Last updated: February 18, 2026
Welcome to leaksear.ch, a data breach search engine. By using our service, you ("User") accept and agree to the following terms and conditions ("Terms of Service"). These Terms of Service govern your access to and use of the service. If you are accepting on behalf of an employer or other entity, you represent and warrant that you have the appropriate legal authority to bind that entity to these terms.
By registering for an account, you agree that you have read, understood, and accept all of the terms and conditions contained in this agreement, including, but not limited to, the Privacy Policy below. Please thoroughly review this document prior to agreeing.
leaksear.ch maintains internal policies regarding data acquisition to ensure that all indexed data corresponds to known, reported security incidents. Specifically:
These policies are designed to ensure that leaksear.ch operates as a defensive security tool rather than a vehicle for further dissemination of improperly obtained data.
This section addresses our legal basis for processing breach records specifically, separate from the processing of user account data (which is addressed in the Privacy Policy below).
leaksear.ch processes breach records under the legitimate interest basis provided by GDPR Article 6(1)(f). Our legitimate interests are:
We have conducted a Legitimate Interest Assessment (LIA) balancing these interests against the privacy rights of data subjects. We have determined that our processing is proportionate given the following safeguards:
The full LIA is maintained as an internal document and is available to data protection authorities upon request.
The data processed by leaksear.ch originates from security incidents where it has already been compromised and is circulating among threat actors. The marginal privacy impact of indexing this data in a controlled, access-gated platform is low compared to the security benefit of enabling victims to discover and remediate their exposure. Without services like leaksear.ch, this data remains accessible primarily to malicious actors while victims remain unaware. The removal process, access controls, and abuse monitoring further reduce the impact on data subjects.
You may not use leaksear.ch or any information acquired from leaksear.ch:
leaksear.ch is intended solely for security research, breach notification, personal data awareness, and other lawful purposes. Violations of this Acceptable Use Policy may result in immediate account termination without refund, and may be reported to the appropriate law enforcement authorities.
By opening an account, you expressly represent and warrant that you are at least 18 years of age and accept the terms and conditions as set forth in this agreement.
Refund requests are handled on a case-by-case basis. To request a refund, please contact support. Refunds may take 3-7 business days depending on your payment provider.
You may delete your account at any time through the account settings. Upon deletion, your account and all associated data will be permanently removed and you will no longer be able to log in. Your email address will be released for re-registration.
leaksear.ch may amend these terms from time to time. Notification of any material changes will be made via the website or email. Continued use of the service after changes are posted constitutes acceptance of the modified terms.
Your access and use of leaksear.ch is subject to the laws, regulations, and rules of any applicable governmental or regulatory authority. If your country of residence is within the European Economic Area, the General Data Protection Regulation will govern your privacy concerns as they relate to this agreement.
This agreement shall be governed by the laws of the State of Delaware, United States, without regard to conflict of laws principles. The United Nations Convention on the International Sale of Goods does not apply.
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED.
To the extent permitted by law, leaksear.ch shall have no liability relating to your use of the service for:
leaksear.ch reserves the right, at any time, to amend, modify, suspend, or terminate the service, any information or content, or any part thereof, and/or your use of or access to them, with or without notice.
You agree to defend, indemnify, and hold leaksear.ch, its officers, directors, employees, agents, licensors, and suppliers harmless from and against any claims, actions or demands, liabilities, and settlements including reasonable legal and related fees and expenses, resulting from or alleged to result from your violation of these Terms or your use of the service.
This agreement constitutes the entire agreement between the parties concerning the use of leaksear.ch and supersedes all prior communications, contracts, or agreements. If any provision of this agreement is adjudged by any court or arbitrator to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary to allow for the remainder to remain in full force and effect.
leaksear.ch is committed to the protection of your private information. We adhere to the requirements of the California Consumer Privacy Act (CCPA), the Fair Credit Reporting Act (FCRA), and the Personal Information Protection and Electronic Documents Act (PIPEDA). Additionally, we abide by the requirements of the European Union General Data Protection Regulation (GDPR), as well as other relevant rules, regulations, and laws.
This Privacy Policy explains how we collect, use, and store information about you. Any form of the word "we" in this Privacy Policy refers to leaksear.ch. If you have any questions or find any part of this Privacy Policy unclear, please contact us at the address provided below.
leaksear.ch is responsible for protecting your private data and information. You can reach us at [email protected].
We collect, use, and store the following information only as necessary to:
The information we collect includes: email address, password (hashed), name, and billing information processed by our payment provider. We do not store full payment card details.
You must provide us with the information necessary to deliver our services. If you do not provide this information, we may not be able to provide all offered services.
We obtain your information from:
We share information about you with other entities only where needed for the reasons listed above and permitted by applicable laws. We do not sell your personal information.
We will store your information for 5 years after termination of your account, unless otherwise required by law. If your data may legally be disposed of prior to then, you will be notified. Active account data is stored for the duration of your use of the service within the legal guidelines of this policy.
You may contact us to:
Please note that these rights are subject to conditions and exemptions established by law. To exercise any of these rights, contact us at [email protected].
If you are a resident of the European Economic Area (EEA), the General Data Protection Regulation (GDPR) provides you with specific rights regarding your personal data. leaksear.ch acts as a data controller for both account data and breach records indexed from publicly reported security incidents. Our legal basis for processing breach records is described in the "Legal Basis for Processing Breach Data" section of the Terms of Service above.
Your rights under the GDPR include:
To exercise any of these rights, contact us at [email protected] with the subject line "GDPR Request". We will respond within 30 days of receipt. If we need additional time (up to 60 additional days for complex requests), we will notify you of the extension and the reasons for it.
If your personal information appears in breach records indexed by leaksear.ch, you have the right to request its removal. This applies regardless of whether you have an account with us. You do not need to be a registered user or a resident of any specific jurisdiction to submit a removal request, though we are legally obligated to honor requests from EEA residents under the GDPR Right to Erasure.
All data removal requests must be submitted through our online data removal form. The form will ask you to provide:
leaksear.ch may amend this policy from time to time. Notification of any material changes will be made via the website. You are entitled to withdraw your consent regarding the collection of your data at any time, as long as such consent is not required to provide you with requested services and products.
leaksear.ch may notify users of data breaches, either internal or external, per legal requirements. Email notification will be made within 72 hours if the breach involves sensitive personal data. Additionally, users will be notified via email when the breach is resolved.
If you have any questions about these terms or our privacy practices, please contact us at [email protected].