Privacy by design
A checker built around privacy by design
4safer is designed to help without putting users or their data at greater risk. These decisions are built into the product, not just described in an editorial policy.
Analytics and attribution
If you allow analytics, 4safer creates a first-party random identifier and stores only its hash. We record page paths, broad traffic source, campaign parameters, country code, privacy-safe link destinations, and key service events such as a completed search or checkout step.
We do not store full IP addresses, raw searched identifiers, advertising identifiers, or cross-site browsing history in analytics. Declining analytics prevents new tracking and removes the first-party analytics cookie. You can reopen Privacy choices at any time.
Transactional email events
For account access and support messages, our email provider may report delivery, bounce, open, and link-click events. We use these events to diagnose failed delivery, protect account access, and understand whether a requested message reached its recipient.
We do not store magic-link tokens from email events. Query parameters are removed before a clicked destination is saved. Email opens can be affected by privacy features and automated scanners, so they are treated as an operational signal rather than proof that a person read a message.
Legal basis and purpose
We process the minimum personal information needed to provide an account, perform an authorized exposure check, deliver an alert, support a purchase, or respond to a request. We rely on the appropriate legal basis for the relevant country and service flow, including consent or the performance of a service you ask us to provide. This page is not legal advice.
Data minimization
We collect and retain only what is needed to provide the service: account and contact details, authorized identifiers, result metadata, purchase status, and monitoring preferences. We do not ask for current passwords, authentication codes, payment card numbers, passport numbers, or bank credentials in an exposure check.
Removal requests and source records
4safer does not own or control the systems where an original incident occurred, and cannot erase information from an organization's systems, public records, or the original source of an exposure. Removing an account or a result from 4safer does not remove the underlying record from those sources.
If you believe an organization exposed or mishandled your information, contact that company or institution directly and use the privacy or data-protection channel it provides. You may also contact the relevant data-protection authority where your local law allows.
To request deletion of your 4safer account, monitoring settings, or information we control, email privacy@4safer.com from the account email address. We may request enough information to verify the request before acting on it.
The lines we do not cross
We do not sell data
We do not sell, license, or exchange users' personal data with third parties for marketing or enrichment.
Checks require ownership confirmation
Every check begins with an ownership step. Email and domains use technical proof through a link or DNS TXT. Other identifiers require a formal ownership declaration.
We do not store leaked content
We do not store passwords, documents, or exposed credentials. We use metadata only: which source, when, and which categories were affected.
We never display credentials
Even when a breach contains a password, the product never displays it in plain text, masked form, or hash. We show exposure metadata only.
Your rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, information about sharing, or withdrawal of consent. Write to privacy@4safer.com. We will distinguish a request about data we control from a request that must be directed to the organization that originated the record.
