Accepted
Email addresses submitted for an exposure search and basic request metadata required to operate and protect the service.
Privacy
An exposure checker should answer a narrow question without becoming another source of sensitive information. These controls define what the registry accepts and what it refuses.
Email addresses submitted for an exposure search and basic request metadata required to operate and protect the service.
Passwords, authentication tokens, MFA codes, recovery codes, payment information, or the contents of private accounts.
The email address entered into the checker is used to compare the request against indexed exposure records and to protect the integrity of the service. Search results do not reveal raw breach records or passwords.
Search activity is retained only for the active assessment period and its approved reporting window. It is not used for advertising, marketing profiles, or sale to third parties.
The registry’s public event interface rejects fields that resemble passwords, credentials, secrets, tokens, OTP values, or MFA codes. Administrative results are isolated behind restricted access.
If you reached the registry through an organizational security exercise, contact your internal Security or Privacy team for questions about participation, access to results, and deletion procedures.