Back to home

Privacy Policy

Last updated September 1, 2026

This policy explains what Breachly holds about you, why we hold it, how long we keep it and what you can ask us to do with it. It is written to be read, not to be skimmed past. The short version: we need an account and a payment to run the service, we keep the records that come with that, and we do not keep what you search for.

1.Who we are and what this covers

Breachly is a lookup and bulk search service. You search an identifier and get the records that match it, or you upload a file and we run the same lookup over every line, then hand the results back in the layout you choose.

This policy covers the website, the signed in app and the Telegram bot. It applies to everyone who uses Breachly, whether you signed up on the site, through Telegram, or both. Where it says "we", it means the team operating Breachly, which is the controller of the data described here.

2.What we collect

Only what the service needs to run and to be paid for.

  • Your account. A username, an email address if you give one, a password, and a profile picture if you upload one. Passwords are stored hashed. Nobody here can read yours, and we cannot send it back to you.
  • Telegram, if you link it. Your Telegram account id, username, display name and profile photo. Linking is optional. An account can live entirely on the site with no Telegram at all, or entirely in the bot. You can disconnect it yourself from the Telegram page in your account, and everything listed here goes with it. For about two weeks after that, no Telegram account can be connected to yours, including the one that was removed.
  • Sessions and devices. For each place you are signed in: the network address, browser, operating system and the rough city and country it resolves to. This is what fills the security list in your profile, so you can spot a session you do not recognise and end it.
  • Billing. The plan you bought, the amount, the coin and network you chose, the payment address we showed you, the transaction reference and when it confirmed. We never hold your wallet, your keys or a card number, because we do not take cards.
  • Usage counts. That a search or a bulk job ran, which kind it was, how much it counted against your allowance and when. This is how limits are measured. It contains no search terms.
  • Bulk search files. The file you upload for a job is processed in memory to run your search and is held only for your active session, then removed from our servers. The results a job produces live in memory for that same session, are never written to our database, and go when the session ends. We keep only the settings you picked, so a job can be resumed where you left it. We never read the contents of your file or your results.
  • Support. The tickets you open and every message in them, including anything you choose to paste into one.
  • Account activity. A trail of things that happened to your account: sign ins, security changes, plan changes, and counts of searches. It records that something happened, never what was searched. An entry for something you did yourself also keeps the network address and rough location it came from, the same way the security list does.

3.What we do not collect

Some of this is worth stating plainly, because it is the part people ask about most.

  • We do not keep your search terms. A search runs and the terms go with it. They are not written to your history, your activity trail or any log we keep. Nobody here, including our own staff, can look up what you searched for, because the record does not exist.
  • We do not keep the results of a single search. What comes back is yours. It is not copied into your account record and it is not attached to your profile. A bulk job is the one exception, and only because you asked for a file: the export you build is stored so you can download it, and it is covered in the retention section below.
  • We do not read your uploaded files for anything else. A file you upload is used to run your job and nothing else. Its contents are never shown anywhere in the app, never used to build a profile of you, and never shared.
  • No advertising, no tracking pixels, no data sales. There are no advertising cookies, no ad networks and no marketing profile of you anywhere. We do not sell, rent or share your data with advertisers or data brokers, and we do not send marketing email. The only outside companies involved at all are the few listed further down, and each of them is there to do a job you asked for.

4.Why we are allowed to process it

If you are in the UK or the EU, these are the legal bases we rely on under the GDPR.

  • To perform our contract with you. Creating your account, running your searches and bulk jobs, applying your plan and its limits, answering your tickets.
  • Our legitimate interests. Keeping accounts secure, detecting and stopping abuse and fraud, and keeping the service reliable. We weigh this against your interests and keep the data involved to the minimum.
  • A legal obligation. Keeping records of payments for the period that tax and accounting rules require.
  • Your choice. Linking Telegram is optional, and you can disconnect it yourself from the Telegram page in your account. Reconnecting is limited to about once every two weeks. Nothing about the core service depends on it.

5.How long we keep it

Most of what follows is kept for as long as your account exists rather than on a timer. We would rather say that plainly than describe a clear out that does not happen.

  • Your account. For as long as the account exists. Ask us to close it and the account record goes with it.
  • A bulk job you left unfinished. It stops being resumable 24 hours after you last worked on it and drops off your active jobs. The entry stays in your job history until you remove it.
  • A finished bulk job. It stays in your job history until you remove it, so you can see what you ran and start the same job again.
  • Files you uploaded, and your results. Held only for your active session. Your uploaded file is processed in memory to run the job and removed from our servers once the session ends; your results live in memory for that session and are never stored in our database. An export you deliberately build is the one thing written to disk, so you can download it: it is kept for a short window (about a week) and then deleted. Nothing about your file or your results is retained beyond that, and no one on our team can read either one.
  • Sessions and devices. Kept for as long as your account exists, including the network address and rough location. Ending a session marks it ended in your security list rather than erasing it, so the list can still show you that it happened and when. Nothing removes these on a schedule. Ask us to clear the older ones and we will, and closing your account takes them with it.
  • Usage counts and activity. Kept while your account exists, because your limits are measured against them and the activity trail is a security record.
  • Support tickets. Kept while your account exists, so an old thread can still be read back.
  • Payment records. Kept for as long as accounting and tax rules require, even after an account is closed. This is the one thing we cannot delete on request.

6.Who else touches it

We keep the list short on purpose. Each of these is here because a part of the service depends on it, and none of them is given what you searched for.

  • Our crypto payment provider. It creates the invoice, watches the network and tells us when a payment confirms. It sees the order amount and the payment details, nothing about your account beyond the order.
  • Telegram. Only if you sign in with Telegram or use the bot. In that case Telegram handles the message and the sign in the way it handles everything else on its platform.
  • The bot check on our sign in and sign up forms. A third-party challenge that tells us a form was filled in by a person. It sees the request, not your account.
  • Our hosting provider. Runs the servers the service sits on. It stores the data on our behalf, under contract, and does not use it for anything of its own.

We will also hand over data where a valid legal order requires it. We do not do so voluntarily, and we tell you if we are permitted to.

7.What our staff can see

Support and administration need some visibility to be useful. Here is the boundary.

  • Staff can see your account details, your plan, your orders, your usage counts and your support threads, in order to answer you and fix problems.
  • Staff cannot see what you searched for, because it is never recorded. That one is absolute: the record does not exist for anyone to read.
  • No one on our team can see the contents of a file you uploaded or the results a job returned. Your file is processed in memory and removed when your session ends, your results are never written to our database, and the app exposes no way for staff to read either. What you upload and what you get back stay yours.
  • Actions taken on your account by an administrator, such as a plan change, are written to your activity trail so you can see that they happened.

8.Cookies and browser storage

  • Sign in cookies. One keeps you signed in between page loads, one remembers the page you were heading for so you land there afterwards, and one protects the sign in form itself. Sign out and they are gone. Without them the app cannot work at all.
  • A language cookie. Remembers the language you chose.
  • Interface preferences. Small things like your theme and the layout choices you made are kept in your own browser storage. They stay on your device and are not sent to us.
  • Nothing else. No advertising cookies, no ad networks, no marketing profile of you anywhere, and no fingerprinting.

9.How we protect it

  • Traffic between you and Breachly is encrypted in transit.
  • Passwords are hashed, never stored in a readable form and never sent back to you.
  • Every signed in session is listed in your profile with the device it belongs to, and you can end any of them, including from another device.
  • Access to production data is limited to the people who need it to run the service.
  • If a security incident ever affects your data, we will tell you and the relevant authority within the time the law allows.

10.Your rights

You can ask us to do any of the following, free of charge.

  • See what we hold about you, and get a copy of it in a portable format.
  • Correct anything that is wrong.
  • Delete your account and the data tied to it, apart from payment records we are required to keep.
  • Restrict or object to processing we base on our legitimate interests.
  • Undo a choice you made. Some of these you control directly: Telegram can be disconnected from the Telegram page in your account.

Open a ticket from the contact page and say what you want. We answer within 30 days and aim to be much quicker. If you are in the UK or the EU and you are not happy with our answer, you can complain to your national data protection authority. No automated decision is ever made about you that has a legal or similarly significant effect.

11.Where your data sits

Breachly runs on rented servers, and the providers listed above are the only ones that touch your data. Where one of them processes it outside the country you are in, the transfer is covered by the standard contractual clauses or an equivalent safeguard recognised under the GDPR.

Ask us where your data is held at the time you ask and we will tell you, from the contact page.

12.Age

Breachly is for adults. You must be at least 18 to hold an account. We do not knowingly collect anything from anyone younger, and if we find out we have, we delete it.

13.Changes to this policy

When this policy changes, the date at the top changes with it. If a change is significant, you will see it in the app before it takes effect rather than having to find it here. The previous version stays available on request.

14.How to reach us

For anything in this policy, including a request about your data, open a ticket from the contact page. It keeps the whole thread in one place and it is the fastest route to a person. If you do not have an account, Telegram at @breachly works too.

You can open a ticket at any hour, and we aim to give you a first reply within the hour.

Questions about this document? Ask us and we will answer.

Contact support