pwned? app Privacy Policy

Last updated: 20 Oct 2025

1. Who we are

pwned? is an open-source iOS/Android application developed and maintained by Daniel Leightley. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Daniel Leightley is the data controller.

Contact: [email protected]


2. What information we process

Category Examples Stored?
Breach-check data E-mail address you enter (transformed to a hash prefix for a k-anonymity range search) Never stored by us – sent over HTTPS to haveibeenpwned.com and immediately discarded by the app
App diagnostics IP address, device model, OS version, timestamps, crash traces Not collected by us

No special-category data are collected.


Purpose Legal basis (UK GDPR)
Checking whether your e-mail appears in a published breach Consent – you choose to submit the address
Delivering and securing the app (e.g., preventing abuse) Legitimate interests – keeping the service reliable and secure

4. How we share data

  • Your breach-check is performed by sending a hashed-range query to Have I Been Pwned (haveibeenpwned.com, Australia).
  • We do not send your data to analytics, advertising, crash reporting, or CDN caching providers.
  • Third parties you interact with (e.g., Have I Been Pwned) process data under their own terms and privacy notices.

5. International transfers

Your hashed-range query is sent to Have I Been Pwned’s service hosted outside the UK (Australia). Data are protected in transit with TLS and we do not store breach-check data on our servers. Have I Been Pwned’s handling of data is governed by their own privacy notice.


6. Data retention

  • Breach-check requests: not stored by us
  • Analytics and crash logs: not collected
  • Back-ups: we do not back up breach-check data (support e-mails you send us may be retained as required to respond)

7. Security measures

  • TLS for all network traffic from the app to Have I Been Pwned
  • Minimal data handling (no server-side storage by us)
  • Least-privilege access to any administrative systems

No method of electronic transmission or storage is completely secure.


8. Your rights

You may request at any time:

  1. Access to personal data we hold about you
  2. Rectification of inaccurate data
  3. Erasure
  4. Restriction of processing
  5. Data portability
  6. Objection to processing based on legitimate interests

To exercise any right, e-mail [email protected]. You may also lodge a complaint with the UK Information Commissioner’s Office.


9. Cookies

The app sets no first-party cookies. Have I Been Pwned and platform providers (e.g., your mobile OS or app store) may process data under their own policies:

You can adjust permissions in your device settings.


The app may show links to external websites not operated by us. We are not responsible for their content or privacy practices.


11. Children

pwned? is not directed at children under 13 and we do not knowingly process their personal data. If you believe a child has provided data, please contact us and we will delete it promptly.


12. Changes to this policy

We may update this notice from time to time. Changes will appear in-app and on the GitHub repository. Material changes will be highlighted 14 days before they take effect.


13. Contact

Questions, concerns, or requests?
E-mail: [email protected]