← Back to OpenExposure

Privacy

Plain-language summary of what happens when you use OpenExposure.

What you search is never stored

The email, phone number or username you enter is used only to run the checks for that search and build your report. It is not written to disk, not logged, and the report is not saved. Results are held in memory for up to 15 minutes so a repeat search is fast, then discarded.

Who sees your search

To find breaches and public profiles, the value you enter is sent to the breach databases and public services we check, the same way it would be if you searched them yourself. Passwords you check never leave your device. Your browser turns the password into a scrambled code and sends only a small piece of it, which is not enough for anyone to work out the password.

The deeper check ("Hacker view")

After a search we check hundreds of public sites for accounts and profiles linked to what you entered, the way an attacker would. These checks never sign in anywhere and never trigger password-reset emails or texts. For an email address, the details are shown only after you enter a 6-digit code we send to that inbox, so nobody can see another person's accounts. Results are held in memory for up to an hour and then discarded. They are never written to disk.

If you received a code you did not ask for, someone searched your email. Nothing is unlocked without the code, so you can ignore it.

Anonymous usage statistics

We count how the site is used so we can keep it running and improve it. For each search we keep: the hour, whether it was an email, phone or username, your country (from our network provider, not your exact location), how many breaches were found, the overall risk level, which attack types were shown, and how long it took. We also keep a running count of how often each breached site appears in results. None of this includes what you searched.

Abuse protection

To stop one person being looked up over and over by strangers, we keep a scrambled fingerprint (a keyed hash) of each searched value and of the visitor's IP address for 30 days. The fingerprint cannot be turned back into the email, phone or IP. If the same value is searched by many different visitors in a day, further searches for it are paused until the next day.

Your browser

Your checklist progress is saved only in your own browser and never sent to us. Clearing your browser data removes it.

No accounts, no ads, no selling

There is no sign-up, no advertising, no tracking cookies, and nothing is sold or shared.

Please only check yourself

Only search for an email, phone number or username that is yours or that you have permission to check.