Breachy
Legal

Legal · Privacy Policy

Breachy — Privacy Policy

Version 1.0 · Effective 5 September 2026

Wolfcore Ltd ("we", "us") operates Breachy. We are registered in England and Wales, company no. 16308559, at 72 Newbiggin, Malton, North Yorkshire, YO17 7JF, and registered with the Information Commissioner's Office under reference ZB977950.

Contact for anything in this policy: info@wolfcore.co.uk.

1. The short version

  • We never ask for, store or transmit your passwords. Not once, not encrypted, not ever.
  • We never hold the stolen data. We learn which breach an address appeared in and what kinds of data it contained; the leaked records themselves are never downloaded, stored or shown.
  • Your monitored addresses are encrypted in our database and masked in the app by default.
  • The AI assistant sees tokens like EMAIL_1. It never receives your real address.
  • We do not sell breach data or personal information. There is no second business model here.
  • You can export everything we hold, or delete it, from your profile.

The rest of this policy is the detail behind those six lines.

2. Our two roles

2.1 Controller — for Free, Personal and Family accounts, and for every account's own registration and billing data. We decide what is collected and why, and this policy explains it.

2.2 Processor — for the staff identities, domains and findings on a Business account. There, the customer organisation is the controller: it decides whose addresses are monitored and why. We act on its instructions under the Data Processing Agreement, and if you are one of that organisation's staff, the organisation is who you should ask about the monitoring in the first instance.

3. What we collect

Account data. Your email address; a display name if you give one; your plan; your notification and privacy settings; any passkeys registered to your account (a credential identifier and a public key — never a biometric, and never anything that can sign on your behalf).

Monitored identities. The email addresses you have verified — starting with the one you sign in with — and the domains your organisation has proved it controls. Addresses are held encrypted with AES-256-GCM, and matched using a keyed HMAC blind index so a lookup never needs the plaintext.

Consent records. Who agreed to monitor which address, when, by what method, and what they were shown. We keep these because the consent is the lawful basis and it has to be evidenced.

Findings. Which breach and infostealer datasets an address appears in, what categories of data those datasets contained, when they occurred and when they reached our source, and the severity we calculated. Not the leaked data itself — see §1.

What you tell us about your own security. Which accounts you have turned two-step verification on for, which passwords you have changed, which remediation steps you have completed.

Assistant conversations. Your questions and our answers, in tokenised form — see §6. We keep a count of questions asked per month to apply your plan's allowance; the text of your questions is not stored for that purpose.

Activity and audit records. Sign-ins, verification attempts, consent changes, exports and deletions, and administrative actions on family and business accounts.

Technical data. A keyed hash of your IP address (never the address itself), coarse device and app version information, and timestamps. Used for session security, rate limiting and abuse prevention.

Billing identifiers. A Stripe customer and subscription identifier, or an Apple/Google transaction identifier. We never see or store your card details — the payment provider holds those.

What we do not collect. Passwords. Payment card numbers. Precise location. Contacts. Message or file contents. Anything from your device beyond what is listed above.

4. Special category data — said plainly

4.1 We do not ask for, and do not intentionally process, special category data.

4.2 But a breach record names its source. Learning that an address appeared in a breach of a health service, a dating service or a political organisation can imply something about the person, and we are not going to pretend otherwise.

4.3 So: we take the source name from our provider and show it to you unchanged. We do not infer, derive, categorise or score anything from what the source implies, we do not use it for profiling, and we do not disclose it to anyone other than the account it belongs to.

5. Why we process it, and our lawful bases

What we doLawful basis
Run your account and provide the service you subscribed toPerformance of a contract
Monitor a specific email addressConsent, given by the person who controls that address, by entering the code sent to it
Monitor addresses at a verified company domain (Business)Our customer's lawful basis as controller — see the DPA
Send sign-in and verification codesPerformance of a contract
Send exposure alerts you have asked forPerformance of a contract; consent for optional channels
Keep the service secure, rate-limit, detect and prevent abuseLegitimate interests
Take payment and keep accounting recordsContract; legal obligation
Improve Breachy using aggregated, anonymised statisticsLegitimate interests

5.1 Where we rely on consent, you can withdraw it at any time; monitoring of that address stops and its findings are deleted. Withdrawing does not affect processing that already happened.

5.2 Where we rely on legitimate interests, we have balanced them against your rights, and you can object — see §10.

6. The AI assistant

6.1 Breachy includes an assistant that explains your findings and what to do about them. It runs on a model provided by Anthropic.

6.2 Your addresses never reach it. Before any request leaves our service, every address in the material is replaced with a token — EMAIL_1, EMAIL_2 — and the tokens are substituted back for display after the answer returns. The model provider receives the tokens, the breach names and the guidance context, and not the identifiers.

6.3 Your conversations are not used to train anyone's models.

6.4 The assistant gives general security guidance. It is not legal, financial or insurance advice, and it can be wrong. Findings themselves come from our sources, not from the model.

7. Who we share it with

We do not sell personal data, and we do not share it for anyone else's marketing. We use the following sub-processors, each under a written contract:

ProviderPurposeLocation
SupabaseDatabaseAWS eu-west-2 (London, UK)
HetznerCloud hosting and infrastructureEU (Germany)
SendGrid (Twilio)Sign-in and verification code deliveryUS — SCCs / UK IDTA
StripePayment processing (web purchases)US/EU — SCCs / UK IDTA
Apple, GoogleIn-app purchase billing and app distributionUS — SCCs / UK IDTA
AnthropicAI breach assistant (tokenised input only)US — SCCs / UK IDTA
XposedOrNotBreach-exposure lookup by emailGoogle Cloud / Cloudflare — outside UK
SentryError and crash monitoring (scrubbed)US/EU — SCCs / UK IDTA

7.1 Crash reports are scrubbed before they leave us. Addresses, tokens, secrets and request bodies are removed, and an event that still looks like it contains personal data is dropped rather than sent. This is enforced in code, not by policy alone.

7.2 We will also disclose personal data where we are legally required to, or to establish or defend legal claims. If our business is sold or reorganised, data may transfer with it, and this policy continues to apply.

7.3 An up-to-date sub-processor list is maintained here. Business customers are notified of changes as the DPA requires.

8. International transfers

Your data is stored in the United Kingdom. The database holding your account, your monitored addresses and your findings runs in London, so the primary record of everything in §3 never leaves the UK.

Some of the providers in §7 are outside the UK. Those transfers are made under UK adequacy regulations where they apply, and otherwise under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment on file.

9. Security

9.1 Monitored addresses are encrypted at rest with AES-256-GCM under a key held outside the database, and matched by keyed HMAC blind index. Encryption keys can be rotated without downtime and old keys retired.

9.2 Authentication is a one-time code to your email address, with a passkey where your device supports it. There are no passwords in Breachy, which means there is no password of ours to breach.

9.3 Every route in our API resolves the caller from their session and checks ownership of the object being requested. Access is denied by default, and a route that fails to declare an ownership rule stops the service from starting rather than shipping open.

9.4 Addresses are masked in the interface by default, and revealing one is recorded.

9.5 Logs and crash reports are redacted before they are written.

9.6 We test the service, including by independent security testing, and we fix what we find.

9.7 No service is perfectly secure. If a breach of our own affects you, we will tell you and the ICO as the law requires.

10. Your rights

10.1 You have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent.

10.2 Access and portability are built in. Your profile has an export that returns everything we hold about you in a machine-readable file, without you having to ask us.

10.3 Erasure is built in. Deleting your account or an identity takes effect immediately — monitoring stops and it disappears from the app — and the underlying records are permanently destroyed 30 days later. The 30 days exist so a mistaken or hostile deletion can be undone by signing back in; after that it is gone and we cannot recover it.

10.4 To exercise any other right, email info@wolfcore.co.uk. We respond within one month, and will tell you if we need longer.

10.5 If you are a member of staff on a Business account, send access and erasure requests to your employer, who is the controller. We will help them respond.

10.6 You can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first.

11. How long we keep things

DataRetained
Account, identities, findingsWhile your account is open
A deleted account or identityHidden immediately; permanently destroyed after 30 days
Consent recordsWith the identity they belong to; destroyed with it
Activity and audit recordsFor the life of the account; destroyed with it
Sign-in attempts and verification challengesPurged automatically on a rolling basis
Domain verification proofsExpire and are re-issued periodically
Billing and accounting records6 years after the end of the relationship, as UK tax law requires
Business account dataOn the customer's instructions, per the DPA

12. Children

12.1 Breachy is not for children. You must be 16 or over to hold an account, and a monitored dependant on a Family plan must be 16 or over.

12.2 If we learn that we hold data about someone under 16, we delete it.

13. Cookies

The apps and the portal set no cookies. See the Cookie Notice.

14. Marketing

We send service messages — exposure alerts, security notices, billing — because they are part of the service. Marketing email is separate, is opt-out at any time, and never contains your findings.

15. Automated decision-making

The Exposure Score is a calculation, not a decision about you. It is derived from the findings on your account and the steps you have completed, it is explained in the app, and nothing legal or similarly significant happens automatically as a result of it.

16. Changes to this policy

We may update this policy. Material changes will be notified by email or in-app notice before they take effect, and the version and date at the top will change.

17. Contact

info@wolfcore.co.uk · Wolfcore Ltd, 72 Newbiggin, Malton, North Yorkshire, YO17 7JF · Company no. 16308559 · ICO ZB977950