Privacy Policy
Last updated
BreachFeed tracks public reporting about data breaches and security incidents and alerts you when something you follow is affected. This page says what the service collects about you, why, who else receives it, how long it is kept and what you can do about it. It describes what the service actually does.
The service is operated by BreachFeed (“BreachFeed”, “we”). To reach us about anything on this page, use the support page.
What we collect
- Your account. Your email address, your name if you give one, and your password — stored only as a one-way hash, never as the password itself. If you turn on two-factor authentication, its secret is stored encrypted.
- What you track. The organizations and keywords you follow, your alert settings, your votes on articles, and your team membership if you belong to one.
- Sign-in history. For each sign-in attempt: the internet address it came from, the browser or device it used, the approximate location of that network (city, region, country), the time and whether it succeeded. We use it to lock out password guessing, to apply the regions the service is available in, and to investigate misuse.
- Devices and phone numbers. The push token of each device where you allow notifications, and any phone number you add for text alerts — which is only ever texted after you confirm a code sent to it.
- Billing. Your plan and the status of your subscription. Payments are handled by Stripe: your card details are entered on Stripe’s pages and never reach our servers.
- What we sent you. Which alerts and briefs went out, and whether an email to you bounced or was marked as spam, so that we stop writing to an address that does not want or cannot take the mail.
- Shares and referrals. When you share an article through the share menu, which article and by which route; and, if you joined with a referral code, whose code it was.
- Messages to support. What you write on the support page reaches us as an email; it is not kept in the service’s own database.
- Server logs. Each request is logged with the page or endpoint it asked for and the network it came from — not the full address, and not what was typed into a search box.
How we use it
To run the service you signed up for: matching reporting to what you track, sending the alerts and briefs you asked for, keeping your account secure, taking payment for paid plans, answering you when you write, and keeping the service working. We do not sell personal data, and we do not use it for advertising.
Who else receives it
We use a small number of companies to deliver the service. Each receives only what its job needs:
| Company | What it receives | Why |
|---|---|---|
| Fly.io | Everything the service stores: it runs our servers and database, in the United States. | Hosting |
| Twilio SendGrid | Your email address and the content of the messages we send you (alerts, the weekly brief, verification, password reset and team invitation emails). It reports back whether a message bounced, was dropped or was marked as spam. | Email delivery |
| Stripe | Your email address, your name if you gave one, and your account’s identifier. Card and billing details are entered on Stripe’s own pages and never reach our servers. | Payments |
| Expo, and through it Apple and Google | Your device’s push token and the title and text of each alert. | Push notifications in the mobile app |
| IPinfo | The network your connection comes from (the first three parts of an IPv4 address, or the /64 of an IPv6 address) — never the full address. | Working out the country and approximate location of a sign-in |
| Twilio | A phone number you added and confirmed, and the text of each alert sent to it. Only where text alerts are available. | Text message alerts |
| Anthropic | For the weekly brief: the names of the entities you track and that week’s incident facts — not your email address or any account identifier. (News articles are also read by its models to build incident records; those are public reporting, not your data.) | Writing the weekly brief |
If you add a webhook destination (a Slack channel, a Microsoft Teams channel, or an endpoint of your own), the alerts for what you track are posted there at your direction: the names of the entities concerned and the headlines and details of the alerts — not your email address or account details. Whoever runs that destination (Slack, Microsoft, or you) then holds what was posted, under their own terms.
We may also disclose information where the law requires it, or where it is needed to investigate misuse of the service or to protect someone’s safety.
How long we keep it
| What | Kept |
|---|---|
| Your account, what you track and your settings | Until you delete the account |
| Sign-in history (address, device, approximate location, outcome) | 365 days |
| The record of which alerts were sent to you | 35 days |
| Email delivery events (bounced, dropped, marked as spam) | 90 days |
| Share events | 365 days |
| The record of account emails we sent you (a failed payment, a plan ending): what kind and when | Until you delete the account |
| Webhook destinations you added (the address is stored encrypted) | Until you remove them, or delete the account |
| Sessions | Until they expire (30 days) or you sign out |
| Push registrations for a device | Until the device has been idle 60 days |
| Team invitations that were not taken up | Until they expire (7 days) |
| The cached location of a network | Up to 60 days |
| The record of actions our staff took on accounts | Kept; it names accounts by identifier, never by email address |
Deleting your account removes it and what hangs from it — what you track, your settings, your sessions and devices, your alert history — along with the sign-in and email-delivery records kept under your address, and your customer record at Stripe. For one day we keep a note that an account was created from a network (the network and the time only), so that the limit on new sign-ups cannot be reset by deleting accounts.
Your choices
- See your data. Account → “Download your data” gives you a copy: your settings, what you track, your alert and sign-in history, your briefs, and anything our staff did to the account.
- Delete your account. Account → “Delete account”, on the site or in the app. It takes effect immediately.
- Change your settings and details. Your password and every alert setting are on the account page and the dashboard. To correct your name or email address, write to us through the support page.
- Stop email. Every alert and brief has a link that stops it without signing in, and your mail app’s own unsubscribe button works too.
- Stop texts and push. Reply STOP to a text to end texts to that number; turn notifications off for a device in the app or in the device’s settings.
Depending on where you live, the law may give you further rights over your information — for example to object to some uses of it, or to complain to a data protection authority. Write to us through the support page and we will respond.
Security
Connections to the service are encrypted. Passwords are stored as one-way hashes, two-factor authentication is available on every account, repeated wrong passwords lock sign-in, and changing your password signs you out everywhere else. No system is perfectly secure: if we learn of a breach affecting your information, we will notify you as the law requires.
Where it is processed
The service’s servers and database are in the United States, and the companies listed above may process information there or elsewhere. If you use BreachFeed from another country, your information is processed outside it.
Children
BreachFeed is not directed to children, and accounts are for people aged 18 or over. We do not knowingly collect information from children.
Changes to this policy
When this page changes, the date at the top changes with it. If a change significantly affects how your information is used, we will tell members by email or on the site before it takes effect.
Contact
Questions about this policy or about your information: the support page. See also our Terms of Service.