Last updated: 4 August 2026 — data protection notice under the GDPR

Privacy Policy

1. Controller

RevealMyRisk (the Service) processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable German law.

Herr Godfrey Mwasanje c/o Block Services Stuttgarter Straße 106 70736 Fellbach Deutschland contact@revealmyrisk.com

VAT is charged for customers in Germany and EU consumers; the reverse-charge procedure is available for EU businesses with a valid VAT identification number. Contact for all data protection matters: contact@revealmyrisk.com.

2. Scope

This notice covers the RevealMyRisk website, the trial registration and the access-controlled security portal, including all modules (Domain 360 Intelligence, raw search, monitoring, training and reporting).

3. Purposes and legal bases

Account creation, authentication, the searches you perform and the notifications you request — performance of a contract, Art. 6(1)(b) GDPR.

Billing and bookkeeping — legal obligation, Art. 6(1)(c) GDPR.

Indexing and querying data from publicly accessible breaches and stealer logs and operating our leak intelligence platform — legitimate interest in securing information systems and in detecting and responding to data breaches, Art. 6(1)(f) GDPR and recital 49.

Security logging, device binding, fraud detection and rate limiting — legitimate interest in protecting the Service and its users, Art. 6(1)(f) GDPR.

Any marketing or analytics identifiers (e.g. a campaign code) — consent, Art. 6(1)(a) GDPR. These are only set if you consent; the platform currently operates without analytics or advertising trackers.

4. Data we collect

Identity and account data: username, display name, first and last name where provided, email address, password stored only as a salted hash, account status, validity period and assigned modules.

Billing data: postal address, phone number, country and VAT number for invoices.

Technical and security data: IP addresses at sign-up and login, a non-reversible device fingerprint used to bind a session to one approved device, your account identifier, the type of search you perform (for example email search, domain search or raw search), the target you submit, and audit logs of privileged and unlock operations (timestamp, account identifier and internal record identifier).

Cookies and local storage: strictly necessary authentication session and device-binding storage. Support-chat or campaign identifiers, where used, are limited to 30 days. The interface language is detected from your browser for the current visit and is not stored.

Breach and leak datasets: personal data contained in breaches and stealer logs that were accessible on the internet without our involvement in the original incident. Depending on the source this may include email addresses, usernames, passwords or password hashes and other profile or technical data present in the leaked file.

Special categories of data: we do not seek to index special categories of personal data (such as data revealing health, political opinions, religious or philosophical beliefs, trade-union membership, sexual orientation or sex life) or data relating to criminal convictions and offences. Where we become aware that such data is present in a dataset, we filter, restrict or remove it.

5. Retention

Inactive accounts: deleted after 12 months of inactivity. Trial accounts expire automatically and are removed thereafter.

Server access logs and security or audit logs: kept for up to 12 months to detect incidents and abuse.

Encrypted backups: 12 months.

Invoices and accounting records: 10 years (German commercial and tax law, § 147 AO, § 257 HGB).

Query results are not stored beyond the session; PDF reports are generated locally in your browser.

Breach and leak datasets: raw breach files and stealer logs are kept for as long as they remain relevant to detect and remediate security incidents and as long as they are still technically accessible from their original public sources. When a dataset is no longer relevant or accessible we delete it or reduce it to a minimal index.

6. Processors and recipients

Cloud hosting, database and authentication infrastructure operated on EU infrastructure under a data processing agreement; content delivery, DNS and WAF providers; the contracted breach-intelligence data provider that answers your query; payment providers; and transactional email providers.

Each provider relies on the GDPR Standard Contractual Clauses or the EU-US Data Privacy Framework where processing takes place outside the EEA.

No data is sold, rented or used for advertising or profiling.

7. International transfers

Data may transit through servers of infrastructure, payment, communication or support providers located outside the EEA. These transfers are covered by the Standard Contractual Clauses referenced in each vendor's data processing addendum, together with supplementary technical measures.

8. Security

All connections use TLS. User passwords are salted and hashed. Access is role-based and device-bound, database access is protected by row-level security, connection credentials are stored server-side only and are never transmitted to the browser, and every privileged action is logged.

Leaked credentials contained in indexed datasets may be stored in clear text so that full-text search is possible; access is rate-limited, logged and restricted to authenticated users. You acknowledge this residual risk when using the Service.

9. Responsibility for query content

Where a customer submits identifiers relating to other persons, that customer acts as controller for those queries and warrants that a lawful basis exists. In that constellation the operator acts solely as processor on documented instructions and does not select, review or evaluate the identifiers submitted.

10. Your GDPR rights

You may access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict (Art. 18), port (Art. 20) and object to (Art. 21) the processing of your data, and withdraw consent at any time with effect for the future.

Requests: contact@revealmyrisk.com or the postal address above. We reply within one month. We may require proof of identity before disclosing personal data.

11. Complaints

You can lodge a complaint with a data protection supervisory authority, in particular the authority of your habitual residence or the competent authority for the controller (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, www.baden-wuerttemberg.datenschutz.de).

12. Changes

Material changes to this notice will be announced at least 30 days in advance by email and via an in-app banner.

13. Data from third-party breaches

Most of the personal data we index in our leak datasets does not come directly from you. It comes from breaches and stealer logs that were exposed by third parties without our involvement in the original incident.

Source of the data. We collect this data from sources that were technically accessible on the internet (for example public forums, paste sites, messaging channels or shared links) and from threat intelligence feeds that rely on such sources. We do not hack systems, bypass authentication, break encryption, buy stolen databases or pay for access to closed criminal forums.

Legal basis. Our legal basis is our legitimate interest, and the legitimate interest of our customers, in detecting and responding to data breaches and securing information systems (Art. 6(1)(f) GDPR and recital 49).

Information of affected persons (Art. 14(5)(b) GDPR). Because these datasets may concern very large numbers of people and are often incomplete or hard to link to reliable contact details, informing each affected person individually would be impossible or would involve a disproportionate effort within the meaning of Art. 14(5)(b) GDPR. This public notice therefore serves as the information measure foreseen by that provision.

Your rights. If your personal data appears in our index, you may at any time ask whether we hold data about you, request a copy, ask us to erase it or restrict its use, and object at any time to processing carried out on the basis of legitimate interest (Art. 21 GDPR). We provide an easy and free removal procedure. Requests can be sent to contact@revealmyrisk.com and we answer within one month where possible.

14. No warranty

The intelligence displayed originates from third-party datasets. Absence of a result does not prove that data has not been exposed, and a result does not prove that an account is currently compromised. Findings must be validated before action is taken.

15. How we recognise your device

Access to the portal is bound to the device you sign in from. This is how that recognition works, so you know exactly what is read from your browser.

What is read at sign-in. When you submit the login form, your browser collects a small set of stable technical characteristics: the browser identification string (user agent), your browser language settings, the number of processor cores and the approximate device memory reported by the browser, the screen resolution, colour depth and pixel ratio, your time zone and UTC offset, and the rendering signature of a tiny image drawn invisibly by the browser.

How it is turned into an identifier. These values are combined and hashed with SHA-256 into a single non-reversible character string (for example a1b2c3d4…). Only this hash — the device fingerprint — leaves your browser. The individual characteristics are not transmitted or stored, and the hash cannot be converted back into them.

What is stored. The fingerprint is sent to our server together with your username and password and is stored in our device register, linked to your account, together with an optional label, the registration date and the last login. Administrators can see, approve, revoke or delete these entries.

How it is used. If your account is device-locked, every login compares the incoming fingerprint with the devices registered for your account. An unknown fingerprint is rejected, and a known but not yet approved device stays blocked until an administrator approves it. The purpose is solely to prevent shared or stolen credentials being used from another machine.

What we do not use. We do not use tracking cookies, advertising identifiers, IP-based recognition or any software installed on your device to identify it, and the fingerprint is never used for advertising, profiling or cross-site tracking. Legal basis: performance of the contract and our legitimate interest in securing accounts (Art. 6(1)(b) and (f) GDPR). Fingerprints are deleted when the device is removed or the account is deleted; you can ask us to reset your device binding at contact@revealmyrisk.com.