Privacy by design.
DataBreachHelp is designed to help people understand breach information without asking for passwords, financial credentials, or raw stolen data.
Email breach checks
Supported breach lookups are sent server-side so provider credentials are not exposed in the browser. We store the email address you submit, along with the search time, completion status, provider, and number of matches, in our private application records. Search values are not included in site analytics events.
Contact and eligibility intake
We store the contact details, breach-notice answers, notes, and documents you submit for evaluation, together with the submission time and consent version. On AWS, search and intake records are stored in DynamoDB and uploaded documents in a private S3 bucket. These records are separate from site analytics.
Site analytics
We use first-party analytics to understand page views, traffic sources, navigation clicks, breach-check activity, and intake funnel performance. Analytics events are designed not to include names, email addresses, phone numbers, intake notes, uploaded documents, or breach-search values. Campaign parameters and referring domains may be recorded for attribution. If Google Analytics is configured, the same privacy-safe event names may also be sent there.
What we do not need
Do not submit passwords, Social Security numbers, bank credentials, payment card numbers, or copies of raw leaked records through this site.
Third-party breach information
Breach catalogue information may be sourced from third-party providers and public reporting. A breach record can contain categories of data associated with an incident; it does not prove that every category applies to every person.
Ownership and contact
Data Breach Help owns and operates databreachhelp.org. Privacy questions can be sent to support@databreachhelp.com. See our About page for more information about the site.