Last updated: August 14, 2026 — version applicable to leakwatch.net
LeakWatch (a sole trader — entreprise individuelle, registration in progress), established at 1 square d'Oslo, France, is the controller of the data described below. For any question regarding your data, contact [email protected].
Free public scan. Entering a GitHub/GitLab username in the scan tool collects nothing about you: it only queries my database of leaks that have already been publicly detected.
Connected account. When you sign in with OAuth (GitHub or GitLab), I receive from the chosen platform your identifier, your username, your avatar and, if you allow it, your public email. I never receive or store your password, nor the full access tokens of your GitHub/GitLab account.
| Data | Purpose | Retention period |
|---|---|---|
| Provider, OAuth identifier and username | Authentication, linking detected leaks to your account | Account lifetime |
| Avatar (URL) | Interface display | Account lifetime |
| Security alerts in case of a detected leak (can be disabled in settings) | Account lifetime, or until you withdraw your consent | |
| Session cookie (JWT, httpOnly) | Maintaining connection | 12 hours maximum |
| IP address | Rate limiting (anti-abuse), not associated with your account | Not stored in database — processed in memory only |
| Stripe customer ID and subscription ID | Paid subscription management | Subscription lifetime + legal billing period |
Detected leaks. As part of its mission, the Service indexes information made public by third parties on source code platforms (repositories, commits, file excerpts containing secrets). This data is not provided by you: it is collected automatically from resources that are already public. Only the beginning of the detected secret (a few characters) is shown in the interface — never its full value. Leaks classified as irrelevant or resolved are deleted after 15 days; active leaks are retained until they are fixed, for security purposes.
Payment. Payment card data never passes through my servers: it is entered and processed directly by Stripe.
In accordance with Article 6 of the GDPR, these processing activities rest on: performance of the contract (account creation, provision of the Service, subscription billing), my legitimate interest (security, abuse prevention, improvement of the Service), and your consent where it is explicitly required — email notifications, which you can disable at any time in your settings, as well as the analytics cookies described in section 6, which are only set after you accept them.
Your data may be transmitted to the following providers, strictly to the extent necessary to provide the Service:
| Data | Purpose | Retention period |
|---|---|---|
| Stripe | Payment processing and subscription management | According to Stripe's privacy policy |
| GitHub / GitLab | OAuth Authentication | Not applicable — these platforms do not receive data from me |
| AI infrastructure provider (false positive classification) | Automated analysis of detected secrets to reduce false positives | 24h caching on LeakWatch side; not stored by the provider |
| PostHog | Product analytics — only with your consent (see section 6) | According to PostHog's privacy policy |
The artificial intelligence classification engine may run locally (in which case secrets never leave my infrastructure) or through a third-party cloud provider, depending on my technical configuration at the time. When cloud mode is active, an excerpt of the detected secret is transmitted to that provider for classification purposes only, and is not retained by them beyond the processing of the request.
I do not sell or rent your personal data to third parties.
Some of the processors I use (notably Stripe and PostHog) may process data outside the European Union, on the basis of the European Commission's standard contractual clauses or an equivalent adequacy mechanism guaranteeing an appropriate level of protection.
LeakWatch sets two technical cookies, strictly necessary for the Service to work: the session cookie (httpOnly, not accessible from JavaScript), which keeps you signed in for 12 hours, and a companion marker with the same lifetime that only records that a session exists, so that public pages do not query the account API for signed-out visitors. Neither carries an identifier, neither serves any advertising purpose, and neither requires consent.
Analytics. LeakWatch uses PostHog, a product analytics tool, to understand how the Service is used and to improve it. PostHog acts as a processor; its servers are located in the United States, a transfer covered by the framework described in section 5. PostHog sets analytics cookies that allow your browser to be recognised from one visit to the next. The data collected consists of the pages viewed, the actions performed in the interface, the device type and the site your visit came from. No security-related technical data — detected secret, repository content, key value — is sent to this tool. Requests pass through my own domain rather than a third-party domain.
No advertising. LeakWatch carries no advertising tag. The Google Ads tag that was previously present has been removed, along with the advertising cookies it set: nothing on the Service performs cross-site tracking or ad personalisation.
Your choice. Analytics cookies are only set after you accept them through the banner shown on your first visit. Until you accept, PostHog is not loaded — its script is not even downloaded. You can change your decision at any time:
LeakWatch does not sell any personal data. Apart from the analytics measurement described above, which is subject to your consent, no third-party tracker is present on the Service.
Detected secrets are never displayed in full in the interface (only a truncated preview is visible). Exchanges with the Service are encrypted (HTTPS). Access to data is restricted to the processing strictly necessary for the Service to operate.
Under the GDPR, you have a right of access, rectification, erasure, restriction, objection and portability of your data, as well as the right to withdraw your consent at any time — in particular for email notifications, from your settings, and for cookies, using the button in section 6. You can exercise these rights by writing to [email protected]. You also have the right to lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr), if you consider that your rights are not being respected.
You may request the deletion of your account and the associated data at any time by contacting me. Deletion ends any current subscription with no refund for the period already billed (see the Terms and Conditions).
This privacy policy may be updated to reflect changes to the Service or to applicable regulations. Any substantial change will be notified to you by email or through the Service before it takes effect.