Legal Document

Privacy Policy

Last Updated: March 8, 2026

Our Commitment to Privacy

At Leaksyr, we believe in privacy as a fundamental right. This policy outlines how we handle your information with the utmost care and security. We collect only what is necessary to provide you with a seamless and secure experience. We're committed to being transparent — no hidden surprises, no confusing legal jargon.

01. Why We Process Data

We process personal data based on clear and legitimate grounds. Here's a simple breakdown:

Legitimate Interest We have a genuine interest in providing cybersecurity intelligence and breach detection services. These tools are designed to help security professionals, researchers, and individuals protect themselves.
Public Interest Our services support important societal goals — from helping law enforcement investigate cybercrime to enabling individuals to check if their own data has been exposed in a breach.
Contract Performance When you sign up, we process data to fulfill our agreement with you — managing your account, delivering services, and processing payments.
Your Consent For optional things like marketing emails, we only act with your explicit permission — and you can withdraw it anytime, no questions asked.

💡 What Leaksyr Does Leaksyr provides a breach-intelligence search service: it indexes credentials and related records that infostealer malware has already exposed and that third parties have already distributed. We do not create, commission, purchase or facilitate any breach, and we do not accept data submissions. Section 06 explains how people whose data appears in the index can have it removed.

02. Information We Collect

Account Essentials Basic details like username, email, and profile info. Your account password is cryptographically hashed and never stored in plain text.
Service Data The technical and usage data needed to run the service safely: connection details such as your IP address, browser and device type and approximate location, the page that referred you, and the activity carried out from your account (searches, exports and API use). We use it to operate the service, understand how it is used and prevent abuse.
Payment Info Handled by regulated third-parties. We do not store or access full credit card or banking details on our servers.

03. How We Use Your Information

We use collected information to operate, maintain, and improve our services. Here's what that looks like in practice:

  • Provide and deliver the services you've requested
  • Optimize platform performance and safeguard security
  • Analyze usage trends to improve and innovate our product
  • Send service-related communications and security alerts
  • Prevent abuse, fraud, and unauthorized access
  • Comply with legal obligations when required by law
  • Support business continuity and operational scaling

04. Third-Party Services

We work with trusted third-party providers to deliver the best experience. Here's what you should know:

Payment Processing Payments are handled by regulated payment processors. We never store your credit card numbers, bank account details, or crypto wallet info on our servers.
Bot Protection We use Cloudflare Turnstile on registration and login to block automated abuse. Cloudflare processes connection data under its own privacy policy.
Server Logs Like any web service we keep standard application and security logs (request metadata and timestamps) so that the platform runs reliably and abuse can be investigated.
Hosting & Infrastructure Our platform is hosted on servers located in the European Union. Connections to the platform are encrypted in transit.

All third-party service providers are selected based on their security standards.

05. Data Security

Security is at the core of everything we do. Here's how we protect your data:

Encryption All data transmission is encrypted using TLS.
Password Hashing Your Leaksyr account password is stored as a salted PBKDF2-SHA256 hash and never in plain text. This applies to your account only: credentials contained in indexed infostealer logs are stored as they were exposed, and Section 06 explains how to have them removed.
Access Controls Strict access controls limit data access to authorized personnel only. We implement CSRF protection and rate limiting against abuse.
Monitoring Regular security monitoring, audit logs, and vulnerability assessments help us detect and respond to threats promptly.

No system is 100% bulletproof. While we implement commercially reasonable security measures, we can't guarantee absolute security against every possible threat. But we constantly work to stay ahead.

06. Removal Requests (Right to Erasure)

If data about you appears in Leaksyr's index, you can ask us to remove it. You do not need an institutional or corporate email address: requests from any email address, including personal ones, are accepted. To prevent abuse we only verify that the request comes from the person the data concerns, or from an organisation acting for a domain it controls.

  • Individuals: email [email protected] and tell us which email addresses or usernames the request concerns. If you write from a different address, we will send a confirmation link to the affected address. Never send us passwords.
  • Organisations: requests concerning a domain you control can be sent from an address at that domain, or with other proof of control such as a DNS record.
  • We respond within one month. For complex or numerous requests this may be extended by up to two further months; we will tell you if that is the case.
  • Removed records are taken out of search results, exports and the API.
  • We may decline a request where the law requires us to keep the data or where an overriding public interest applies, for example an ongoing incident investigation by the affected organisation. We explain our decision, and you may lodge a complaint with a data protection supervisory authority.

Removal requests are free of charge and do not require a Leaksyr account.

07. Data Retention & Cookies

We practice data minimization. Your personal information is retained only for as long as your account is active or as needed to provide you services, comply with our legal obligations, resolve disputes, and enforce our agreements. Once data is no longer needed, it is securely deleted or anonymized.

Cookies We use essential cookies necessary for the secure operation of the site (such as keeping you logged in). You can control cookie preferences directly through your browser settings.

Account Data Your account data is kept while your account is active. If you delete your account, your personal data is permanently removed from our systems.

08. Your Rights

You have full control over your data. Here are your rights — no fine print, no tricks:

Access You can request a copy of any personal data we hold about you.
Correction You can ask us to correct any inaccurate or incomplete data about you.
Deletion You can request deletion of your account and personal data by contacting us.
Restrict Processing In certain cases, you can ask us to pause or limit how we process your data.
Data Portability Get your data in a structured, commonly used format to transfer to another service.
Withdraw Consent Where we rely on your consent, you can withdraw it at any time by contacting us.

To exercise any of these rights, simply contact our privacy team. We aim to respond within one month.

09. International Users

We welcome users from around the world. Depending on your location, additional privacy rights may apply under local laws such as:

  • EU/EEA: Full GDPR rights including access, rectification, erasure, portability, and more
  • United States: Rights under CCPA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), and other state privacy laws
  • United Kingdom: Rights under UK GDPR and the Data Protection Act 2018
  • Canada: PIPEDA protections for personal information
  • Brazil: LGPD rights including access, correction, and deletion
  • Australia: Australian Privacy Principles under the Privacy Act 1988

10. International Data Transfers

Our services may involve transferring data across borders. When this happens, we ensure your data remains protected through:

  • Strong technical and organizational security measures
  • Encryption of data in transit and at rest
  • Strict access controls limiting data to authorized personnel only
  • Contractual commitments with third-party providers to maintain high data protection standards

11. Children's Privacy

Our platform is designed for users who are 18 years of age or older. While we don't actively verify ages, our services and content are intended for an adult audience. If you're a parent or guardian with concerns, feel free to reach out to us — we're happy to help.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we'll post the updated version on this page and refresh the "Last Updated" date at the top. We encourage you to check back periodically. No sneaky changes — if anything major shifts, we'll make sure it's clearly visible.

Privacy Questions?

If you have any questions about our privacy practices or wish to exercise your rights, don't hesitate to reach out. We're here to help.