← LeakWatch

Privacy Policy

Last updated: August 14, 2026 — version applicable to leakwatch.net

1. Data Controller

LeakWatch (a sole trader — entreprise individuelle, registration in progress), established at 1 square d'Oslo, France, is the controller of the data described below. For any question regarding your data, contact [email protected].

2. Data I collect

Free public scan. Entering a GitHub/GitLab username in the scan tool collects nothing about you: it only queries my database of leaks that have already been publicly detected.

Connected account. When you sign in with OAuth (GitHub or GitLab), I receive from the chosen platform your identifier, your username, your avatar and, if you allow it, your public email. I never receive or store your password, nor the full access tokens of your GitHub/GitLab account.

DataPurposeRetention period
Provider, OAuth identifier and usernameAuthentication, linking detected leaks to your accountAccount lifetime
Avatar (URL)Interface displayAccount lifetime
EmailSecurity alerts in case of a detected leak (can be disabled in settings)Account lifetime, or until you withdraw your consent
Session cookie (JWT, httpOnly)Maintaining connection12 hours maximum
IP addressRate limiting (anti-abuse), not associated with your accountNot stored in database — processed in memory only
Stripe customer ID and subscription IDPaid subscription managementSubscription lifetime + legal billing period

Detected leaks. As part of its mission, the Service indexes information made public by third parties on source code platforms (repositories, commits, file excerpts containing secrets). This data is not provided by you: it is collected automatically from resources that are already public. Only the beginning of the detected secret (a few characters) is shown in the interface — never its full value. Leaks classified as irrelevant or resolved are deleted after 15 days; active leaks are retained until they are fixed, for security purposes.

Payment. Payment card data never passes through my servers: it is entered and processed directly by Stripe.

3. Legal basis for processing

In accordance with Article 6 of the GDPR, these processing activities rest on: performance of the contract (account creation, provision of the Service, subscription billing), my legitimate interest (security, abuse prevention, improvement of the Service), and your consent where it is explicitly required — email notifications, which you can disable at any time in your settings, as well as the analytics cookies described in section 6, which are only set after you accept them.

4. Recipients and subcontractors

Your data may be transmitted to the following providers, strictly to the extent necessary to provide the Service:

DataPurposeRetention period
StripePayment processing and subscription managementAccording to Stripe's privacy policy
GitHub / GitLabOAuth AuthenticationNot applicable — these platforms do not receive data from me
AI infrastructure provider (false positive classification)Automated analysis of detected secrets to reduce false positives24h caching on LeakWatch side; not stored by the provider
PostHogProduct analytics — only with your consent (see section 6)According to PostHog's privacy policy

The artificial intelligence classification engine may run locally (in which case secrets never leave my infrastructure) or through a third-party cloud provider, depending on my technical configuration at the time. When cloud mode is active, an excerpt of the detected secret is transmitted to that provider for classification purposes only, and is not retained by them beyond the processing of the request.

I do not sell or rent your personal data to third parties.

5. Transfers outside the European Union

Some of the processors I use (notably Stripe and PostHog) may process data outside the European Union, on the basis of the European Commission's standard contractual clauses or an equivalent adequacy mechanism guaranteeing an appropriate level of protection.

6. Cookies

LeakWatch sets two technical cookies, strictly necessary for the Service to work: the session cookie (httpOnly, not accessible from JavaScript), which keeps you signed in for 12 hours, and a companion marker with the same lifetime that only records that a session exists, so that public pages do not query the account API for signed-out visitors. Neither carries an identifier, neither serves any advertising purpose, and neither requires consent.

Analytics. LeakWatch uses PostHog, a product analytics tool, to understand how the Service is used and to improve it. PostHog acts as a processor; its servers are located in the United States, a transfer covered by the framework described in section 5. PostHog sets analytics cookies that allow your browser to be recognised from one visit to the next. The data collected consists of the pages viewed, the actions performed in the interface, the device type and the site your visit came from. No security-related technical data — detected secret, repository content, key value — is sent to this tool. Requests pass through my own domain rather than a third-party domain.

No advertising. LeakWatch carries no advertising tag. The Google Ads tag that was previously present has been removed, along with the advertising cookies it set: nothing on the Service performs cross-site tracking or ad personalisation.

Your choice. Analytics cookies are only set after you accept them through the banner shown on your first visit. Until you accept, PostHog is not loaded — its script is not even downloaded. You can change your decision at any time:

LeakWatch does not sell any personal data. Apart from the analytics measurement described above, which is subject to your consent, no third-party tracker is present on the Service.

7. Security

Detected secrets are never displayed in full in the interface (only a truncated preview is visible). Exchanges with the Service are encrypted (HTTPS). Access to data is restricted to the processing strictly necessary for the Service to operate.

8. Your rights

Under the GDPR, you have a right of access, rectification, erasure, restriction, objection and portability of your data, as well as the right to withdraw your consent at any time — in particular for email notifications, from your settings, and for cookies, using the button in section 6. You can exercise these rights by writing to [email protected]. You also have the right to lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr), if you consider that your rights are not being respected.

9. Account deletion

You may request the deletion of your account and the associated data at any time by contacting me. Deletion ends any current subscription with no refund for the period already billed (see the Terms and Conditions).

10. Changes to this policy

This privacy policy may be updated to reflect changes to the Service or to applicable regulations. Any substantial change will be notified to you by email or through the Service before it takes effect.