Pixelvault Labs · Privacy Policies

BreachCheck — Privacy Policy

Publisher: Pixelvault Labs
Last updated: 27 September 2026

The short version

BreachCheck is designed so that we cannot see your passwords, even if we wanted to. There are no accounts, no servers of ours, no analytics, and no tracking of any kind.

How breach checking works (k-anonymity)

When you check a password:

  1. Your password is hashed with SHA-1 on your device, inside the extension.
  2. Only the first 5 characters of that hash are sent to the free HaveIBeenPwned Pwned Passwords API (https://api.pwnedpasswords.com/range/…), with response padding requested so the reply size reveals nothing.
  3. The API returns a list of hash suffixes (about 800 candidates) that share those 5 characters. Your device compares them locally and tells you whether your full hash is among them.

The full password — and even the full hash — never leaves your device. This technique is called k-anonymity, and it is the method HaveIBeenPwned itself recommends for password checking. No cookies, no identifiers, and no user data accompany the request.

What we collect

Nothing. BreachCheck collects, stores, and transmits zero personal data:

Network requests

The only network request BreachCheck ever makes is the anonymous 5-character hash-prefix lookup to api.pwnedpasswords.com when you press "Check for breaches". If the service rate-limits the request, the extension retries once politely, then tells you to wait — your password is never stored regardless of the outcome.

Data retention

Because we collect nothing, there is nothing to retain, share, or delete on our side. Everything the extension stores lives in your browser's local storage and is removed if you uninstall the extension.