Legal · Privacy Policy
Breachy — Privacy Policy
Version 1.0 · Effective 5 September 2026
Wolfcore Ltd ("we", "us") operates Breachy. We are registered in England and Wales, company no. 16308559, at 72 Newbiggin, Malton, North Yorkshire, YO17 7JF, and registered with the Information Commissioner's Office under reference ZB977950.
Contact for anything in this policy: info@wolfcore.co.uk.
1. The short version
- We never ask for, store or transmit your passwords. Not once, not encrypted, not ever.
- We never hold the stolen data. We learn which breach an address appeared in and what kinds of data it contained; the leaked records themselves are never downloaded, stored or shown.
- Your monitored addresses are encrypted in our database and masked in the app by default.
- The AI assistant sees tokens like
EMAIL_1. It never receives your real address. - We do not sell breach data or personal information. There is no second business model here.
- You can export everything we hold, or delete it, from your profile.
The rest of this policy is the detail behind those six lines.
2. Our two roles
2.1 Controller — for Free, Personal and Family accounts, and for every account's own registration and billing data. We decide what is collected and why, and this policy explains it.
2.2 Processor — for the staff identities, domains and findings on a Business account. There, the customer organisation is the controller: it decides whose addresses are monitored and why. We act on its instructions under the Data Processing Agreement, and if you are one of that organisation's staff, the organisation is who you should ask about the monitoring in the first instance.
3. What we collect
Account data. Your email address; a display name if you give one; your plan; your notification and privacy settings; any passkeys registered to your account (a credential identifier and a public key — never a biometric, and never anything that can sign on your behalf).
Monitored identities. The email addresses you have verified — starting with the one you sign in with — and the domains your organisation has proved it controls. Addresses are held encrypted with AES-256-GCM, and matched using a keyed HMAC blind index so a lookup never needs the plaintext.
Consent records. Who agreed to monitor which address, when, by what method, and what they were shown. We keep these because the consent is the lawful basis and it has to be evidenced.
Findings. Which breach and infostealer datasets an address appears in, what categories of data those datasets contained, when they occurred and when they reached our source, and the severity we calculated. Not the leaked data itself — see §1.
What you tell us about your own security. Which accounts you have turned two-step verification on for, which passwords you have changed, which remediation steps you have completed.
Assistant conversations. Your questions and our answers, in tokenised form — see §6. We keep a count of questions asked per month to apply your plan's allowance; the text of your questions is not stored for that purpose.
Activity and audit records. Sign-ins, verification attempts, consent changes, exports and deletions, and administrative actions on family and business accounts.
Technical data. A keyed hash of your IP address (never the address itself), coarse device and app version information, and timestamps. Used for session security, rate limiting and abuse prevention.
Billing identifiers. A Stripe customer and subscription identifier, or an Apple/Google transaction identifier. We never see or store your card details — the payment provider holds those.
What we do not collect. Passwords. Payment card numbers. Precise location. Contacts. Message or file contents. Anything from your device beyond what is listed above.
4. Special category data — said plainly
4.1 We do not ask for, and do not intentionally process, special category data.
4.2 But a breach record names its source. Learning that an address appeared in a breach of a health service, a dating service or a political organisation can imply something about the person, and we are not going to pretend otherwise.
4.3 So: we take the source name from our provider and show it to you unchanged. We do not infer, derive, categorise or score anything from what the source implies, we do not use it for profiling, and we do not disclose it to anyone other than the account it belongs to.
5. Why we process it, and our lawful bases
| What we do | Lawful basis |
|---|---|
| Run your account and provide the service you subscribed to | Performance of a contract |
| Monitor a specific email address | Consent, given by the person who controls that address, by entering the code sent to it |
| Monitor addresses at a verified company domain (Business) | Our customer's lawful basis as controller — see the DPA |
| Send sign-in and verification codes | Performance of a contract |
| Send exposure alerts you have asked for | Performance of a contract; consent for optional channels |
| Keep the service secure, rate-limit, detect and prevent abuse | Legitimate interests |
| Take payment and keep accounting records | Contract; legal obligation |
| Improve Breachy using aggregated, anonymised statistics | Legitimate interests |
5.1 Where we rely on consent, you can withdraw it at any time; monitoring of that address stops and its findings are deleted. Withdrawing does not affect processing that already happened.
5.2 Where we rely on legitimate interests, we have balanced them against your rights, and you can object — see §10.
6. The AI assistant
6.1 Breachy includes an assistant that explains your findings and what to do about them. It runs on a model provided by Anthropic.
6.2 Your addresses never reach it. Before any request leaves our service, every address in the material is replaced with a token — EMAIL_1, EMAIL_2 — and the tokens are substituted back for display after the answer returns. The model provider receives the tokens, the breach names and the guidance context, and not the identifiers.
6.3 Your conversations are not used to train anyone's models.
6.4 The assistant gives general security guidance. It is not legal, financial or insurance advice, and it can be wrong. Findings themselves come from our sources, not from the model.
7. Who we share it with
We do not sell personal data, and we do not share it for anyone else's marketing. We use the following sub-processors, each under a written contract:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database | AWS eu-west-2 (London, UK) |
| Hetzner | Cloud hosting and infrastructure | EU (Germany) |
| SendGrid (Twilio) | Sign-in and verification code delivery | US — SCCs / UK IDTA |
| Stripe | Payment processing (web purchases) | US/EU — SCCs / UK IDTA |
| Apple, Google | In-app purchase billing and app distribution | US — SCCs / UK IDTA |
| Anthropic | AI breach assistant (tokenised input only) | US — SCCs / UK IDTA |
| XposedOrNot | Breach-exposure lookup by email | Google Cloud / Cloudflare — outside UK |
| Sentry | Error and crash monitoring (scrubbed) | US/EU — SCCs / UK IDTA |
7.1 Crash reports are scrubbed before they leave us. Addresses, tokens, secrets and request bodies are removed, and an event that still looks like it contains personal data is dropped rather than sent. This is enforced in code, not by policy alone.
7.2 We will also disclose personal data where we are legally required to, or to establish or defend legal claims. If our business is sold or reorganised, data may transfer with it, and this policy continues to apply.
7.3 An up-to-date sub-processor list is maintained here. Business customers are notified of changes as the DPA requires.
8. International transfers
Your data is stored in the United Kingdom. The database holding your account, your monitored addresses and your findings runs in London, so the primary record of everything in §3 never leaves the UK.
Some of the providers in §7 are outside the UK. Those transfers are made under UK adequacy regulations where they apply, and otherwise under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment on file.
9. Security
9.1 Monitored addresses are encrypted at rest with AES-256-GCM under a key held outside the database, and matched by keyed HMAC blind index. Encryption keys can be rotated without downtime and old keys retired.
9.2 Authentication is a one-time code to your email address, with a passkey where your device supports it. There are no passwords in Breachy, which means there is no password of ours to breach.
9.3 Every route in our API resolves the caller from their session and checks ownership of the object being requested. Access is denied by default, and a route that fails to declare an ownership rule stops the service from starting rather than shipping open.
9.4 Addresses are masked in the interface by default, and revealing one is recorded.
9.5 Logs and crash reports are redacted before they are written.
9.6 We test the service, including by independent security testing, and we fix what we find.
9.7 No service is perfectly secure. If a breach of our own affects you, we will tell you and the ICO as the law requires.
10. Your rights
10.1 You have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent.
10.2 Access and portability are built in. Your profile has an export that returns everything we hold about you in a machine-readable file, without you having to ask us.
10.3 Erasure is built in. Deleting your account or an identity takes effect immediately — monitoring stops and it disappears from the app — and the underlying records are permanently destroyed 30 days later. The 30 days exist so a mistaken or hostile deletion can be undone by signing back in; after that it is gone and we cannot recover it.
10.4 To exercise any other right, email info@wolfcore.co.uk. We respond within one month, and will tell you if we need longer.
10.5 If you are a member of staff on a Business account, send access and erasure requests to your employer, who is the controller. We will help them respond.
10.6 You can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first.
11. How long we keep things
| Data | Retained |
|---|---|
| Account, identities, findings | While your account is open |
| A deleted account or identity | Hidden immediately; permanently destroyed after 30 days |
| Consent records | With the identity they belong to; destroyed with it |
| Activity and audit records | For the life of the account; destroyed with it |
| Sign-in attempts and verification challenges | Purged automatically on a rolling basis |
| Domain verification proofs | Expire and are re-issued periodically |
| Billing and accounting records | 6 years after the end of the relationship, as UK tax law requires |
| Business account data | On the customer's instructions, per the DPA |
12. Children
12.1 Breachy is not for children. You must be 16 or over to hold an account, and a monitored dependant on a Family plan must be 16 or over.
12.2 If we learn that we hold data about someone under 16, we delete it.
13. Cookies
The apps and the portal set no cookies. See the Cookie Notice.
14. Marketing
We send service messages — exposure alerts, security notices, billing — because they are part of the service. Marketing email is separate, is opt-out at any time, and never contains your findings.
15. Automated decision-making
The Exposure Score is a calculation, not a decision about you. It is derived from the findings on your account and the steps you have completed, it is explained in the app, and nothing legal or similarly significant happens automatically as a result of it.
16. Changes to this policy
We may update this policy. Material changes will be notified by email or in-app notice before they take effect, and the version and date at the top will change.
17. Contact
info@wolfcore.co.uk · Wolfcore Ltd, 72 Newbiggin, Malton, North Yorkshire, YO17 7JF · Company no. 16308559 · ICO ZB977950