Privacy Policy
Effective July 26, 2026 · last updated July 26, 2026
This policy covers recentbreaches.com only. It is deliberately specific: it describes what this site actually collects, which is much less than a site with user accounts. Recent Breaches has no accounts and no logins. If you hold a GalaxyWarden account, the GalaxyWarden Privacy Policy covers that account and everything we process for it.
1. Who we are
BATECH LLC operates recentbreaches.com, at 3154 Glendale Blvd #1234, Los Angeles, CA 90039-1830, United States. “Recent Breaches”, “GalaxyWarden” and “DoxxScan™” are trade names of BATECH LLC. In this document “we”, “us” and “our” mean BATECH LLC, and “the Site” means recentbreaches.com and the feeds, APIs and embeddable widgets we publish from it.
BATECH LLC is the “controller” of the personal data described here under the GDPR/UK GDPR, and the “business” under the CCPA as amended by the CPRA. Questions, requests and complaints: press@recentbreaches.com.
2. What we collect
Reading this site does not require you to give us anything. In total we collect:
- Newsletter email address — only if you subscribe. We store the address, the consent wording and version you agreed to, the time you agreed, whether you ticked the optional partner-marketing box, and which page you subscribed from. We keep the consent record because GDPR requires us to be able to prove consent.
- Server and CDN logs — IP address, user agent, referring page, requested URL, timestamp, and response status. Generated automatically by our host and by Cloudflare for delivery, security, abuse prevention and debugging.
- Product analytics — if you consent. PostHog records page views, clicks, performance metrics and a pseudonymous device identifier, and may capture a masked session replay. Text inputs are masked.
- Advertising data — if you consent. Google AdSense and its associated domains set cookies and read device and IP data to select and measure ads.
- Embed telemetry — when one of our widgets or API endpoints is called from another site we record the referring domain and a request count, so we can see where our widgets are used. That is about the embedding site, not about you.
We do not ask you to enter, and this site does not collect, your name, address, phone number, date of birth, government identifiers, payment details or passwords. We do not run a breach lookup on this host — the free exposure scan lives on galaxywarden.com and is covered by that site’s policy.
The breach records we publish are about organisations and about incidents reported in public sources. They are not derived from anything you give us.
3. Why we use it, and our legal bases
- To send the newsletter — consent (GDPR Art. 6(1)(a)). Withdraw it at any time via the unsubscribe link in any email.
- To serve, secure and debug the site — legitimate interests (Art. 6(1)(f)) in keeping a free public site available and free of abuse.
- Analytics and advertising — consent (Art. 6(1)(a)), and consent under the ePrivacy Directive for the cookies and similar technologies themselves. Nothing optional loads before you choose.
- To comply with law and to establish or defend legal claims — legal obligation and legitimate interests.
4. Cookies, analytics and advertising
Full detail is in the Cookie Policy. In short: strictly necessary cookies (set by Cloudflare and by our own consent record) always run; analytics and advertising tags do not load at all until you consent, where consent is required. You can change or withdraw your choice at any time via Cookie settings in the footer.
Where we cannot confidently determine that you are outside the EEA, UK or Switzerland, we show the consent banner and treat consent as required. That is deliberate: we would rather ask an American reader an unnecessary question than drop an advertising cookie on a European one without permission.
5. Who we share it with
We do not sell your personal information for money. We use a small number of providers, and this is the complete list for this site:
- Cloudflare — CDN, DNS, TLS and bot/abuse protection. Sees request metadata including your IP address for every request.
- Render — application and database hosting.
- PostHog — product analytics and masked session replay (consent only).
- Google — AdSense advertising and ad measurement, including the googlesyndication.com and doubleclick.net domains (consent only).
- SendGrid — delivery of the newsletter. Sees the recipient address and message content.
We may also disclose information where we are legally required to, or where it is necessary to investigate abuse or to establish, exercise or defend legal claims. If the business is sold or merged, information may transfer with it; this policy would continue to apply until superseded.
Newsletter subscribers who tick the optional partner box also receive marketing from GalaxyWarden and its vetted partners. Ticking that box is never required and it is never pre-ticked.
6. Retention
- Newsletter records — for as long as you are subscribed. After you unsubscribe we keep a minimal suppression record (your address and the unsubscribe date) so we do not email you again, plus the consent record for up to 3 years as proof of lawful processing.
- Server and CDN logs — typically 30–90 days, longer only where a specific security investigation requires it.
- Analytics — per PostHog’s retention settings, and no longer than 12 months for identified event data.
- Advertising cookies — per Google’s own retention periods, which are described in their policies.
7. International transfers
We are based in the United States and our providers are largely US-based, so data about you is processed in the United States. Where personal data is transferred out of the EEA, the UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) in our contracts with those providers.
8. Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out. You may also complain to your local supervisory authority.
If you are a California resident, you have the right to know what personal information we collect, use, disclose and share; to access it and obtain a copy; to have it deleted; to correct inaccuracies; to opt out of the sale or sharing of personal information and of targeted advertising; to limit the use of sensitive personal information (we do not collect any on this site); and not to be discriminated against for exercising these rights.
Other US state privacy laws — Colorado, Connecticut, Virginia, Utah, Texas and others — give broadly equivalent rights, and we honour requests from residents of those states on the same basis.
How to make a request: email press@recentbreaches.com from the address you want us to act on, and tell us what you want. Because this site has no accounts, the email address you subscribed with is normally the only way we can identify you; if we cannot verify a request we will say so rather than act on the wrong person’s data. We respond within 30 days (45 days for CCPA requests, extendable once where permitted). You may use an authorised agent.
9. Do Not Sell or Share My Personal Information
We do not sell personal information for money, and we never have.
However, Recent Breaches serves Google AdSense. Under the CCPA as amended by the CPRA, letting an advertising partner set cookies and receive identifiers in order to serve cross-context behavioural advertising counts as “sharing” — and may count as a “sale” — even though no money changes hands for your data. We would rather say so plainly than argue the point.
You can opt out right here. Opting out stops advertising and analytics tags from loading on this site and records the choice in a first-party cookie on this device:
Because there are no accounts on this site, the choice is stored per browser. If you clear your cookies, use a different browser, or use a different device, please set it again.
Global Privacy Control. We honour the GPC signal. If your browser or extension sends GPC, we treat it as an opt-out of sale and sharing and we do not load advertising or analytics tags, without you having to click anything.
You can also ask us to record the opt-out against your newsletter subscription by emailing press@recentbreaches.com. Opting out will not degrade the site — you will see the same journalism either way.
10. Children
Recent Breaches is not directed to children. We do not knowingly collect personal information from anyone under 13, and the newsletter is intended for readers aged 16 and over. If you believe a child has given us information, email press@recentbreaches.com and we will delete it.
11. Security
The site is served over HTTPS, fronted by Cloudflare, and hosted on managed infrastructure with encryption at rest. Access to the subscriber table is limited to the people who need it. No system is perfectly secure, and we do not claim otherwise.
12. People and organisations named in our reporting
This section is not about site visitors. Where a page names a person or an organisation as part of our breach reporting, we are processing that information for journalism and in our legitimate interest in reporting on matters of public interest. If you are named and want a correction, a right of reply, or the removal of personal data or a claim we cannot substantiate, write to press@recentbreaches.com. We review promptly — see our editorial standards.
13. Changes to this policy
We will update this policy as the site changes. The effective date at the top always reflects the current version, and material changes will be flagged on the site.
14. Contact
BATECH LLC
3154 Glendale Blvd #1234, Los Angeles, CA 90039-1830, United States
press@recentbreaches.com · support@galaxywarden.com