Skip to content
Legal

Privacy policy

What we store, for how long, and what we deliberately never record.

Draft version. This text has been prepared and is waiting for the operator to approve it. It is not yet legally binding.

The German version is the authoritative one.

Principle

This service handles two of the most sensitive things a person has: their email address and indications about their passwords. We therefore build the service so that it knows as little as possible and keeps it for as short a time as possible.

This statement describes what actually happens. It is written from the technical specification of the system and is changed together with it.

Controller

Company
Innovation care AG
Address
Höhenweg 7
Town
8834 Schindellegi
UID
CHE-303.169.039
Email
support@swisscyberguard.ch

Where the data comes from

There are no other sources. We buy no address lists, enrich nothing and obtain no data about you from third parties.

  • From you: the address you check and, for a subscription, your mobile number and the plan chosen.
  • From the operator of the data-breach database: whether an address appears in breaches that have come to light, and which kinds of data were affected there. We do not maintain that store ourselves and cannot change it.
  • From the payment provider: the status of a payment. Card details do not reach us.

The free check

When you check an email address, it is sent to our server, normalised there and compared against known data breaches. In doing so we create no record that ties the query to a person.

The result is cached for a few hours, so that a rush on the same address does not trigger an external lookup every time. The key to this cache is a hash of the address salted with a secret value, not the address itself: no list of the addresses checked can be recovered from the store.

What is reported back is a level, not the content of a breach. No registration is needed for the check, and no account is created.

If you check someone else’s address

The input field accepts any address, including one that is not yours. By submitting it you confirm that you are authorised to do so.

An address that is not yours is treated exactly as your own is: a single lookup, no personal record, no content from a breach, no disclosure of the result. We record nowhere who entered the address.

We cannot inform the person concerned individually about such a lookup: we would know neither who they are, nor could we establish it without creating precisely the record we deliberately do not keep. The law provides for this case and lets the information fall away where it is impossible or disproportionate.

Anyone who suspects that their address has been checked here can contact us. Our answer will be that we hold nothing about it – and that is not an evasive answer, it is the complete one.

Why we are allowed to do this

A lookup concerns personal data, and Swiss data protection law requires a justification for it where it could affect the personality of the person concerned.

Our justification is the overriding interest of the person concerned in learning that they are affected, together with the restraint of the interference: a single lookup prompted by the person entering the address, no stored record, no content from the breach displayed, no disclosure to third parties, no profiling, no trade in data.

For the same reason, ongoing monitoring – unlike the one-off check – is possible only after the holder of the address has confirmed it themselves. Having an address monitored permanently that is not your own is not possible.

The password check

Checking a password takes place in your browser. Your password does not leave your device, and it reaches neither our server nor any third party.

Only the first five characters of its check value are sent. Those five characters denote a range of many thousands of possible passwords, cannot be attributed to any person, and go to the operator of the password database abroad, see “Where the data is held”. The comparison itself then happens locally on your device.

We store passwords in no form: neither in plain text, nor as a hash, nor truncated. Nor do we ever display a password or any part of one – neither yours nor anyone else’s. That is an undertaking, not merely a property of the current implementation.

What we store for a subscription

A subscription cannot be provided without these details. Every one of them has a purpose:

DetailPurpose
Monitored email addressThe subject of the monitoring and, depending on the plan, delivery of the alert
Mobile numberDelivery of the alert SMS
Status and plan of the subscriptionBilling and entitlement
Reference of the payment providerRecurring billing
Time of your confirmationEvidence of your consent
Log of the alerts sentTraceability and cost control

What we deliberately never store

  • Passwords, in any form – neither in plain text, nor as a hash, nor truncated.
  • Queries from the free check in any form that ties them to a person.
  • Card details or means of payment – these stay with the payment provider.
  • IP addresses beyond what the abuse brake needs in memory for a short time.

Retention

  • Cached check results: six hours, under a salted hash.
  • Counters of the abuse brake: transient, held in memory, they do not survive a restart.
  • Subscription data: for the duration of the subscription. When it ends, whatever does not have to be retained is deleted.
  • Details relevant to accounting: ten years, because the law prescribes that period for business records.
  • Alert log: twelve months, enough for support and cost checks.
  • Send log: ninety days. It records which address a message went to, what kind it was, and whether the relay accepted it – not its subject, not its content, and no link it contains.
  • Log of manual interventions: no fixed period. When someone in operations unblocks an address by hand or resends a confirmation, we record the action, the time, and the reason. It is the one entry we do not delete automatically, because overriding a safety mechanism has to stay explainable afterwards.

Disclosure to third parties

We do not sell data and we run no advertising networks. Only what is needed to provide the service is passed on, and only to the service providers appointed for it:

  • The operator of the data-breach database, for comparing an address that has been checked and for the password check.
  • The SMS provider, for delivering an alert to your mobile number.
  • The operator of the email relay our messages are sent through – confirmations, order receipts and, depending on the plan, alerts to a monitored address.
  • The payment provider Payrexx, for handling the payment. Card details are entered there and do not reach us.
  • The hosting provider on whose Swiss infrastructure the application runs.

Where the data is held

The application, its database and the backups run on Swiss infrastructure. Two processing operations leave Switzerland:

  • The comparison of an address and the password check. The operator of the data-breach database has its registered seat in Australia and runs its infrastructure in the United States. What is sent is the address to be checked, or the first five characters of a check value, never a password.
  • The delivery of the alert SMS. The SMS provider has not yet been determined; the country of its registered seat will be named here before the subscription starts.

Data security

The most effective measure is not to collect in the first place: the greater part of what would be worth protecting here never comes into being. What is needed beyond that we secure with appropriate technical and organisational measures.

Transmission is encrypted throughout. Access to the application and its database is restricted to the people who need it to run the service. Card details do not reach us, and passwords do not exist with us.

Cookies, analytics and server logs

We set no tracking cookies and embed no analytics services, advertising networks or external fonts. The typeface used is delivered from our own server, so that no third party sees your IP address. We use no content delivery network; the page comes directly from our server.

Whatever is stored on your device to run the site can be refused or deleted in your browser at any time. There is no consent banner, because there is nothing for which we would need a consent.

We keep no access log that ties individual page views to a person. Only aggregated counters with no personal reference are collected, such as how many checks were answered from the cache.

If it happens to us

If, despite these precautions, a breach of data security occurs, we report it to the Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible, as soon as it is likely to entail a high risk for the persons concerned. We inform those affected in so far as this is necessary for their protection or the authority requires it.

A service that warns about other people’s data breaches owes that account about itself first.

Your rights

You have the following rights in relation to the operator named above:

  • Information about whether we process data about you, and which. The information is free of charge and is as a rule provided within 30 days; it also covers the origin of the data and the recipients.
  • Correction of inaccurate data, deletion, and the prohibition of a particular processing. Where neither the accuracy nor the inaccuracy can be established, you can require a notation of dispute.
  • Release or transfer of the data you have given us for the subscription, in a common electronic format.
  • Withdrawal of a consent given, with effect for the future, at any time and without giving reasons.

Information about the free check

You can make a request for information about the free check as well, and we will answer it. The right exists regardless of whether anything is stored.

The answer will be that we hold nothing about you that could be tied to a query. That is the purpose of the design and not a side effect of it.

An entry in the underlying data-breach database cannot be removed through us, because we neither maintain that database nor can change it. The operator of the database provides a procedure of its own for that; on request we will tell you how to get there.

If you do not agree with our processing, you can inform the Federal Data Protection and Information Commissioner. The Commissioner opens an investigation of their own motion or upon a report, and tells you what came of it.

Changes

This statement is adapted when the service changes. The version published here at the time is the one that applies.

Version July 2026.