How it works · five steps, about thirty seconds

What actually happens when you run a scan

No dashboard to learn and nothing to install. You prove an address is yours, we tell you who is holding your data, and you get a list you can work through.

Checked against the Have I Been Pwned record142 holders tracked, 22 of them UK

You prove the address is yours

We send a six-digit code to the address and you type it back. That is the entire sign-in — there is no password to choose, forget, or have stolen from us. It is also why there is no box for looking up somebody else: the product cannot show you an inbox you cannot open. That rule is written down, with the mechanism behind it.

The code-entry screen: a six-digit code has been sent to a masked address.

We find out who is holding your data

Two different problems, checked at once. Known breaches tell you which companies have already lost your details and exactly what leaked — passwords, addresses, phone numbers. Data brokers are the quieter half: firms that legally buy, package and resell UK personal records to anyone who pays. Every holder we track is published by name.

The published holder register filtered to the United Kingdom, showing 22 of 22 holders with what each one holds, how you come off, and who sends the request.

You get a picture instead of a data dump

A list of sixty breach names tells you nothing you can act on. The report opens with a sentence naming what is actually wrong, then a bar showing how many findings are still exposed and how many have been dealt with. Under that, a breakdown by what is at risk and a plain sentence for each finding explaining what somebody could do with it. If a leaked password is still in use anywhere, that goes to the top.

An example exposure report: three findings, each with what is held and what to do about it.

Then a list you can finish

Every finding becomes one ranked, concrete job — change this password, turn on two-factor here, send this broker a removal request. Highest impact first, and you tick them off as you go, so the work has an end rather than being a permanent background worry.

An example removal tracker: seven holders, three removed, the statutory month running on the rest.

And we watch it for you afterwards

Removal is not permanent. Brokers repurchase and republish, typically within about four months, and new breaches surface constantly. With monitoring on we re-check on a schedule and email you when your address turns up somewhere new — so you find out from us rather than from the news.

The monitoring alert email as it arrives: subject line “your email appeared in 1 new breach”, the breach named with its date, what to do about it, and a link to the full finding.

What the words mean

Every term below is one we use on the pricing page. Tap any of them for why it matters.

They buy the electoral roll, credit-file marketing data, company filings and the rest, join it together, and sell the result to anyone who pays. Nothing was hacked. Your name, address history and phone number are on sale because collecting and selling them is a business, and in the UK you have a legal right to make them stop.

Why we will never let you search for someone else

The same data that shows you your own exposure would show a stalker their target’s. There is no version of a “look up anyone” feature that is safe to build, so we have not built one and we will not — and the one-time code makes that a property of the product rather than a promise about our intentions. The no-lookup promise →

See what is out there about you

Free, thirty seconds, your own address only. No card, no password.

Run my free scan