BreachCheck is designed so that we cannot see your passwords, even if we wanted to. There are no accounts, no servers of ours, no analytics, and no tracking of any kind.
When you check a password:
https://api.pwnedpasswords.com/range/…), with response padding
requested so the reply size reveals nothing.The full password — and even the full hash — never leaves your device. This technique is called k-anonymity, and it is the method HaveIBeenPwned itself recommends for password checking. No cookies, no identifiers, and no user data accompany the request.
Nothing. BreachCheck collects, stores, and transmits zero personal data:
The only network request BreachCheck ever makes is the anonymous 5-character hash-prefix lookup to
api.pwnedpasswords.com when you press "Check for breaches". If the service rate-limits the
request, the extension retries once politely, then tells you to wait — your password is never stored
regardless of the outcome.
Because we collect nothing, there is nothing to retain, share, or delete on our side. Everything the extension stores lives in your browser's local storage and is removed if you uninstall the extension.