⚠ Draft placeholder. This page is built from the facts in the LeakGuard content brief so the site structure is complete. It is not a substitute for a real privacy policy β€” have this reviewed (or written) by counsel before publishing, and confirm it matches your actual App Store privacy nutrition label and current analytics defaults before launch.

Legal

Privacy Policy

Last updated: [add date before publishing]

What we collect

LeakGuard is designed to minimize what it collects. We do not store your plaintext passwords or email addresses in a way that identifies you with a specific check. Password check history is stored as a SHA-256 hash, retained for 90 days.

How password checks work

Password breach checks use k-anonymity: your password is hashed on your device, and only a 5-character hash prefix is sent to Have I Been Pwned's API. See our full privacy explainer for the exact technical flow.

How email checks work

Email breach checks route through a proxy service. In Private Check mode, your email is hashed by that proxy before being checked, following the same k-anonymity principle used for passwords.

Sign-in data

If you choose to sign in with Apple, Google, or email, we receive the identifiers those providers share with us. You may also use LeakGuard anonymously without signing in.

Analytics

LeakGuard uses anonymous, aggregated analytics to understand app usage and improve reliability. [Confirm and state clearly here whether this is opt-in or opt-out, and provide a way to control it in Settings β€” this must match actual app behavior before publishing.]

Third-party services

LeakGuard uses the following services to operate: Have I Been Pwned (breach data), Firebase (authentication, waitlist storage, feature flags, AI assistant), Superwall and StoreKit (subscriptions), and crash/analytics tooling. None of these services receive your plaintext password.

Data deletion

To request deletion of your data, email privacy@leakguard.app.

Contact

Questions about this policy: privacy@leakguard.app