Privacy notice Plain English
Your email is checked,
not collected.
Breachlight is designed to answer one question and then forget the lookup. We do not create accounts, build search histories, or store submitted email addresses or lookup hashes.
What you submit
You submit an email address only when you press “Check my email.” Browser validation happens before the lookup begins.
Breachlight does not ask for your password and will never display leaked password values.
Primary lookup
Your email address is sent directly from your browser to XposedOrNot over HTTPS. It returns known source names and, when available, the types of data exposed.
According to XposedOrNot’s published terms, searches are processed in memory and are not logged. Its own policies govern that processing.
Fallback lookup
If the primary service is unavailable, your browser converts the normalised email address into a SHA-256 hash and sends only the first 24 hexadecimal characters of that hash to Breachlight’s fallback endpoint.
The fallback endpoint forwards that shortened hash to LeakCheck. It is not written to a database, log, cookie, or analytics system by Breachlight.
Bot protection
If the fallback lookup is needed, Breachlight uses Cloudflare Turnstile to distinguish legitimate use from automated abuse. The managed challenge is loaded only at that point, not for every primary lookup.
Turnstile may process browser and device signals under Cloudflare’s privacy policy. Breachlight does not receive a device profile; it receives only a short-lived verification token and does not retain it.
Retention and tracking
- No email addresses or lookup hashes are retained by Breachlight.
- No account or search history is created.
- No advertising cookies or behavioural profiling are used.
- Responses are marked not to be stored by browser or intermediary caches.
- The fallback route is paced without recording an email, hash, or IP address.
Operational measurements
Breachlight counts successful and failed checks, the provider used, and a broad response-time band. These counters contain no email address, lookup hash, result contents, form fields, cookie identifier, or IP address.
The counters exist only in volatile application memory and reset automatically when the service restarts. They are used solely to identify outages and performance problems.
Hosting information
Like nearly every public website, Breachlight’s hosting and network providers may process ordinary connection metadata—such as an IP address, user agent, requested path, and timestamp—for delivery, security, and reliability. Breachlight does not add that connection metadata to its product measurements or combine it with a submitted email address.
Third-party breach providers process lookup requests under their own policies, described below.
Responsible use
Only check an address that you own or are authorised to assess. Breachlight is not intended for surveillance, harassment, account targeting, or compiling information about another person without permission.
Limits of the result
Breach databases have different sources and update schedules. A match means the provider has associated the address with a known exposure record. No match is reassuring, but it cannot prove that the address has never been exposed.
The result is a security aid, not a credit-monitoring, identity-protection, or legal service.
Provider policies
Third-party processing is governed by each provider’s terms and privacy information:
Breachlight only needs the email address you want to check. If a page claiming to be Breachlight asks for a password, close it.