Legal

Privacy Policy

Last updated: August 2026

Breachrr is a product of Breachrr Ltd., which is the controller of the personal data described in this policy. Where this policy refers to “Breachrr”, “we”, “us”, or “our”, it refers to Breachrr Ltd.

What we collect

When you create an account, we collect your company name, work email address, and a hashed password. We do not store plain-text passwords.

When you use the free audit tool, we collect the domain or email address you audit. If you request a follow-up report, we store your email address to deliver the report.

When you add a domain to your account or submit an audit request, we record your affirmative confirmation that you are authorised to monitor the asset, together with a timestamp and the network identifier from which the confirmation was made. These records support the authorisation requirement in our Terms of Service and may be relied on in the event of a dispute concerning your use of the service.

We collect standard server logs (IP address, browser type, pages visited) for security and operational purposes.

How we use your data

We use your domain to run monitoring scans across our data sources. We use your email address to send you alerts when new exposures are detected, and to deliver reports you request.

We do not sell your data to third parties. We do not use your data for advertising. We do not share your scan results with any party other than you.

We rely on the following legal bases to process your personal data: performance of our contract with you (running monitoring, delivering findings, and providing the account features you have subscribed to); our legitimate interests (security, product analytics, service improvement, and defence of legal claims); your consent (where required, particularly for non-essential cookies and analytics); and compliance with legal obligations (including tax, accounting, and regulatory requirements).

Email audit privacy guardrail

The free email audit at /audit sends the full report only to the audited address. We do not forward email audit results to any other destination. This is enforced server-side and cannot be overridden.

Data sources

Breachrr aggregates data from multiple third-party breach databases, infostealer intelligence feeds, public code repositories, and domain infrastructure records. We do not store the underlying breach data — we query it at scan time and return results to you.

Cookies and analytics

We use cookies and product analytics tools to understand how the service is used and to improve it. Essential cookies are necessary for the service to function (for example, to keep you signed in). Non-essential cookies and analytics — including product analytics and, where enabled, marketing analytics — are used only where you have provided consent.

For visitors in the European Economic Area, the United Kingdom, and other regions where consent is required by law, non-essential cookies and analytics are loaded only after you accept them through the cookie banner shown on first visit. You may withdraw consent at any time by clearing cookies or contacting us.

Third-party service providers

We use third-party service providers to operate Breachrr, including for infrastructure and database hosting, transactional email delivery, payment processing, and product analytics. A current list of service providers is available on request to info@breachrr.com. Where a customer's use of Breachrr requires a formal Data Processing Agreement, we will enter into one on request.

International transfers

Your personal data may be processed in countries other than your own, including where our service providers are located. Where the destination country does not provide an equivalent level of data protection under applicable law, we put appropriate safeguards in place, including standard contractual clauses or equivalent transfer mechanisms.

Data retention

We retain your personal data only for as long as necessary for the purposes described in this policy.

  • Account data (registered email address, company name, hashed password, domains under monitoring, and configuration): retained for the duration of your subscription and for 90 days after cancellation, then permanently deleted.
  • Findings and remediation notes: deleted with your account data.
  • Attestation records (the authorisation confirmations, timestamps, and network identifiers described above): retained for 3 years after termination of your account, so that they remain available in the event of a dispute concerning your use of the service.
  • Free audit data (domains and email addresses submitted through the free audit tool): retained for 12 months, then deleted.
  • Server logs (IP address, browser type, pages visited): retained for 30 days.
  • Billing and tax records (invoices, transaction records, and related financial data): retained for 7 years, in line with statutory obligations.

Your rights

You may request access to, rectification of, or deletion of your personal data at any time by emailing info@breachrr.com. We will process such requests within 30 days.

If you are located in the European Economic Area or the United Kingdom, you have specific rights under the EU General Data Protection Regulation (GDPR) and the UK GDPR, including the rights to access your personal data, to have it rectified or erased, to restrict or object to its processing, to data portability, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.

If you are a California resident, you have rights under the California Consumer Privacy Act, including the right to know what personal information we collect and to request its deletion. We do not sell personal data, and Breachrr is not designed to profile individuals for advertising.

Security

All data is transmitted over TLS. Passwords are hashed using bcrypt. We do not store payment card data — payments are processed by Paystack and are subject to their security standards.

In the event of a personal data breach affecting your data, we will notify affected users without undue delay and in accordance with applicable law.

Changes to this policy

We may update this policy from time to time. Material changes will be announced at least 30 days in advance by email to the address associated with your account and by notice within the service. Non-material changes (such as clarifications) take effect on posting. Continued use of Breachrr after changes take effect constitutes acceptance of the updated policy.

Contact

Questions about this policy: info@breachrr.com