Skip to content
Questions

Common questions

How the check works, what happens to your data, and what the subscription does for you.

How does the check work?

We compare your email address against data from breaches that have become known. These are intrusions at online services where customer data was taken and subsequently made public.

The result is a rating from 0 to 2: nothing found, findings with no passwords involved, or findings where passwords were among the data taken. What counts is always the highest value across all findings, not the value of the most recent one.

What happens to my email address?

It is used for the comparison and is not then stored as one person’s query. No account is created, no profile, and no log entry that ties the check to you.

The result sits in a cache for a few hours, so that the same address is not looked up again on every visit. The key to that cache is a salted hash, not a readable address.

What exactly does level 2 mean?

Level 2 means this: in at least one breach that contains your address, passwords were among the kinds of data affected.

It does not mean that we know your password, or that we know what form it was held in. That detail is simply not part of the public data. Change the password concerned, and every identical one, regardless.

Nothing was found. Am I safe?

You are not in the data sets we evaluated – that is today’s picture and not a guarantee. Breaches come to light continually, often only years after the intrusion, and not every intrusion ever becomes public.

That is exactly what monitoring is for: you check once yourself, and after that the service gets in touch when something changes.

What should I do first after a finding?

Change the password of the service concerned, and change it everywhere else you have used the same password. Reused passwords are the real damage a breach does.

Then turn on two-factor sign-in wherever you can. It protects an account even when the password is known.

What does the subscription do?

It keeps monitoring your addresses after you have checked once. If one of them turns up in a newly disclosed breach, you get an SMS – not another email, which would land in a mailbox that may itself be the one affected.

Plans start at CHF 9.80 per month, billed yearly.

Why does it cost anything?

The one-off check is free and stays free. Monitoring is not: every address you register keeps being compared against newly disclosed breaches, and every alert goes out as an SMS. The underlying data sets are licensed for a fee and the service runs on Swiss infrastructure – both are a running cost, not a one-time one.

The subscription is this service’s only revenue. We do not fund it with advertising and we do not sell data – what we do not store about a check is not something we could sell either. Depending on the plan, third-party services are included as well, and those cost something in their own right.

Why an SMS and not an email?

Because the monitored address is itself what the alert is about. If a mailbox has been compromised, it is the wrong channel for the message that it has been compromised.

So the alert always goes by SMS. In the Guard Platinum plan it also goes by email to the address concerned, so that each person learns directly what affects them rather than through whoever holds the subscription. The SMS stays the channel that does not depend on the mailbox in question.

Can I have my password checked?

Yes, and the check takes place entirely in your browser. Only the first five characters of a check value are sent, and those look the same for many thousands of possible passwords; the comparison itself then happens locally on your device.

Your password does not leave your device, is stored nowhere and is never displayed – neither in full nor in part.

What makes this different from a free breach lookup?

The one-off check itself, not much: it draws on the same public directory of known breaches that the freely available checking pages answer from. Anyone who only wants to know whether an address appears there learns it free of charge in several places, and that is as it should be.

The difference begins afterwards. A directory answers when you ask; here the address stays registered and you receive an SMS as soon as it turns up in a newly disclosed breach – on a channel that does not depend on the very mailbox in question. Operation and data storage are Swiss, the free check is not kept as one person’s query, and the service is funded by the subscription rather than by advertising.

And on passwords, a public directory says only that some were among the affected data. Whether one of them is readable for a particular address is a per-record lookup – that we answer in the protected area, for addresses whose ownership has been confirmed, and nowhere else.

Is the service Swiss?

The application and its database run on Swiss infrastructure, operated by a Swiss company. The data on breaches comes from international sources; that cannot be solved any other way, because breaches are international.

Can I cancel at any time?

Yes. The subscription runs for a year and can be cancelled to the end of the current billing period. Billing is yearly and in advance. With Guard Gold, two of the twelve months are free.

No answer here? The privacy policy sets out in detail how data is handled.