Our Global Compliance Commitment

BreachHub is committed to respecting the privacy rights of all users, regardless of their country of residence. We operate under a privacy-first architecture: we collect only the minimum data required to deliver our service, we never store query results, and we never sell or share personal data.

This page outlines how BreachHub aligns with major data protection regulations worldwide. If your jurisdiction is not listed, the same principles apply — minimal collection, no retention of query data, full user rights on request.

GDPR — European Union & EEA (Regulation 2016/679)

Applies to: Users located in EU/EEA member states.

Legal basis (Art. 6): Contract performance (Art. 6(1)(b)) for account and subscription management. Legitimate interest (Art. 6(1)(f)) for rate limiting and abuse prevention. We do not rely on consent for any processing activity.

Data collected: Telegram User ID, UUID, API key, subscription dates. No email, no IP address, no cookies, no query content retained.

Retention: Account data deleted within 48 hours of subscription expiry. Query content never persisted — processed in memory and discarded.

Your rights (Art. 15–22): Access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection, and right not to be subject to automated decision-making.

International transfers: BreachHub routes queries to third-party OSINT providers which may be located outside the EEA. No account data is transferred. Query routing to external providers falls outside our control and no results are retained.

Supervisory authority: You may lodge a complaint with your national supervisory authority or the EDPB — edpb.europa.eu. CNIL (France): cnil.fr. ICO (UK): ico.org.uk.

UK GDPR — United Kingdom

Applies to: Users located in the United Kingdom.

Following Brexit, the UK operates under its own UK GDPR (retained from EU Regulation 2016/679 via the Data Protection Act 2018). BreachHub applies the same standards as EU GDPR for UK users.

Supervisory authority: Information Commissioner's Office (ICO) — ico.org.uk.

CCPA / CPRA — California, USA

Applies to: California residents under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

We do not sell personal information. BreachHub does not sell, rent, or share personal data with third parties for commercial purposes — ever.

Your rights:

  • Right to know what personal information we collect and why
  • Right to delete your personal information
  • Right to opt out of sale — not applicable as we do not sell data
  • Right to non-discrimination for exercising your privacy rights
  • Right to correct inaccurate personal information
  • Right to limit use of sensitive personal information — we do not collect sensitive data as defined by CPRA

To exercise any right, contact us at [email protected] or use the data removal form. We respond within 45 days as required by law.

LGPD — Brazil (Lei Geral de Proteção de Dados)

Applies to: Brazilian users under Federal Law No. 13,709/2018.

Legal basis: Contract performance (Art. 7, VI) for account management. Legitimate interest (Art. 7, IX) for security and abuse prevention.

Your rights (Art. 18):

  • Confirmation of the existence of processing
  • Access to your personal data
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymisation, blocking, or deletion of unnecessary data
  • Data portability
  • Deletion of personal data processed with consent
  • Information on third parties with whom data has been shared
  • Information on the possibility of denying consent and consequences
  • Revocation of consent

Supervisory authority: Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd.

PIPEDA — Canada

Applies to: Canadian users under the Personal Information Protection and Electronic Documents Act.

BreachHub collects personal information only for the identified purpose of delivering OSINT API services. We obtain implicit consent through the act of subscribing, and data is limited to what is strictly necessary.

Your rights: Access to your personal information, the right to challenge its accuracy, and the right to withdraw consent (which will result in account closure). Contact us at [email protected].

Supervisory authority: Office of the Privacy Commissioner of Canada — priv.gc.ca.

PDPA — Singapore

Applies to: Singapore users under the Personal Data Protection Act 2012.

BreachHub collects and uses personal data only for purposes a reasonable person would consider appropriate in the circumstances. We do not transfer personal data to third parties for their own use.

Your rights: Access to and correction of your personal data. Contact us at [email protected].

Supervisory authority: Personal Data Protection Commission — pdpc.gov.sg.

PDPA — Thailand

Applies to: Thai users under the Personal Data Protection Act B.E. 2562 (2019).

Legal basis: Contractual necessity for account and subscription management. We do not process sensitive personal data as defined under Section 26 of the Thai PDPA.

Your rights: Access, rectification, erasure, restriction, data portability, objection, and the right to withdraw consent. Requests responded to within 48 hours.

Supervisory authority: Personal Data Protection Committee (PDPC Thailand).

POPIA — South Africa

Applies to: South African users under the Protection of Personal Information Act, 2013.

BreachHub processes personal information lawfully, minimally, and for the specific purpose of delivering API services. We do not process special categories of personal information.

Your rights: Access to, correction of, and deletion of personal information. Right to object to processing. Right to lodge a complaint.

Supervisory authority: Information Regulator (South Africa) — inforegulator.org.za.

APPI — Japan

Applies to: Japanese users under the Act on Protection of Personal Information.

BreachHub handles personal information with care and uses it solely for the purpose of providing OSINT API access. We do not provide personal information to third parties without user consent, except as required to deliver the service.

Your rights: Disclosure, correction, addition, deletion, and suspension of use of your personal information.

Supervisory authority: Personal Information Protection Commission (PPC Japan) — ppc.go.jp.

Universal Principles — All Jurisdictions

Regardless of jurisdiction, BreachHub applies the following baseline principles to all users worldwide:

  • Minimal collection: Only Telegram User ID, UUID, API key, and subscription dates — nothing else
  • No query storage: Search content and results are never written to disk, never logged
  • No data sales: We do not sell, rent, or monetise personal data under any circumstances
  • No cookies or tracking: No analytics, no advertising networks, no fingerprinting
  • Prompt response: All data subject requests acknowledged within 72 hours, resolved within 48 hours
  • Security: TLS encryption, hashed API keys, access controls, no persistent logs
  • Transparency: This page reflects actual practices — no hidden processing

How to Exercise Your Rights

To submit a data access, correction, deletion, or portability request — regardless of your country — use one of the following:

Please include your Telegram username or UUID so we can locate your account. We will acknowledge your request within 72 hours and resolve it within 48 hours (or the shorter deadline required by your local law).

Updates to This Statement

This Global Compliance Statement is reviewed regularly and updated to reflect changes in applicable law or our practices. The date above reflects the last revision. Continued use of the platform after an update constitutes acknowledgment of the revised statement.