Privacy Policy
Effective July 26, 2026 · last updated July 26, 2026
This policy covers recentbreaches.com only. It is deliberately specific: it describes what this site actually collects, which is much less than a site with user accounts. Recent Breaches has no accounts and no logins. If you hold a GalaxyWarden account, the GalaxyWarden Privacy Policy covers that account and everything we process for it.
1. Who we are
BATECH LLC operates recentbreaches.com, at 3154 Glendale Blvd #1234, Los Angeles, CA 90039-1830, United States. “Recent Breaches”, “GalaxyWarden” and “DoxxScan™” are trade names of BATECH LLC. In this document “we”, “us” and “our” mean BATECH LLC, and “the Site” means recentbreaches.com and the feeds, APIs and embeddable widgets we publish from it.
BATECH LLC is the “controller” of the personal data described here under the GDPR/UK GDPR, and the “business” under the CCPA as amended by the CPRA. Questions, requests and complaints: press@recentbreaches.com.
2. What we collect
Reading this site does not require you to give us anything. In total we collect:
- Newsletter email address — only if you subscribe. We store the address, the consent wording and version you agreed to, the time you agreed, whether you ticked the optional partner-marketing box, and which page you subscribed from. We keep the consent record because GDPR requires us to be able to prove consent.
- Server and CDN logs — IP address, user agent, referring page, requested URL, timestamp, and response status. Generated automatically by our host and by Cloudflare for delivery, security, abuse prevention and debugging.
- Product analytics — if you consent. PostHog records page views, clicks, performance metrics and a pseudonymous device identifier, and may capture a masked session replay. Text inputs are masked.
- Advertising data — if you consent. Google AdSense and its associated domains set cookies and read device and IP data to select and measure ads.
- Embed telemetry — when one of our widgets or API endpoints is called from another site we record the referring domain and a request count, so we can see where our widgets are used. That is about the embedding site, not about you.
- Free breach-check email address — only if you type one into the breach-check box that appears on our breach and guide pages. That box submits to this domain and the lookup runs here (see below). We send the address to Have I Been Pwned to ask which known breaches contain it, and we store the address together with the result of that check, your IP address, the page you came from, any campaign parameters in the link you arrived on, and the time. We keep that record and use it to follow up with you about your result and about GalaxyWarden’s paid products.
- Follow-this-breach email address — only if you ask to be emailed when there is news on a specific breach. Stored with the same consent record as a newsletter signup: the wording and version you agreed to, the time, and the page you asked from.
- Abuse-prevention identifiers — when you use the breach-check box we set one cookie (
gw_fs, about a year) holding a random id with no meaning outside our own rate limits, and we record a one-way hash of what you searched for — never the search itself — so the free-scan limit cannot be reset by clearing cookies or changing networks.
We do not ask you to enter, and this site does not collect, your name, address, phone number, date of birth, government identifiers, payment details or passwords.
A breach lookup does run on this host. The free exposure scan is operated by GalaxyWarden, but its box appears on pages here and, since 1 August 2026, submits to recentbreaches.com rather than to galaxywarden.com. So if you use it, the address you type is received by this site, sent to Have I Been Pwned, and stored as described above. It is stored by GalaxyWarden, and what happens to it afterwards — including any email you receive as a result — is covered by the GalaxyWarden Privacy Policy. Reading this site still requires nothing from you; this applies only if you choose to use that box.
The breach records we publish are about organisations and about incidents reported in public sources. They are not derived from anything you give us.
3. Why we use it, and our legal bases
- To send the newsletter — consent (GDPR Art. 6(1)(a)). Withdraw it at any time via the unsubscribe link in any email.
- To run a breach check you asked for — consent (Art. 6(1)(a)), given by submitting the box. To follow up with you about the result and about our paid products — legitimate interests (Art. 6(1)(f)), or consent where local law requires it. Every such email carries an unsubscribe link, and you can object at any time.
- To serve, secure and debug the site — legitimate interests (Art. 6(1)(f)) in keeping a free public site available and free of abuse, including the free-scan limits described in section 2.
- Analytics and advertising — consent (Art. 6(1)(a)), and consent under the ePrivacy Directive for the cookies and similar technologies themselves. Nothing optional loads before you choose.
- To comply with law and to establish or defend legal claims — legal obligation and legitimate interests.
4. Cookies, analytics and advertising
Full detail is in the Cookie Policy. In short: strictly necessary cookies (set by Cloudflare, by our own consent record, and — only if you use the breach-check box — the gw_fs free-scan limit cookie described in section 2) always run; analytics and advertising tags do not load at all until you consent, where consent is required. You can change or withdraw your choice at any time via Cookie settings in the footer.
Where we cannot confidently determine that you are outside the EEA, UK or Switzerland, we show the consent banner and treat consent as required. That is deliberate: we would rather ask an American reader an unnecessary question than drop an advertising cookie on a European one without permission.
5. Who we share it with
We do not sell your personal information for money. We use a small number of providers, and this is the complete list for this site:
- Cloudflare — CDN, DNS, TLS and bot/abuse protection. Sees request metadata including your IP address for every request.
- Render — application and database hosting.
- PostHog — product analytics and masked session replay (consent only).
- Google — AdSense advertising and ad measurement, including the googlesyndication.com and doubleclick.net domains (consent only).
- SendGrid — delivery of the newsletter. Sees the recipient address and message content.
- Have I Been Pwned — the breach-lookup service behind the breach-check box. Receives the email address you type into that box, and only that address. Not used for anything else, and nothing is sent to it unless you submit the box yourself.
- GalaxyWarden — our own sister service, which operates the breach-check box and holds the address, result and lead record it creates.
We may also disclose information where we are legally required to, or where it is necessary to investigate abuse or to establish, exercise or defend legal claims. If the business is sold or merged, information may transfer with it; this policy would continue to apply until superseded.
Newsletter subscribers who tick the optional partner box also receive marketing from GalaxyWarden and its vetted partners. Ticking that box is never required and it is never pre-ticked.
6. Retention
- Newsletter records — for as long as you are subscribed. After you unsubscribe we keep a minimal suppression record (your address and the unsubscribe date) so we do not email you again, plus the consent record for up to 3 years as proof of lawful processing.
- Server and CDN logs — typically 30–90 days, longer only where a specific security investigation requires it.
- Analytics — per PostHog’s retention settings, and no longer than 12 months for identified event data.
- Advertising cookies — per Google’s own retention periods, which are described in their policies.
- Breach-check and follow-a-breach records — kept until you ask us to delete them. We do not currently expire them on a schedule, and we would rather say so than name a period we do not enforce. Email press@recentbreaches.com and we will delete them.
- Abuse-prevention records — the
gw_fscookie lasts about a year in your browser; the hashed-search records behind the free-scan limit are counted over a rolling 24 hours.
7. International transfers
We are based in the United States and our providers are largely US-based, so data about you is processed in the United States. Where personal data is transferred out of the EEA, the UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) in our contracts with those providers.
8. Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out. You may also complain to your local supervisory authority.
If you are a California resident, you have the right to know what personal information we collect, use, disclose and share; to access it and obtain a copy; to have it deleted; to correct inaccuracies; to opt out of the sale or sharing of personal information and of targeted advertising; to limit the use of sensitive personal information (we do not collect any on this site); and not to be discriminated against for exercising these rights.
Other US state privacy laws — Colorado, Connecticut, Virginia, Utah, Texas and others — give broadly equivalent rights, and we honour requests from residents of those states on the same basis.
How to make a request: email press@recentbreaches.com from the address you want us to act on, and tell us what you want. Because this site has no accounts, the email address you subscribed with is normally the only way we can identify you; if we cannot verify a request we will say so rather than act on the wrong person’s data. We respond within 30 days (45 days for CCPA requests, extendable once where permitted). You may use an authorised agent.
9. Do Not Sell or Share My Personal Information
We do not sell personal information for money, and we never have.
However, Recent Breaches serves Google AdSense. Under the CCPA as amended by the CPRA, letting an advertising partner set cookies and receive identifiers in order to serve cross-context behavioural advertising counts as “sharing” — and may count as a “sale” — even though no money changes hands for your data. We would rather say so plainly than argue the point.
You can opt out right here. Opting out stops advertising and analytics tags from loading on this site and records the choice in a first-party cookie on this device:
Because there are no accounts on this site, the choice is stored per browser. If you clear your cookies, use a different browser, or use a different device, please set it again.
Global Privacy Control. We honour the GPC signal. If your browser or extension sends GPC, we treat it as an opt-out of sale and sharing and we do not load advertising or analytics tags, without you having to click anything.
You can also ask us to record the opt-out against your newsletter subscription by emailing press@recentbreaches.com. Opting out will not degrade the site — you will see the same journalism either way.
10. Children
Recent Breaches is not directed to children. We do not knowingly collect personal information from anyone under 13, and the newsletter is intended for readers aged 16 and over. If you believe a child has given us information, email press@recentbreaches.com and we will delete it.
11. Security
The site is served over HTTPS, fronted by Cloudflare, and hosted on managed infrastructure with encryption at rest. Access to the subscriber table is limited to the people who need it. No system is perfectly secure, and we do not claim otherwise.
12. People and organisations named in our reporting
This section is not about site visitors. Where a page names a person or an organisation as part of our breach reporting, we are processing that information for journalism and in our legitimate interest in reporting on matters of public interest. If you are named and want a correction, a right of reply, or the removal of personal data or a claim we cannot substantiate, write to press@recentbreaches.com. We review promptly — see our editorial standards.
13. Changes to this policy
We will update this policy as the site changes. The effective date at the top always reflects the current version, and material changes will be flagged on the site.
14. Contact
BATECH LLC
3154 Glendale Blvd #1234, Los Angeles, CA 90039-1830, United States
press@recentbreaches.com · support@galaxywarden.com