains would mean guessing how many values each rule covers.
| Field evaluated | Active rules | On a data subject request |
|---|---|---|
| Website domain | 1,984 | 66 |
| Website TLD | 9 | 0 |
| Username | 546 | 197 |
| Email domain | 63 | 1 |
| Email TLD | 1 | 0 |
| Total | 2,603 | 264 |
Of those, 1 match by pattern rather than by exact value. A single pattern rule covers an indeterminate number of values, so the totals above should be read as a count of rules, never as a count of blocked domains.
Anyone can ask for their data to be removed, free of charge, with or without an account. Requests filed from the public site are confirmed by a link sent to the address concerned, so that nobody can file on behalf of someone else.
| Received during the period | 150 |
| Approved | 143 |
| Rejected | 7 |
| Still under review | 0 |
| Filed without an account, never confirmed by the requester | 0 |
| Filed from the public site rather than from an account | 0 |
Requests are counted in the quarter they were received, with their status as observed on 25 August 2026. A request received late in a quarter and decided afterwards stays in that quarter.
| Active data quality rules | 290 |
| Corrupted batches deleted from the index | 0 |
| Administrator accesses to a customer account, during the period | 34 |
Data quality rules discard records whose parsing produced something that is not a usable credential. Corrupted batches are whole source batches removed from the index because parsing destroyed the identifiers they contained. Both remove data from the index rather than add to it.
LeakRadar indexes credential files that are already in circulation: stealer logs, combolists, breach dumps and posts published on dark web forums. What matters is what we do not do to obtain them.
There is no anonymous access and no free tier over the credential datasets. Every account is bound to a confirmed email address, to accepted contractual terms and to a billing identity. The paywall is an identification gate as much as a price: we would rather serve fewer people than serve people we cannot name.
Every search and every unlock is recorded with the account, the timestamp and the originating IP address. Customers warrant a lawful basis for each query, and misuse ends the relationship without refund. The count of suspended accounts above is what that rule looks like when it is applied rather than merely written down.
Refusals describe a service more precisely than intentions do. These are products we could sell and do not.
During the period we received 0 binding legal demands from any authority, and complied with 0. Lawful process should be addressed to contact@leakradar.io and is answered without undue delay. The publisher’s identity and registered office are in our Terms of Service.
No authority has direct, automated, bulk or privileged access to our systems. There is no administrative interface reserved for public bodies and no back door. We answer lawful process, and we do not grant access outside it.
Separately from any legal demand, eligible law enforcement, government and military teams in the EU or US can get free access for their official work by emailing contact@leakradar.io. That access carries no technical privilege: the same interface, the same limits and the same per-record metering as any paying customer. The only difference is that there is no invoice. It is a pricing decision, not a legal channel, and it is not counted in the figure above.
The following documents are held and are provided in full to the competent supervisory authority on request. They are internal accountability records and are not published, because they describe the security architecture of the service.
Business customers can obtain an extract of the Record of Processing Activities under the confidentiality terms of our Data Processing Agreement. Our security measures, our sub-processors and our retention schedule are public.
You do not need an account, and it costs nothing. Use the removal request form. For an email address, we send a confirmation link to that address, because approving an unverified request would let anyone erase someone else’s record. Domain requests are reviewed by hand.
An approved request deletes the matching records from the credential index and blocks the value permanently, so it cannot reappear from a later source. Where the same value also appears inside a verbatim source archive that we index as full text, the value is blocked from every search rather than excised from the file itself, because editing a source archive would destroy the integrity of the evidence it constitutes.
You can also object to the processing, or ask what we hold about you, by writing to contact@leakradar.io.
Each counter is stated here as the exact question it answers, so that the number can be read without trusting us about what it means.