BreachFeed

Privacy Policy

Last updated

BreachFeed tracks public reporting about data breaches and security incidents and alerts you when something you follow is affected. This page says what the service collects about you, why, who else receives it, how long it is kept and what you can do about it. It describes what the service actually does.

The service is operated by BreachFeed (“BreachFeed”, “we”). To reach us about anything on this page, use the support page.

What we collect

  • Your account. Your email address, your name if you give one, and your password — stored only as a one-way hash, never as the password itself. If you turn on two-factor authentication, its secret is stored encrypted.
  • What you track. The organizations and keywords you follow, your alert settings, your votes on articles, and your team membership if you belong to one.
  • Sign-in history. For each sign-in attempt: the internet address it came from, the browser or device it used, the approximate location of that network (city, region, country), the time and whether it succeeded. We use it to lock out password guessing, to apply the regions the service is available in, and to investigate misuse.
  • Devices and phone numbers. The push token of each device where you allow notifications, and any phone number you add for text alerts — which is only ever texted after you confirm a code sent to it.
  • Billing. Your plan and the status of your subscription. Payments are handled by Stripe: your card details are entered on Stripe’s pages and never reach our servers.
  • What we sent you. Which alerts and briefs went out, and whether an email to you bounced or was marked as spam, so that we stop writing to an address that does not want or cannot take the mail.
  • Shares and referrals. When you share an article through the share menu, which article and by which route; and, if you joined with a referral code, whose code it was.
  • Messages to support. What you write on the support page reaches us as an email; it is not kept in the service’s own database.
  • Server logs. Each request is logged with the page or endpoint it asked for and the network it came from — not the full address, and not what was typed into a search box.

Cookies

The site sets only the cookies it needs to work: the ones that keep you signed in, a short-lived one while you complete a two-factor sign-in or set-up, and — if you arrive through a referral link — one that remembers the code for 30 days so it can be applied if you sign up. There are no advertising or analytics cookies, and no third-party trackers.

How we use it

To run the service you signed up for: matching reporting to what you track, sending the alerts and briefs you asked for, keeping your account secure, taking payment for paid plans, answering you when you write, and keeping the service working. We do not sell personal data, and we do not use it for advertising.

Who else receives it

We use a small number of companies to deliver the service. Each receives only what its job needs:

CompanyWhat it receivesWhy
Fly.ioEverything the service stores: it runs our servers and database, in the United States.Hosting
Twilio SendGridYour email address and the content of the messages we send you (alerts, the weekly brief, verification, password reset and team invitation emails). It reports back whether a message bounced, was dropped or was marked as spam.Email delivery
StripeYour email address, your name if you gave one, and your account’s identifier. Card and billing details are entered on Stripe’s own pages and never reach our servers.Payments
Expo, and through it Apple and GoogleYour device’s push token and the title and text of each alert.Push notifications in the mobile app
IPinfoThe network your connection comes from (the first three parts of an IPv4 address, or the /64 of an IPv6 address) — never the full address.Working out the country and approximate location of a sign-in
TwilioA phone number you added and confirmed, and the text of each alert sent to it. Only where text alerts are available.Text message alerts
AnthropicFor the weekly brief: the names of the entities you track and that week’s incident facts — not your email address or any account identifier. (News articles are also read by its models to build incident records; those are public reporting, not your data.)Writing the weekly brief

If you add a webhook destination (a Slack channel, a Microsoft Teams channel, or an endpoint of your own), the alerts for what you track are posted there at your direction: the names of the entities concerned and the headlines and details of the alerts — not your email address or account details. Whoever runs that destination (Slack, Microsoft, or you) then holds what was posted, under their own terms.

We may also disclose information where the law requires it, or where it is needed to investigate misuse of the service or to protect someone’s safety.

How long we keep it

WhatKept
Your account, what you track and your settingsUntil you delete the account
Sign-in history (address, device, approximate location, outcome)365 days
The record of which alerts were sent to you35 days
Email delivery events (bounced, dropped, marked as spam)90 days
Share events365 days
The record of account emails we sent you (a failed payment, a plan ending): what kind and whenUntil you delete the account
Webhook destinations you added (the address is stored encrypted)Until you remove them, or delete the account
SessionsUntil they expire (30 days) or you sign out
Push registrations for a deviceUntil the device has been idle 60 days
Team invitations that were not taken upUntil they expire (7 days)
The cached location of a networkUp to 60 days
The record of actions our staff took on accountsKept; it names accounts by identifier, never by email address

Deleting your account removes it and what hangs from it — what you track, your settings, your sessions and devices, your alert history — along with the sign-in and email-delivery records kept under your address, and your customer record at Stripe. For one day we keep a note that an account was created from a network (the network and the time only), so that the limit on new sign-ups cannot be reset by deleting accounts.

Your choices

  • See your data. Account → “Download your data” gives you a copy: your settings, what you track, your alert and sign-in history, your briefs, and anything our staff did to the account.
  • Delete your account. Account → “Delete account”, on the site or in the app. It takes effect immediately.
  • Change your settings and details. Your password and every alert setting are on the account page and the dashboard. To correct your name or email address, write to us through the support page.
  • Stop email. Every alert and brief has a link that stops it without signing in, and your mail app’s own unsubscribe button works too.
  • Stop texts and push. Reply STOP to a text to end texts to that number; turn notifications off for a device in the app or in the device’s settings.

Depending on where you live, the law may give you further rights over your information — for example to object to some uses of it, or to complain to a data protection authority. Write to us through the support page and we will respond.

Security

Connections to the service are encrypted. Passwords are stored as one-way hashes, two-factor authentication is available on every account, repeated wrong passwords lock sign-in, and changing your password signs you out everywhere else. No system is perfectly secure: if we learn of a breach affecting your information, we will notify you as the law requires.

Where it is processed

The service’s servers and database are in the United States, and the companies listed above may process information there or elsewhere. If you use BreachFeed from another country, your information is processed outside it.

Children

BreachFeed is not directed to children, and accounts are for people aged 18 or over. We do not knowingly collect information from children.

Changes to this policy

When this page changes, the date at the top changes with it. If a change significantly affects how your information is used, we will tell members by email or on the site before it takes effect.

Contact

Questions about this policy or about your information: the support page. See also our Terms of Service.