BREACHED — PRIVACY POLICY (GLOBAL)
Last Updated: July 5, 2026
Introduction
This Privacy Policy explains how Unleeshed Studios ("Company," "we," "our," or "us") collects, uses, stores, and protects information when you use the Breached mobile application ("App") and related services ("Services").
This Privacy Policy applies to users worldwide. Certain rights and protections vary depending on your jurisdiction. By using the App, you agree to the practices described here. If you do not agree, do not use the App.
How the App Works (Summary)
Breached lets you check where your own personal information may have been exposed online. You enter identifiers about yourself — such as your name, email address, username, phone number, city, or date of birth — and the App checks them against third-party data-breach databases and public-profile sources to produce a "scan report" showing where your information appears. Reports are compiled from third-party and public sources, may be inaccurate or incomplete, and are provided for informational purposes only. See Important Disclaimers below.
Information We Collect
No Account Required
The App does not require an account, login, name, or email to install or open. We do not create a persistent user profile or a personal user identifier for you. To prevent abuse of our backend, the App uses Apple's App Attest (via Firebase App Check) to confirm that requests come from a genuine, unmodified copy of the App — this attestation contains no personal information and is not linked to your identity.
Information You Provide
To run a scan, you may enter identifiers about yourself, such as:
• Your name and identity details (such as approximate age or date of birth, gender, city, or username/handle)
• Your email address and/or phone number
This information is used only to perform your scan and is not stored on our servers (see Data Retention).
Locally Stored History
Scan reports you generate are stored locally on your device only, in the App's private storage. We do not upload or retain your report history on our servers.
Usage and Analytics Data
To understand how the App is used and to improve it, we use Google Firebase Analytics. Firebase Analytics collects pseudonymous product-usage information such as: which screens you view, in-app events and actions (for example, completing onboarding, starting a scan, viewing the subscription screen, or subscribing), session and engagement data, app version, device model, operating system version, general device settings, and a random, app-generated analytics instance identifier. Firebase may also derive a coarse, approximate location (such as country or region) from your IP address. This is used for aggregate, statistical analytics only.
We do not send the name, identity details, email, phone number, scan inputs, or report contents to analytics as event data. Analytics data is not used to advertise to you, is not sold, and is not combined with third-party data to track you across other companies' apps or websites. The App does not use the Advertising Identifier (IDFA) and does not request App Tracking Transparency permission.
Automatically Collected Information
When the App contacts our backend, our infrastructure providers (Google Firebase / Google Cloud) may process limited technical data inherent to any network request, including IP address, device model, operating system version, and timestamps, for security, abuse prevention, and operational reliability.
Subscription information is handled through Apple StoreKit. We do not receive or store your payment card details.
Information We Do Not Collect
We do not collect:
• Account credentials or passwords
• The Advertising Identifier (IDFA) or other advertising identifiers
• Precise location data
• Contacts, photos, or messages
• Cross-app or cross-site tracking data for advertising
How Your Scan Works
To generate a report, the identifiers you enter are checked against the following third-party breach databases and public-data sources. Each provider receives only the specific input needed to perform its lookup — never your analytics data, device information, or subscription details:
• Have I Been Pwned — your email address is sent, through our secure backend, to check whether it appears in known data breaches.
• LeakCheck — your email address is sent, through our secure backend, to a leaked-credential index. This returns the names of breach sources and the types of data fields exposed (for example, "email," "password," "address") — never the actual leaked values.
• Gravatar — your email address is converted to a one-way SHA-256 hash on your device; only the hash is sent, to find a public profile photo, name, or bio you may have published. Your raw email is not sent to Gravatar.
• GitHub (public API) — your email address is used to find a public GitHub account you may have associated with it.
Password-strength and password-breach checks, where offered, use k-anonymity: only the first five characters of an irreversible hash of the password leave your device, and the full password is never transmitted.
Results are compiled from these third-party and public sources. They may be inaccurate, incomplete, or out of date and are provided for informational purposes only. Your data is not used to train AI models.
How We Use Information
We use information to:
• Operate, maintain, and secure the App
• Generate your scan reports
• Prevent abuse of our service
• Process subscriptions through Apple
• Understand usage and improve the App's features, performance, and reliability (via aggregate analytics)
We do not sell your data, share data with advertisers, or use your data to train AI models.
Data Sharing
We share information only with essential service providers:
• Have I Been Pwned — data-breach lookups (your email address only)
• LeakCheck — leaked-credential index lookups (your email address only)
• Gravatar (Automattic) — public-profile lookups (a hash of your email address only)
• GitHub — public-account lookups (your email address only)
• Google Firebase / Google Cloud — backend functions, abuse prevention (App Check), and product analytics (Firebase Analytics)
• Apple StoreKit — payments and subscriptions
We may also disclose information where required by law, to protect our rights, users, or the public, or in connection with a merger, acquisition, or sale of assets.
Data Retention
The identifiers you provide to run a scan are processed transiently and are not retained on our servers after the report is produced. Report history is stored only locally on your device and is deleted when you delete the App or clear it within the App. Our backend retains limited, automatically generated technical logs for a limited period for security and operations. Aggregate analytics data is retained by Google Firebase for a limited retention period in accordance with our analytics configuration and Google's policies.
Responsible Use
Breached is designed for checking your own exposure. When you enter identifiers, you represent that you are entitled to check that information and are using the App lawfully. The App must not be used to investigate, monitor, harass, stalk, or contact any other person, or for any unlawful purpose. You are solely responsible for the information you input and for how you use the output.
Security
We use industry-standard safeguards, including encryption in transit (TLS), server-side secrets management, app attestation (Apple App Attest via Firebase App Check), and restricted access controls. No method of transmission or storage is completely secure, but we apply reasonable protections.
International Privacy Rights
If you are located in the European Economic Area (EEA), United Kingdom, Switzerland, Canada, Australia, Brazil, or a U.S. state with applicable privacy laws (including California under the CCPA/CPRA), you may have rights to access, correct, delete, restrict, or obtain a copy of your personal data, and to object to certain processing.
Because the App operates without an account and does not retain your inputs on our servers, much of the data described here exists only on your own device and can be removed by deleting your history or uninstalling the App. Analytics data is pseudonymous and aggregate; you can further limit it by deleting the App. For any request regarding data we may hold, contact us using the information below.
Your data may be transferred to and processed in the United States, with appropriate safeguards where required by law. California residents may exercise CCPA/CPRA rights (including the right to know, delete, and non-discrimination); we do not sell or share personal information for cross-context behavioral advertising.
Children's Privacy
The App is intended for users 17 and older and is not directed to children. We do not knowingly collect personal information from children under 13. If we learn that such information has been collected, we will delete it promptly.
Important Disclaimers
• Informational only. Reports are compiled from third-party breach databases and publicly available sources. They may be inaccurate, incomplete, or entirely wrong, and are provided for informational purposes. They are not a guarantee about the security of any account and should not be relied upon as your sole security measure.
• Not professional advice. The App does not provide legal, financial, or security-professional advice, and does not remove your information from any breach or data broker on your behalf.
• Accuracy. We do not guarantee the accuracy, completeness, or currency of any information surfaced or generated, and we are not responsible for how you use it.
• Your responsibility. You are solely responsible for complying with all applicable laws when using the App.
Data Breach Notification
If a breach occurs affecting personal information, we will notify affected users and regulators as required by applicable law.
Changes to This Policy
We may update this Privacy Policy periodically. The "Last Updated" date reflects the most recent version. Continued use of the App after changes constitutes acceptance of the updated policy.
Contact Us
Unleeshed Studios
Atlanta, GA
United States
Email: unleeshedstudios@gmail.com
© 2026 Unleeshed Studios. All rights reserved.