β Draft placeholder. This page is built from the facts in the LeakGuard content brief so the site structure is complete. It is not a substitute for a real privacy policy β have this reviewed (or written) by counsel before publishing, and confirm it matches your actual App Store privacy nutrition label and current analytics defaults before launch.
Last updated: [add date before publishing]
LeakGuard is designed to minimize what it collects. We do not store your plaintext passwords or email addresses in a way that identifies you with a specific check. Password check history is stored as a SHA-256 hash, retained for 90 days.
Password breach checks use k-anonymity: your password is hashed on your device, and only a 5-character hash prefix is sent to Have I Been Pwned's API. See our full privacy explainer for the exact technical flow.
Email breach checks route through a proxy service. In Private Check mode, your email is hashed by that proxy before being checked, following the same k-anonymity principle used for passwords.
If you choose to sign in with Apple, Google, or email, we receive the identifiers those providers share with us. You may also use LeakGuard anonymously without signing in.
LeakGuard uses anonymous, aggregated analytics to understand app usage and improve reliability. [Confirm and state clearly here whether this is opt-in or opt-out, and provide a way to control it in Settings β this must match actual app behavior before publishing.]
LeakGuard uses the following services to operate: Have I Been Pwned (breach data), Firebase (authentication, waitlist storage, feature flags, AI assistant), Superwall and StoreKit (subscriptions), and crash/analytics tooling. None of these services receive your plaintext password.
To request deletion of your data, email privacy@leakguard.app.
Questions about this policy: privacy@leakguard.app