Breachy
Legal

Legal · Terms & Conditions

Breachy — Terms & Conditions

Version 1.1 · Effective 28 September 2026

1. Who we are, and what this agreement covers

1.1 Provider: Wolfcore Ltd, a company registered in England and Wales (company no. 16308559), registered office 72 Newbiggin, Malton, North Yorkshire, YO17 7JF ("Wolfcore", "we", "us"). ICO registration ZB977950.

1.2 Breachy means the Breachy mobile applications, the web portal, and the services reached through them.

1.3 These terms form an agreement between you and Wolfcore from the moment you create an account. If you are agreeing on behalf of an organisation, you confirm you have authority to bind it, and "you" means that organisation.

1.4 Two sets of rules run through this agreement, and it matters which applies to you:

  • Consumer terms apply on the Free, Personal and Family plans, where you are acting for purposes outside your trade, business, craft or profession. Sections 5, 13.4 and 16 are written for you, and nothing in this agreement limits your statutory rights.
  • Business terms apply on the Business plan. Section 9 applies, and the Data Processing Agreement is incorporated by reference.

Where a clause applies to only one of the two, it says so.

1.5 Also incorporated: the Acceptable Use Policy, the Privacy Policy, and — on the Business plan — the Data Processing Agreement.

2. What Breachy does

2.1 Breachy checks email addresses you have verified, and domains you have proved you control, against known data-breach and infostealer records. It tells you what was exposed, scores your overall exposure, and walks you through fixing it.

2.2 What a finding means. Appearing in a breach record means your data was in a set that was exposed. It does not mean an account was accessed, and it does not mean anyone has used it. We keep that distinction everywhere in the product, and we keep it here.

2.3 We never hold the stolen data. Our sources tell us which breach an address appeared in and what kinds of data that breach contained. The leaked records themselves — the passwords, the personal details — are never downloaded, stored or shown by Breachy. A finding is a fact about an address; it is not a copy of what was taken.

2.4 What Breachy is not. It is not antivirus, a password manager, a credit-monitoring service, identity-theft insurance, or a guarantee that you will be told about every exposure. It cannot see breaches nobody has disclosed, breaches our sources do not hold, or data circulating privately. An empty result means we found nothing, not nothing happened.

2.5 We never handle your passwords. Breachy does not ask for, store, or transmit a password to any third-party service, in any form. Any communication that appears to come from us and asks for one is not from us.

2.6 Breachy depends on third-party breach intelligence, and its coverage, accuracy and timing are set by those sources. We describe them in the Privacy Policy.

3. Accounts and sign-in

3.1 Breachy has no passwords. You sign in with a code sent to your email address, and — where your device supports it — with a passkey.

3.2 You are responsible for keeping access to your email account and your devices secure, and for anything done through your account by someone with that access.

3.3 Tell us at info@wolfcore.co.uk if you believe someone else has access to your account.

3.4 One account belongs to one person. Do not share sign-in access.

4. Plans, prices and payment

4.1 Current plans and prices are shown in the app and on our website. Prices are in pounds sterling and include VAT where it applies.

4.2 Where you pay matters.

  • Bought in the iOS or Android app: Apple or Google is the merchant. They take the payment, they hold the billing relationship, and refunds and cancellations go through them under their terms, not ours.
  • Bought through our web portal: Wolfcore is the merchant, payment is processed by Stripe, and sections 4.3 to 4.6 apply.

4.3 Subscriptions renew automatically at the end of each billing period until cancelled. A monthly plan renews monthly; an annual plan renews annually.

4.4 You may cancel at any time. Cancellation stops the next renewal; it does not shorten the period you have already paid for, and your plan runs to the end of it.

4.5 We may change prices. Existing subscribers get at least 30 days' notice by email, and a change takes effect at the next renewal. If you do not want the new price, cancel before then.

4.6 If a payment fails we may retry it, and may suspend paid features until it succeeds. We will tell you before we do.

4.7 The free plan. The Free plan is a single exposure check of the address you sign in with. We may change what the Free plan includes, or withdraw it, on reasonable notice. We will not take away something you have paid for.

5. Your right to cancel — consumers only

5.1 Under the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 you have 14 days from the day you enter into the contract to cancel a paid plan bought through our web portal and get a refund.

5.2 If you ask us to start the service inside that 14-day period — which is what happens when you subscribe and keep using Breachy — you may still cancel, and we may charge a proportionate amount for the service you actually received before cancelling.

5.3 To cancel, email info@wolfcore.co.uk or use the cancellation controls in your account. You do not have to give a reason.

5.4 For purchases made in the iOS or Android app, the equivalent right sits with Apple or Google and is exercised through their refund process.

5.5 Nothing here affects your rights under the Consumer Rights Act 2015, which include the right to a repeat performance or a price reduction if the service is not supplied with reasonable care and skill.

6. Acceptable use

6.1 The Acceptable Use Policy is part of this agreement, and breaking it is a breach of these terms.

6.2 In short: monitor addresses and domains you are entitled to monitor, and do not use what Breachy shows you to harm anyone.

7. Addresses, domains and consent

7.1 Every monitored address is verified by the address itself. The address you sign in with is verified by the sign-in code. Adding any other address sends a code to that address, and monitoring begins only when the code is entered. That is the whole consent mechanism: you can add any address you like, and nothing happens until whoever reads that inbox agrees.

7.2 You must not attempt to monitor an address you do not control and do not have permission to monitor. Verification exists to make that difficult; attempting it anyway is a breach of this agreement and of the Acceptable Use Policy.

7.3 Domains. An organisation sets one company domain. Setting it does not monitor anyone: a person's address at that domain is checked only after they have accepted an invitation to the organisation and verified the address themselves, as in 7.1. Personal mailbox providers cannot be set as a company domain, and a domain held by another organisation cannot be set until that organisation releases it. We may ask an organisation to demonstrate that a domain is its own, and may remove a domain that is not.

7.4 Anyone whose address is monitored may withdraw consent at any time, from their own account or by emailing info@wolfcore.co.uk. Withdrawing stops monitoring immediately and deletes the findings for that address.

8. Family plans and dependants

8.1 A Family plan has one guardian, who administers it, and up to five other members.

8.2 A dependant must be 16 or over. Breachy is not designed for younger children, and you must not add an address belonging to someone under 16. A guardian adding a dependant confirms their age, and that confirmation is recorded.

8.3 Adding a dependant sends a verification code to their own address. Monitoring begins only when that code is entered.

8.4 Guardian controls let a guardian receive a dependant's alerts, approve certain actions, and see the family dashboard. The dependant is shown which controls are on. We will not build a version of this that hides monitoring from the person being monitored.

8.5 A dependant may leave a family at any time and keep their own account.

9. Business plans

9.1 On the Business plan, you are the controller of your staff's personal data and Wolfcore is your processor. The Data Processing Agreement governs that processing and is incorporated into this agreement.

9.2 You warrant that you have a lawful basis for having us monitor the addresses and domains you register, that you have told the people concerned as your own transparency obligations require, and that you are entitled to the domains you verify.

9.3 Findings about a member of staff describe that person. Treat them as personal data and as security information, and restrict access inside your organisation accordingly.

10. Intellectual property

10.1 Breachy, and everything in it other than your data, belongs to Wolfcore. You get a non-exclusive, non-transferable right to use it while your account is active.

10.2 Your data stays yours. You grant us only the licence we need to run the service for you.

10.3 We may use aggregated, anonymised statistics — counts, trends, distributions — to improve Breachy and to describe how exposure behaves generally. Nothing that identifies you or your organisation is used this way.

10.4 Breach records come from third-party sources and are not ours to license onward. Do not scrape, resell or redistribute them.

11. Data protection

11.1 For Free, Personal and Family accounts, Wolfcore is the controller of your personal data, and the Privacy Policy explains what we do with it.

11.2 For Business accounts, Wolfcore is the processor of the staff data you register, and the controller of your own account and billing data.

11.3 The AI assistant never receives your real addresses. They are replaced with tokens such as EMAIL_1 before anything is sent to the model, and put back afterwards for display only. This is described in the Privacy Policy.

12. Warranties and disclaimers

12.1 We will provide Breachy with reasonable care and skill.

12.2 Beyond that, and to the extent the law allows, Breachy is provided as is. We do not warrant that it will be uninterrupted, that our sources are complete or accurate, that every exposure affecting you will be detected, or that acting on our guidance will prevent harm.

12.3 Breachy tells you about breaches that happened somewhere else. We did not cause them and we cannot undo them.

12.4 Breachy's guidance is general security guidance. It is not legal, financial or insurance advice.

13. Liability

13.1 Nothing in this agreement limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited.

13.2 We are not liable for indirect or consequential loss, loss of profit, loss of business, or loss of goodwill.

13.3 Business plans. Our total aggregate liability, whether in contract, tort (including negligence) or otherwise, will not exceed the total fees paid by you to us in the 12 months immediately preceding the event giving rise to the claim.

13.4 Consumers. We are responsible for loss you suffer that is a foreseeable result of our breaking this agreement or failing to use reasonable care and skill. We are not responsible for loss that was not foreseeable. This section does not affect your statutory rights.

13.5 We are not liable for loss arising from a third party's breach — the breach is the thing we tell you about, not something we caused — or from your decision not to act on a finding.

14. Suspension and termination

14.1 You may close your account at any time from the app. Closing it stops monitoring immediately and starts the deletion described in the Privacy Policy.

14.2 We may suspend or restrict access where we reasonably believe Breachy is being used in breach of this agreement or the Acceptable Use Policy, or in a way that poses a legal, security or reputational risk. Where it is safe and lawful to do so, we will tell you why and give you a chance to put it right.

14.3 Either party may terminate on written notice if the other commits a material breach that is not remedied within 30 days of notice, or becomes insolvent.

14.4 On termination we stop monitoring, and your data is deleted as described in the Privacy Policy. You can export everything we hold before you go.

15. Changes to this agreement

15.1 We may update this agreement. Material changes will be notified by email or in-app notice at least 30 days before they take effect.

15.2 If you do not accept a material change, you may cancel before it takes effect and we will refund any unused part of a period you have already paid for.

15.3 Changes we are required to make by law may take effect sooner where the law requires it.

16. Complaints — consumers

16.1 Email info@wolfcore.co.uk. We will acknowledge within 5 working days and aim to resolve within 30 days.

16.2 If you are unhappy with the outcome, you may bring proceedings in the courts described in section 18. If your complaint concerns your personal data, you may also complain to the Information Commissioner's Office at ico.org.uk.

17. General

17.1 You may not assign this agreement without our consent. We may assign it to a successor of our business.

17.2 Notices to us go to info@wolfcore.co.uk; notices to you go to the email address on your account.

17.3 This agreement, and the documents it incorporates, is the entire agreement between us on its subject matter.

17.4 If a clause is found unenforceable, the rest stands.

17.5 Neither party is liable for a failure caused by something beyond its reasonable control, other than an obligation to pay.

17.6 A person who is not a party has no rights under the Contracts (Rights of Third Parties) Act 1999.

18. Governing law and jurisdiction

18.1 This agreement, and any dispute or other matter arising out of it, are governed by and construed in accordance with the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

18.2 If you are a consumer resident elsewhere in the United Kingdom, you may bring proceedings in the courts of the part of the UK where you live, and the mandatory consumer-protection law of that part applies.


Wolfcore Ltd · 72 Newbiggin, Malton, North Yorkshire, YO17 7JF · Company no. 16308559 · ICO ZB977950 · info@wolfcore.co.uk