Privacy Policy

Effective 2026-07-19

1. Introduction

This Privacy Policy explains how Am I Hacked? ("we", "our", "us") collects, uses, shares, and protects personal data when you use aih.gg, including our dashboard and APIs (the "Service"). We act as the data controller for the personal data described in this policy. You can contact us about privacy at [email protected].

The Service is an OSINT and breach-intelligence tool. This policy covers both your data as an account holder and, in Section 4, how search queries and search results involving other people's data are handled.

2. Information We Collect

Account information

  • Name and email address. Sign-in is passwordless: we email you one-time verification codes instead of storing a password.
  • Optional profile picture, if you upload one.
  • Account status information, such as email verification state, role, and any account restrictions.

Security and session information

  • Session records, including a session token, IP address, and browser/device information (user agent), shown to you in account settings and used in security alerts.
  • Short-lived verification codes used for sign-in, email verification, and email changes.

Billing information

  • Our payment provider, Stripe, collects your card details directly; full card numbers never touch our servers. We store your Stripe customer reference, references to your saved payment methods, your subscription status, and your search-credit balance.
  • Invoices and billing history are held by Stripe and displayed to you in the dashboard.

Usage information

  • Search queries you run (the identifier searched, its type, and options selected) and associated metadata such as timestamps and result status.
  • On eligible plans, a search history covering roughly the last 7 days.
  • Your one-time free search status, and API key details such as key name, prefix, permissions, usage counts, and rate-limit state. API keys themselves are stored hashed.

Support information

  • Support tickets and replies you submit, along with ticket status and references.

Device and technical information

  • Strictly necessary cookies for authentication (see Section 5) and standard technical logs generated when you use the Service.

We do not knowingly collect any special-category data about you, and we do not run advertising or analytics trackers.

3. How We Use Your Information

We use personal data to:

  • provide the Service: authenticate you, run your searches, stream results, maintain your history and credit balance, and operate the API (performance of our contract with you);
  • process payments, subscriptions, and credit purchases via Stripe (performance of contract; legal obligations for tax and accounting);
  • protect accounts and the Service: send security alerts about new sign-ins, email changes, and API key changes; detect and prevent fraud, abuse, and misuse; enforce rate limits and our Terms (legitimate interests in securing the Service, and performance of contract);
  • provide support and respond to your requests, including via support tickets (performance of contract);
  • send service communications such as verification codes and important account or billing notices (performance of contract). We do not currently send marketing emails;
  • comply with legal obligations and establish, exercise, or defend legal claims.

Authorised staff may access your account data (including, where necessary, viewing the dashboard as your account) to investigate problems, provide support, and enforce our Terms. Such access is limited to what the task requires.

4. Search Queries and Information About Other People

  • When you run a search, your query (for example an email address, username, phone number, or IP address) is sent to specialist external intelligence and data providers that perform the lookup, together with a pseudonymous account reference used for request attribution and abuse prevention. Your name and email address are not shared with these providers.
  • IP Lookup queries are processed by the geolocation provider ip-api.com; the IP address you enter is sent to them to produce the result.
  • Search results are returned to you in real time from these providers. We do not operate our own database of breached data; we retain queries and result metadata only as described in Sections 2 and 7 (for example your 7-day search history).
  • Queries may relate to people other than you. If you search identifiers belonging to someone else, you are responsible for having a lawful basis to do so and for how you use the results, as set out in our Terms of Service.
  • If you believe information about you has appeared in search results and you wish to exercise your data protection rights over it, contact us at [email protected]. Where the data originates from an external provider, we will direct you to the relevant provider and assist where we reasonably can.

5. Cookies and Local Storage

  • We use one strictly necessary cookie, the authentication session cookie, to keep you signed in. It is essential for the Service and does not require consent.
  • Your cookie banner choice is stored in your browser's local storage so we do not ask again.
  • We do not use advertising or analytics cookies.
  • On billing pages, Stripe sets its own cookies as part of payment processing and fraud prevention; see Stripe's privacy policy for details.
  • Some interface preferences (such as theme) may also be stored locally in your browser; these stay on your device.

6. Who We Share Data With

We do not sell your personal data. We share it only with service providers who process it on our behalf, with the parties described in Section 4, and where the law requires:

  • Stripe: payment processing, subscriptions, invoices, and fraud prevention.
  • Postmark: delivery of transactional email (verification codes, security alerts, account notices).
  • Cloudflare: network security, proxying, and delivery of the Service (this is how we receive your IP address).
  • Upstash: hosted Redis used for caching, search history, credit balances, and processing safeguards.
  • Managed database and object storage providers: hosting of our PostgreSQL database and, if you upload a profile picture, S3-compatible storage. Profile pictures are stored under a hashed reference at a publicly accessible URL, so avoid uploading anything sensitive.
  • External intelligence and data providers: receive search queries as described in Section 4 (including ip-api.com for IP lookups).
  • Brandfetch: service logos shown in results are loaded from Brandfetch's CDN, either via our servers or directly by your browser (in which case Brandfetch receives your IP address as part of the image request).

We may also disclose personal data where required by law or legal process, to enforce our Terms, or to protect the rights, property, or safety of us, our users, or others, and in connection with a merger, acquisition, or sale of assets (in which case this policy continues to apply to data transferred).

7. Data Retention

  • Account data: kept while your account exists and deleted or anonymised after account deletion, except where we must keep records longer (for example billing records for tax purposes).
  • Sessions: kept until they expire or you revoke them.
  • Verification codes: short-lived and expire automatically.
  • Search history: accessible for roughly 7 days; short-lived search caches expire within about an hour.
  • Support tickets: kept while your account exists, and as needed to resolve disputes.
  • Billing records: kept for as long as tax and accounting law requires.

8. International Transfers

Some of our providers (including Stripe, Postmark, Upstash, Cloudflare, Brandfetch, and external intelligence providers) may process data outside the UK/EEA, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses with those providers.

9. Security

We take proportionate technical and organisational measures to protect personal data, including passwordless sign-in with one-time codes, hashed storage of API keys, security alert emails for sensitive account events, session management with revocation, encrypted transport (HTTPS), and access controls with role restrictions for administrative functions. No online service can guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and regulators where required by law.

10. Your Rights

Depending on your location (including under the UK and EU GDPR), you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • correct inaccurate data (name, email, and profile picture can be changed in account settings);
  • delete your data (the Service has no self-service account deletion yet, so email us and we will action it);
  • restrict or object to certain processing, including any processing based on legitimate interests;
  • data portability, where processing is based on contract or consent;
  • complain to your supervisory authority (in the UK, the Information Commissioner's Office), though we would welcome the chance to resolve concerns first.

To exercise any right, contact [email protected]. We may need to verify your identity before acting, and we respond within the timescales required by law.

11. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18. If you believe a minor has provided us personal data, contact us and we will delete it.

12. Changes to This Policy

We may update this policy from time to time. The effective date above shows the current version, and material changes will be notified by email or a notice in the Service before they take effect.

13. Contact

Privacy questions and rights requests: [email protected]. General support: [email protected].