Last updated: 20 Oct 2025
1. Who we are
pwned? is an open-source iOS/Android application developed and maintained by Daniel Leightley. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Daniel Leightley is the data controller.
Contact: [email protected]
2. What information we process
| Category | Examples | Stored? |
|---|---|---|
| Breach-check data | E-mail address you enter (transformed to a hash prefix for a k-anonymity range search) | Never stored by us – sent over HTTPS to haveibeenpwned.com and immediately discarded by the app |
| App diagnostics | IP address, device model, OS version, timestamps, crash traces | Not collected by us |
No special-category data are collected.
3. Why we use your information (legal bases)
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Checking whether your e-mail appears in a published breach | Consent – you choose to submit the address |
| Delivering and securing the app (e.g., preventing abuse) | Legitimate interests – keeping the service reliable and secure |
4. How we share data
- Your breach-check is performed by sending a hashed-range query to Have I Been Pwned (haveibeenpwned.com, Australia).
- We do not send your data to analytics, advertising, crash reporting, or CDN caching providers.
- Third parties you interact with (e.g., Have I Been Pwned) process data under their own terms and privacy notices.
5. International transfers
Your hashed-range query is sent to Have I Been Pwned’s service hosted outside the UK (Australia). Data are protected in transit with TLS and we do not store breach-check data on our servers. Have I Been Pwned’s handling of data is governed by their own privacy notice.
6. Data retention
- Breach-check requests: not stored by us
- Analytics and crash logs: not collected
- Back-ups: we do not back up breach-check data (support e-mails you send us may be retained as required to respond)
7. Security measures
- TLS for all network traffic from the app to Have I Been Pwned
- Minimal data handling (no server-side storage by us)
- Least-privilege access to any administrative systems
No method of electronic transmission or storage is completely secure.
8. Your rights
You may request at any time:
- Access to personal data we hold about you
- Rectification of inaccurate data
- Erasure
- Restriction of processing
- Data portability
- Objection to processing based on legitimate interests
To exercise any right, e-mail [email protected]. You may also lodge a complaint with the UK Information Commissioner’s Office.
9. Cookies
The app sets no first-party cookies. Have I Been Pwned and platform providers (e.g., your mobile OS or app store) may process data under their own policies:
- Have I Been Pwned: https://haveibeenpwned.com/Privacy
You can adjust permissions in your device settings.
10. Links to other sites
The app may show links to external websites not operated by us. We are not responsible for their content or privacy practices.
11. Children
pwned? is not directed at children under 13 and we do not knowingly process their personal data. If you believe a child has provided data, please contact us and we will delete it promptly.
12. Changes to this policy
We may update this notice from time to time. Changes will appear in-app and on the GitHub repository. Material changes will be highlighted 14 days before they take effect.
13. Contact
Questions, concerns, or requests?
E-mail: [email protected]