1. Who we are

Breach Watchdog is developed by AppDev020, reachable at appdev020@proton.me.

2. What data we process

Email addresses

When you check an email address, it is sent to Have I Been Pwned, LeakCheck and XON to check against known data breaches. This email address is not stored by us on external servers. Monitored email addresses are stored encrypted on your device.

Password check

Passwords are never sent in full. A SHA-1 hash of the password is created; only the first 5 characters of that hash are sent to Have I Been Pwned and XON (k-anonymity model). The original password never leaves your device.

URL scanner

When you scan a URL, the link is sent to Google Web Risk to check for malware and phishing. Google processes this URL in accordance with their privacy policy. We do not store scanned URLs.

Domain check

For a domain check, DNS records (SPF/DMARC) are retrieved via Cloudflare DNS-over-HTTPS and WHOIS data is retrieved via the public RDAP protocol. No personal data is sent.

Google sign-in

To redeem a promo code you can optionally sign in with Google. That creates a Firebase Auth account. We receive your Google name, email address, and a unique user ID (UID). We use that UID to tie promo redemption to your account (including after reinstall) and as your purchase identity with RevenueCat. Signing in is not required to use the app.

Purchases

For processing purchases (one-time Pro unlock) we use RevenueCat (revenuecat.com). RevenueCat processes purchase data via Google Play. We do not have access to your payment details. Please refer to the RevenueCat privacy policy for more information.

Crash reports

Crash reporting is off by default. Only if you enable it in Settings does Firebase Crashlytics (Google) collect technical information on crashes, such as the device type, Android version, and stack trace. Device identifiers may be included as part of the crash report. No additional personally identifiable data (such as names or email addresses) is collected.

3. What we don't do

4. Security

Monitored email addresses are stored encrypted on your device via Android Keystore. Report data is stored locally in a secure database.

5. Retention and account deletion

Email addresses you check are relayed through our secure Cloud Function proxy to third parties and are not stored by us. Monitored addresses live only encrypted on your device. Firebase Auth data remains for as long as your account exists. We keep promo-code records to prevent reuse of single-use codes; when you delete your account we scrub your user ID from those records, but a redeemed code stays marked as used. Deleting your account also removes any Pro access linked to it, including access unlocked by a redeemed promo code.

You can delete your account in the app (Settings → Delete account) or via breachwatchdog.nl/en/delete-account, which explains what is removed and what is retained.

6. Children

Breach Watchdog is not intended for children under the age of 13.

7. Changes

We may update this policy. The most recent version is always available here or via the link in the Play Store.

8. Contact

Questions? Email appdev020@proton.me