Breachy
Legal

Legal · Acceptable Use Policy

Breachy — Acceptable Use Policy

Version 1.1 · Effective 28 September 2026

This policy forms part of the Breachy Terms & Conditions. Breaking it is a breach of those terms.

1. Definitions

1.1 Breachy — the Breachy applications, portal and services.

1.2 Monitored Address — an email address that has been verified by a code sent to that address, and is being checked against breach records.

1.3 Company Domain — the email domain an organisation has set on its account. Only members who have accepted an invitation to that organisation, and verified their own address at that domain, are matched to it.

1.4 Finding — a record that a Monitored Address, including a member's verified address at a Company Domain, appears in a known breach or infostealer dataset, together with what that dataset contained.

1.5 Dependant — a member of a Family plan whose monitoring a guardian administers.

2. Authorised use

2.1 Breachy is for monitoring the breach exposure of addresses and domains you are entitled to monitor, and for acting on what it finds.

2.2 You may monitor:

  • an email address you control, proved by verifying it;
  • an address belonging to someone who has confirmed the verification code themselves;
  • the addresses at your organisation's own domain, where each person has accepted an invitation and verified their own address.

2.3 Verification is not a formality. It is the mechanism by which the person being monitored consents. Do not try to work around it.

3. Prohibited uses

You must not use Breachy to:

3.1 Monitor an address belonging to someone who has not consented, including by obtaining their verification code by deception, coercion, or access to their inbox that they have not knowingly given you.

3.2 Monitor a person covertly — including a partner, ex-partner, family member, employee or anyone else — where they are not aware the monitoring is happening. Breachy is not a surveillance tool and we will not treat it as one.

3.3 Monitor a domain you do not control, or make a verification claim over a domain belonging to someone else.

3.4 Take Findings about a person and use them to threaten, harass, extort, stalk, defame, discriminate against, or otherwise harm them.

3.5 Attempt to access an account belonging to someone else, whether or not Breachy showed it as exposed. A Finding is a warning to the person affected; it is not a target list.

3.6 Resell, redistribute, scrape, bulk-export or republish breach records obtained through Breachy, or use them to build a competing dataset.

3.7 Use Breachy to enrich, verify or validate a list of addresses obtained elsewhere, including for marketing, credential-stuffing, or lead generation.

3.8 Add addresses in bulk that you have no relationship with, or use Breachy as a lookup service on behalf of third parties.

3.9 Use Breachy for anything unlawful, or in breach of the Computer Misuse Act 1990, the Data Protection Act 2018 or the UK GDPR.

3.10 Circumvent, disable or interfere with security, rate limits, quotas, plan limits or authentication, or probe the service for vulnerabilities outside a testing programme we have agreed with you in writing.

3.11 Attempt to extract, reconstruct or repurpose the AI assistant's instructions, or use the assistant to generate content unrelated to your own security posture.

3.12 Share account access, or resell access to Breachy.

4. Monitoring people you are responsible for

4.1 A Family plan may include a Dependant aged 16 or over whose address has been confirmed by the verification code sent to it.

4.2 The Dependant is shown which guardian controls are switched on. You must not represent to a Dependant that monitoring is off when it is on, or configure the account to conceal it.

4.3 A Dependant may withdraw consent and leave the family at any time. You must not obstruct that.

4.4 On a Business plan, monitoring staff addresses is your decision as controller, and your transparency obligations to those staff are yours to meet. Breachy gives you the records; it does not give you a lawful basis.

5. Findings are security information

5.1 A Finding about a member of staff, or about a family member, describes a real person and usually describes something that happened to them rather than something they did.

5.2 Restrict access to Findings inside your organisation to the people who need them, and use them to help the person affected rather than to assess or penalise them.

5.3 Do not disclose a Finding about an individual more widely than the response requires.

6. Accuracy and limits

6.1 Breach data comes from third-party sources. It can be incomplete, mis-dated, or wrong, and an address can appear in a dataset that has been mislabelled.

6.2 Do not treat a Finding as proof that an account was accessed, that a person was negligent, or that a specific password is in use. It is evidence that data was in an exposed set.

6.3 Do not present Breachy output as a certification, audit, or assurance to a third party.

7. Suspension and enforcement

7.1 Wolfcore may investigate suspected breaches of this policy and may suspend or restrict access, remove content, or terminate the agreement in accordance with its terms where it reasonably believes Breachy is being used in breach of this policy or in a manner that poses legal, security or reputational risk.

7.2 Where the suspected misuse is covert monitoring of an individual, we may suspend immediately and without prior notice, and we may tell the person being monitored.

7.3 Serious misuse may be reported to any relevant regulator or law-enforcement authority.

8. Reporting misuse

8.1 If you believe Breachy is being used against you, or in breach of this policy, email info@wolfcore.co.uk. Tell us the address concerned and what is happening.

8.2 If you believe you are being monitored without your knowledge, we will act on that report regardless of who holds the account.

9. Changes to this policy

9.1 We may update this policy. Material changes will be notified in accordance with the Terms & Conditions.

10. Governing law

10.1 This policy is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.


Wolfcore Ltd · 72 Newbiggin, Malton, North Yorkshire, YO17 7JF · Company no. 16308559 · info@wolfcore.co.uk