leaksear.chleaksear.ch
Data WellsPricingBlogFAQSupportDashboard
leaksear.chleaksear.ch

Breach data search engine. Billions of records, millisecond results.

Terms of Service & Privacy Policy

Product

  • Data Wells
  • Search
  • Pricing
  • API Docs
  • MCP Integration

Company

  • About
  • Blog
  • RSS Feed
  • Data Removal
  • FAQ
  • Support
© 2026 leaksear.ch. All rights reserved.

Legal Documentation

Last updated: February 18, 2026

Quick Navigation

Terms of Service

  • Preamble
  • General Provisions
  • Data Sourcing Policy
  • Legal Basis for Processing
  • Acceptable Use
  • Accounts & Billing
  • Governing Law
  • Warranties & Liability
  • Entire Agreement

Privacy Policy

  • Overview
  • Information We Collect
  • Cookies
  • Information Sharing
  • Data Retention
  • Your Rights
  • GDPR Rights
  • Data Removal Requests
  • Data Breach Policy

Terms of Service

Preamble

Welcome to leaksear.ch, a data breach search engine. By using our service, you ("User") accept and agree to the following terms and conditions ("Terms of Service"). These Terms of Service govern your access to and use of the service. If you are accepting on behalf of an employer or other entity, you represent and warrant that you have the appropriate legal authority to bind that entity to these terms.

By registering for an account, you agree that you have read, understood, and accept all of the terms and conditions contained in this agreement, including, but not limited to, the Privacy Policy below. Please thoroughly review this document prior to agreeing.

General Provisions

  • Any violation of these Terms of Service will result in immediate account closure without compensation.
  • You may only use the service as it was intended to be used.
  • By registering, purchasing, or using our service, you agree to these Terms of Service.
  • leaksear.ch indexes records from security incidents that have been publicly reported and widely disseminated. We do not solicit, commission, or directly obtain data through unauthorized access to any system. Our service exists to help individuals and organizations determine whether their information has been exposed in known security incidents and to take appropriate protective action. leaksear.ch does not verify or evaluate each piece of data and makes no warranties or guarantees about any of the information offered. leaksear.ch does not intentionally possess or have access to secure or private financial information. leaksear.ch is not a credit reporting agency and does not offer consumer reports.
  • None of the information offered by leaksear.ch is to be considered for purposes of determining any entity or person's eligibility for credit, insurance, employment, or housing.
  • Using the site and its services is at your own risk and responsibility. leaksear.ch does not hold any responsibility for any damage that might occur due to the usage of our services. By using our services you take full responsibility for your actions.
  • Terms of Service may be changed or modified at any given time without notice.
  • You may not abuse or misuse this service in any way.

Data Sourcing Policy

leaksear.ch maintains internal policies regarding data acquisition to ensure that all indexed data corresponds to known, reported security incidents. Specifically:

  • We do not accept submissions from anonymous or unverifiable sources.
  • We do not purchase data from threat actors or other unauthorized parties.
  • We do not index data from incidents that have not been publicly reported by credible sources.
  • DataWells (indexed breach datasets) are reviewed before ingestion to ensure they correspond to known, reported security incidents.

These policies are designed to ensure that leaksear.ch operates as a defensive security tool rather than a vehicle for further dissemination of improperly obtained data.

Legal Basis for Processing Breach Data

This section addresses our legal basis for processing breach records specifically, separate from the processing of user account data (which is addressed in the Privacy Policy below).

Lawful Basis

leaksear.ch processes breach records under the legitimate interest basis provided by GDPR Article 6(1)(f). Our legitimate interests are:

  • Enabling individuals to discover whether their personal information has been compromised in security incidents.
  • Enabling organizations to assess credential exposure across their domains and protect their users.
  • Supporting cybersecurity research and incident response.
  • Contributing to the broader security ecosystem by making breach exposure discoverable rather than exploitable only by malicious actors.

Legitimate Interest Assessment

We have conducted a Legitimate Interest Assessment (LIA) balancing these interests against the privacy rights of data subjects. We have determined that our processing is proportionate given the following safeguards:

  • Data subject removal — Removal requests are honored for all individuals regardless of jurisdiction. See Section 10a of the Privacy Policy below for the full process.
  • Access controls — Breach records are access-controlled behind authentication and a credit system rather than freely browsable or bulk-downloadable.
  • Acceptable use enforcement — Our Acceptable Use Policy prohibits misuse including credential stuffing, identity theft, harassment, and unauthorized resale.
  • Abuse monitoring — We actively monitor for and terminate abusive usage patterns.

The full LIA is maintained as an internal document and is available to data protection authorities upon request.

Balancing Test Summary

The data processed by leaksear.ch originates from security incidents where it has already been compromised and is circulating among threat actors. The marginal privacy impact of indexing this data in a controlled, access-gated platform is low compared to the security benefit of enabling victims to discover and remediate their exposure. Without services like leaksear.ch, this data remains accessible primarily to malicious actors while victims remain unaware. The removal process, access controls, and abuse monitoring further reduce the impact on data subjects.

Acceptable Use

You may not use leaksear.ch or any information acquired from leaksear.ch:

  • To engage in activities that would violate applicable local, state, national, or international law, or any regulations having the force of law.
  • To make any phone call or send any email or text message that does not comply with CAN-SPAM, the Telephone Consumer Protection Act, or any other applicable federal or state law.
  • To evaluate a consumer's eligibility for credit or insurance, employment, government licenses or benefits, renting a dwelling, or for any other purpose specified in the Fair Credit Reporting Act (FCRA), Federal Trade Commission or court interpretations of the FCRA, or similar state statutes.
  • In any manner that may violate any local, state, federal, or international privacy law to which you may be subject based on your location or the location of the person searched.
  • To harass, stalk, threaten, or otherwise target any individual using data obtained from this service.
  • To attempt unauthorized access to any account, system, or network, including but not limited to credential stuffing, password spraying, brute-force attacks, or testing stolen credentials against third-party services.
  • To facilitate identity theft, fraud, social engineering, phishing, or any form of impersonation using information obtained from this service.
  • To distribute, sell, or re-sell data obtained from this service without express written permission.
  • To attempt to reverse-engineer, scrape, or programmatically extract data from this service beyond the documented API.
  • To compile data obtained from this service into datasets for the purpose of building competing services or products.
  • To circumvent, disable, or interfere with security-related features of the service, including rate limiting, authentication mechanisms, or access controls.

leaksear.ch is intended solely for security research, breach notification, personal data awareness, and other lawful purposes. Violations of this Acceptable Use Policy may result in immediate account termination without refund, and may be reported to the appropriate law enforcement authorities.

Accounts & Billing

Registration

By opening an account, you expressly represent and warrant that you are at least 18 years of age and accept the terms and conditions as set forth in this agreement.

Credits & Subscriptions

  • Search results are unlocked using credits. One credit unlocks the full results of a single search query, regardless of the number of results.
  • Credits persist on subscription cancellation and are not revoked.
  • Searches returning zero results do not consume credits.

Refunds

Refund requests are handled on a case-by-case basis. To request a refund, please contact support. Refunds may take 3-7 business days depending on your payment provider.

Account Deletion

You may delete your account at any time through the account settings. Upon deletion, your account and all associated data will be permanently removed and you will no longer be able to log in. Your email address will be released for re-registration.

Updates

leaksear.ch may amend these terms from time to time. Notification of any material changes will be made via the website or email. Continued use of the service after changes are posted constitutes acceptance of the modified terms.

Governing Law

Your access and use of leaksear.ch is subject to the laws, regulations, and rules of any applicable governmental or regulatory authority. If your country of residence is within the European Economic Area, the General Data Protection Regulation will govern your privacy concerns as they relate to this agreement.

This agreement shall be governed by the laws of the State of Delaware, United States, without regard to conflict of laws principles. The United Nations Convention on the International Sale of Goods does not apply.

Warranties & Liability

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED.

To the extent permitted by law, leaksear.ch shall have no liability relating to your use of the service for:

  • Consequential, incidental, exemplary, special, or punitive damages, even if advised of the possibility of such.
  • Loss of business, profits, business information, or business interruption, or any other pecuniary loss.
  • Direct damages, actually proven, exceeding $100.00 USD.

leaksear.ch reserves the right, at any time, to amend, modify, suspend, or terminate the service, any information or content, or any part thereof, and/or your use of or access to them, with or without notice.

You agree to defend, indemnify, and hold leaksear.ch, its officers, directors, employees, agents, licensors, and suppliers harmless from and against any claims, actions or demands, liabilities, and settlements including reasonable legal and related fees and expenses, resulting from or alleged to result from your violation of these Terms or your use of the service.

Entire Agreement

This agreement constitutes the entire agreement between the parties concerning the use of leaksear.ch and supersedes all prior communications, contracts, or agreements. If any provision of this agreement is adjudged by any court or arbitrator to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary to allow for the remainder to remain in full force and effect.

Privacy Policy

leaksear.ch is committed to the protection of your private information. We adhere to the requirements of the California Consumer Privacy Act (CCPA), the Fair Credit Reporting Act (FCRA), and the Personal Information Protection and Electronic Documents Act (PIPEDA). Additionally, we abide by the requirements of the European Union General Data Protection Regulation (GDPR), as well as other relevant rules, regulations, and laws.

1. Overview

This Privacy Policy explains how we collect, use, and store information about you. Any form of the word "we" in this Privacy Policy refers to leaksear.ch. If you have any questions or find any part of this Privacy Policy unclear, please contact us at the address provided below.

2. Who Is Responsible for Protecting My Information?

leaksear.ch is responsible for protecting your private data and information. You can reach us at [email protected].

3. Information We Collect

We collect, use, and store the following information only as necessary to:

  • Provide you with leaksear.ch services
  • Conduct the day-to-day operation and maintenance of accounts
  • Process requests for information
  • Comply with regulatory and legal obligations
  • Investigate suspicious activity
  • Ensure security of the website
  • Manage and improve our website and services
  • Protect leaksear.ch's rights and property

The information we collect includes: email address, password (hashed), name, and billing information processed by our payment provider. We do not store full payment card details.

4. Cookies

leaksear.ch uses essential cookies only for session management and authentication. We do not use tracking cookies or third-party analytics cookies.

5. Required Information

You must provide us with the information necessary to deliver our services. If you do not provide this information, we may not be able to provide all offered services.

6. Where We Get Your Information

We obtain your information from:

  • Directly from you (registration, account settings)
  • Payment processors (billing information)

7. Information Sharing

We share information about you with other entities only where needed for the reasons listed above and permitted by applicable laws. We do not sell your personal information.

8. Data Retention

We will store your information for 5 years after termination of your account, unless otherwise required by law. If your data may legally be disposed of prior to then, you will be notified. Active account data is stored for the duration of your use of the service within the legal guidelines of this policy.

9. Your Rights

You may contact us to:

  • Request that we share information we have about you
  • Request that we correct information we have about you
  • Request that we delete your information
  • Request that we restrict use or deletion of your information
  • Object to the collection, use, and storage of your information
  • Request that we export your data or transfer it to another service
  • Withdraw any consent you have given us

Please note that these rights are subject to conditions and exemptions established by law. To exercise any of these rights, contact us at [email protected].

10. Individual Rights for European Economic Area Residents (GDPR)

If you are a resident of the European Economic Area (EEA), the General Data Protection Regulation (GDPR) provides you with specific rights regarding your personal data. leaksear.ch acts as a data controller for both account data and breach records indexed from publicly reported security incidents. Our legal basis for processing breach records is described in the "Legal Basis for Processing Breach Data" section of the Terms of Service above.

Your rights under the GDPR include:

  • Right of Access (Art. 15) — You may request confirmation of whether we process personal data concerning you and, if so, request a copy of that data.
  • Right to Rectification (Art. 16) — You may request correction of inaccurate personal data or completion of incomplete data.
  • Right to Erasure (Art. 17) — You may request deletion of your personal data. See Section 10a below for the specific process for breach record removal.
  • Right to Restriction of Processing (Art. 18) — You may request that we restrict the processing of your data under certain circumstances.
  • Right to Object (Art. 21) — You may object to the processing of your personal data at any time.
  • Right to Data Portability (Art. 20) — You may request to receive your data in a structured, commonly used, and machine-readable format.
  • Right to Lodge a Complaint — You have the right to lodge a complaint with a supervisory authority in your country of residence.

To exercise any of these rights, contact us at [email protected] with the subject line "GDPR Request". We will respond within 30 days of receipt. If we need additional time (up to 60 additional days for complex requests), we will notify you of the extension and the reasons for it.

10a. Data Subject Removal Requests (Breach Record Takedown)

If your personal information appears in breach records indexed by leaksear.ch, you have the right to request its removal. This applies regardless of whether you have an account with us. You do not need to be a registered user or a resident of any specific jurisdiction to submit a removal request, though we are legally obligated to honor requests from EEA residents under the GDPR Right to Erasure.

How to Submit a Removal Request

All data removal requests must be submitted through our online data removal form. The form will ask you to provide:

  • A contact email address where we can reach you with updates.
  • The email address(es) or other identifying information you want removed from breach records.
  • A brief reason for your removal request (e.g. you are the data subject, or are authorized to act on their behalf).

What Happens After You Submit

  • Acknowledgment — We will confirm receipt of your request within 5 business days.
  • Verification — We may ask you to verify your identity to prevent unauthorized removal of third-party data. This typically involves confirming ownership of the email address(es) in question.
  • Processing — Once verified, we will remove or suppress the matching records from our search index within 30 days.
  • Confirmation — You will receive an email confirming the removal has been completed.

Scope and Limitations

  • Removal applies only to data indexed by leaksear.ch. We cannot remove data from the original breach source, other third-party services, or any publicly available copies of the data.
  • We may retain a hashed record of removed identifiers solely to prevent re-indexing of the same data in the future.
  • Requests that are manifestly unfounded, excessive, or intended to obstruct legitimate security research may be declined with an explanation.

11. Updates

leaksear.ch may amend this policy from time to time. Notification of any material changes will be made via the website. You are entitled to withdraw your consent regarding the collection of your data at any time, as long as such consent is not required to provide you with requested services and products.

12. Data Breach Policy

leaksear.ch may notify users of data breaches, either internal or external, per legal requirements. Email notification will be made within 72 hours if the breach involves sensitive personal data. Additionally, users will be notified via email when the breach is resolved.

Contact Us

If you have any questions about these terms or our privacy practices, please contact us at [email protected].