Skip to content
idleakcheck
LEGAL, PRIVACY POLICY

Privacy Policy

LAST UPDATED, 17 / 05 / 2026
QUICK SUMMARY
  • Account: email + hashed password (or OAuth subject if you signed in with Google or Apple). Billing through Stripe — we never see card numbers.
  • Searches: we log the values you searched along with IP, timestamps, endpoint, and result counts to run the Service and prevent abuse.
  • Sub-processors: Stripe (payments), OVHcloud (hosting), Cloudflare (edge / WAF), Postmark (email), Sentry (errors, scrubbed). Full list below.
  • Retention: identifiers erased 30 days after account deletion. Audit logs retained 13 months on consumer plans, 24 months on Investigator and Enterprise.
  • If you appear in results: use the Data Removal page to request removal, correction, or to file an abuse report.
01

What this policy covers

This Privacy Policy explains what information IDLeakCheck, Inc. ("IDLeakCheck", "we") collects, how we use it, where it comes from, and the rights you have under U.S. state privacy laws (CCPA, CPRA, VCDPA, CTDPA, and others). Where GDPR or comparable laws apply to you, we are the data controller for personal data processed through the Service.

It applies to (a) website visitors and registered users of idleakcheck.com, our APIs, and our investigator / enterprise consoles, and (b) people whose personal data may appear in Service results. It does not cover the third-party websites linked from our pages.

02

Identifiers you give us

You add up to 14 identifier types to your profile: first / middle / last name, date of birth, email, phone, street, city, state, ZIP, SSN last-4, driver license, VIN, and IP. You can add a subset, edit, or remove any field at any time.

For Family & Friends plans, identifiers added for monitored relatives or friends are treated identically and require an attestation that you have authority to monitor that person.

Please don’t send sensitive documents (such as government IDs) unless we explicitly ask for them in the context of a specific case.

03

Account and billing data

We collect your email and a hashed password (or your OAuth subject if you signed in with Google or Apple). We do not send marketing email; account-bound communications only.

For paid plans we collect a Stripe customer ID and the metadata Stripe returns to us (transaction ID, payment status, plan / price ID). We never receive or store your full card number, CVC, or expiration; that data lives only with Stripe.

We retain billing-history records for 7 years to meet U.S. tax and accounting requirements.

04

Sources we query on your behalf

When you run a search, IDLeakCheck issues lookups against four pillars: (1) breach corpora and paste-site dumps, (2) U.S. public records (voter rolls, court filings, property records, business registrations), (3) live social-media presence checks (Google account, LinkedIn, Instagram, Venmo, PayPal, and similar consent-respecting endpoints), and (4) dark-web archives via licensed mirrors.

We do not sell or trade the queries you run. Aggregate query telemetry (e.g. "X% of searches included an email") is used internally to improve coverage; it is never tied to a specific user externally.

05

Logging and security signals

For every authenticated and unauthenticated request we automatically capture: IP address; date and time; whether you were logged in (and if so, your username / user ID, otherwise "Anonymous"); the endpoint or path called; HTTP status / response code; request duration; and security signals used for fraud detection, rate limiting, and bot challenges.

In some operational logs we also record the full request URL. We don’t routinely log your browser User-Agent on regular search activity, but we may record it for specific security events (for example, when investigating suspected abuse).

We use short-lived anti-replay tokens to protect sensitive endpoints. Those tokens can include derived security signals (such as a hash of the User-Agent) and are not written to normal search audit logs.

06

Search submissions

When you submit a search, we process the fields you enter — which may include name, address, date of birth, email, phone, and SSN last-4 — alongside the logging and security signals described above.

We keep search audit logs to operate the Service, prevent abuse, and troubleshoot. These logs can include the timestamp, IP address, username (or "Anonymous"), endpoint path, the exact values you searched for, a normalized / cleaned version of those values, the result count, and request timing.

07

How long we keep things

Active identifiers and findings are retained for the life of your account. On account deletion we erase identifiers within 30 days from primary storage, with backup expiration following on the standard 90-day rotation.

Search audit logs and security event logs are retained for 13 months on Self and Family & Friends plans, and for 24 months on Investigator and Enterprise plans, after which they are deleted or aggregated. Billing-history records are retained for 7 years (see §03).

08

Sub-processors

We rely on a limited set of sub-processors to run the Service: OVHcloud (hosting and primary database, EU regions), Stripe (payments), Cloudflare (edge, WAF, bot challenges including Turnstile), Postmark (transactional email), and Sentry (error reporting, scrubbed of identifiers). The current list is published at /legal/subprocessors; we will give 30 days’ notice before adding a new sub-processor that materially changes how data is handled.

09

Cookies and similar technologies

We use cookies and similar storage technologies for authentication, security, and service operation. We do not use them for advertising or cross-site tracking.

Cookies we set:
  • idl_session — your authenticated session. HttpOnly, Secure, SameSite=Lax. Sliding 12-hour lifetime.
  • idl_cs — per-session transport-encryption key handle. HttpOnly, Secure, SameSite=Lax. 1-hour lifetime.
  • idl_2fa_trust — remembers a device that has passed two-factor authentication so you aren’t re-prompted for 30 days. HttpOnly, Secure, SameSite=Lax. 30-day lifetime. Set only after you opt in.
  • idl_imp_actor — used internally during administrative impersonation to allow exit back to the admin account. HttpOnly, Secure. Set only when an admin is acting on behalf of a user.
  • idl_theme — remembers your light/dark preference so the page doesn’t flash on load. Not HttpOnly.
Cookies set by third parties when their features are active on a page:
  • Stripe (__stripe_mid, __stripe_sid) — set on pages where we display payment forms, used for fraud prevention by our payment processor.
  • Cloudflare (__cf_bm, cf_clearance) — set across the site for bot management and DDoS protection.
  • Cloudflare Turnstile — set transiently on sign-in, sign-up, and search pages for human-verification challenges.

Your choices. You can change your cookie preferences any time via the "Manage cookies" link in the site footer. The "Reject all" option in our cookie banner takes effect in one click. We honor the Global Privacy Control (GPC) signal as an opt-out of any sale or sharing of personal information (we do not sell or share personal information regardless).

For the full cookie inventory and your choices, see our Cookie Policy.

10

Your rights

You can request access, correction, export, or deletion of your profile data at any time via the Data Removal page. Deletion is honored within 30 days; export is provided in machine-readable JSON.

California residents (CCPA / CPRA) have the right to know what personal information we have collected, to delete it, to correct it, to opt out of "sales" or "sharing" (we do neither), and to limit use of "sensitive personal information" (we already use SSN-last-4 only for the lookup you initiated).

Residents of states with comparable privacy laws (Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, and others) have analogous rights and can use the same controls.

Residents of the EU, UK, and EEA exercising rights under GDPR or UK GDPR may also contact our Data Protection Officer directly at dpo@idleakcheck.com. Requests are responded to within 30 days as the law allows.

11

Personal information categories (California disclosure)

This section summarises the categories of personal information we collect from California residents, the sources we collect from, the business purposes for which we use each category, the categories of recipients with whom we share each category, and the retention period. This disclosure is provided under California Civil Code § 1798.130(a)(5)(B).

CATEGORYEXAMPLESSOURCESBUSINESS PURPOSERECIPIENTSRETENTION
A — Identifiersaccount email, account ID, name, IP address, device identifiers, session cookiesDirectly from you; public records; breach corporaProvide the Service, authentication, security, abuse detection, communicationsSub-processors (see §08); law-enforcement when legally requiredActive account + 30 days post-deletion (audit log 13–24 months)
B — Personal records (Cal. Civ. Code § 1798.80)name, postal address, telephone, SSN last 4, driver-licence reference, date of birthPublic records; breach corpora; consumer-submitted recordsProvide search results; identifier clustering; profile assemblyAuthenticated viewers within the Service (subject to per-tier masking); never soldIndefinitely while record remains in source datasets; removed on verified deletion request
C — Protected classificationsage, gender, race / ethnicity (where present in source records)Public records; voter recordsIdentifier clustering; profile presentationAuthenticated viewers; never soldSame as Category B
D — Commercial informationsubscription tier, billing history, refund history, account eventsStripe; your interactions with the ServiceBilling, fraud prevention, support, accountingStripe (payment processor); never sold7 years (tax / accounting)
E — Biometric informationNone collected.
F — Internet / network activityIP address, browser metadata, search history, profile views, API call metadataYour interactions with the ServiceSecurity, abuse detection, rate limiting, debugging, service operationSub-processors (Cloudflare, Sentry); never sold13–24 months in audit logs per plan tier
G — Geolocation dataapproximate location derived from IP (city / region only — never precise GPS)Your IP address at request timeFraud prevention, abuse-pattern detectionSub-processors (MaxMind GeoLite2 runs offline on our servers); never soldStored alongside the originating request log
H — Sensory dataNone collected.
I — Professional informationoccupation, employer, professional licence references (where present in source records)Public recordsIdentifier clustering; profile presentationAuthenticated viewers; never soldSame as Category B
J — Education informationNone collected.
K — Inferencesderived aliases; address-key clusters; family-relationship suggestions; exposure scoreComputed by IDLeakCheck from Categories A–C, F, G, IProfile assembly, score calculationAuthenticated viewers; never soldRecomputed on each profile view; not separately stored long-term
L — Sensitive personal informationSSN (last 4 digits, gated to enterprise workspaces with can_see_ssn flag); driver-licence number (gated to enterprise workspaces with can_see_driver_license flag); precise authentication credentials (your account password — stored as a bcrypt hash)Public records (SSN/DL); directly from you (credentials)Service operation; restricted by workspace flag attestations under DPPA / GLBAAuthenticated viewers ONLY where the workspace has a signed attestation; never soldSame as Category B (records) / Active account (credentials)

We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We honour the Global Privacy Control (GPC) signal as an opt-out request regardless.

You can limit the use of sensitive personal information (Category L) by submitting a request via Data Removal. Note that some sensitive information (your account credentials) is required to operate your account and cannot be limited without account closure.

You can exercise the rights described in §10 — delete, access, correct, portability, limit sensitive PI, and opt-out of sale or share — through the Data Removal form. We respond to verifiable requests within 45 days under California law (up to 90 days for complex requests, with written notice of the extension).

12

If you appear in results

If you believe information shown by the Service is inaccurate, or you have a legitimate request for removal or correction, please use the Data Removal page. Include enough detail to identify the relevant result(s) — for example, full name and state / region, plus optional identifiers such as birth year, email, or phone.

We review good-faith requests and may remove or correct information where appropriate. Abuse and misuse reports also go through the same form.

13

Sharing with third parties

We do not sell or share personal information for cross-context advertising. Findings stay in your account unless you explicitly export, share a recipient link, or invite a teammate.

Share-recipient links are privacy-defaulted: the sharer’s name, organization, and avatar are hidden from the recipient by default, SSN is suppressed, and dates are shown in MM / DD / YYYY format. You can override these defaults case by case.

We may disclose account information, contact details, search history, IP addresses, device signals, and other relevant records to law enforcement (a) when required by valid legal process such as a subpoena, court order, or search warrant, or (b) when we observe credible misuse of the Service to harass, threaten, dox, stalk, or defraud any person — including other IDLeakCheck users. The Terms of Service describe this in more detail. Where reasonable and not legally prohibited, we will notify the affected user before disclosure.

14

Security

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Access to production systems requires SSO with hardware-backed MFA. We follow NIST 800-53 control families and complete an annual SOC 2 Type II audit; the most recent report is available under NDA from security@idleakcheck.com.

If we detect a breach affecting your data, we will notify you without undue delay and in any event within 72 hours of confirmed scope.

15

Children

IDLeakCheck is not directed to children under 13. We do not knowingly collect personal information from children under 13. Family & Friends plans allow parents and legal guardians to add minors they are responsible for, with explicit attestation; that data is treated with the same protections as adult identifiers.

16

Changes to this policy

Material changes will be announced at least 30 days in advance via the email on file and via an in-product banner. The "Last updated" date below always reflects the most recent revision.

17

Contact

Privacy questions, rights requests, removal / correction requests, and abuse reports all route through the Data Removal page. For other legal notices, see the contact section in the Terms of Service.

See also the Terms of Service, the Refunds, Cancellations, and Account Enforcement Policy, and the Data Removal page for removal, correction, and abuse reports.