Privacy & security

A tool that maps your exposure should handle your data with restraint.

SeQurance searches one email address at a time from a verified account. We keep only what is needed to build your report, explain what leaves our system, and give you control over deletion.

Encrypted saved identifiers Evidence, not identity verdicts No anonymous bulk search Deletion stays in your control

Accountable access

Searches require a verified SeQurance account, run one address at a time, and are never offered as anonymous bulk lookup.

Credentials stay out

Passwords, provider tokens, raw breach rows, cookies and stealer logs do not become part of a SeQurance report.

You control deletion

You can remove an audit and its derived evidence from your dashboard when you no longer want to keep it.

What happens to your data, step by step.

Five visible stages, from the search you start to the result you control.

  1. 01You choose an address

    A verified account chooses one email address. Saved search addresses are encrypted and receive a keyed lookup value for equality checks.

  2. 02Purpose-limited checks run

    Each approved check receives only the lookup form it needs: a domain, a normalized-email hash, an exact username, or—on an eligible paid plan—the normalized email.

  3. 03Results are minimized

    Returned data is filtered to approved evidence fields. Raw pages, raw breach rows, passwords and unrelated personal details are discarded.

  4. 04Evidence becomes your report

    Audit status, evidence, findings and the rule-versioned score are kept. A possible match remains a clue, not an identity verdict.

  5. 05You decide what remains

    Keep the result for comparison or delete the audit and its derived evidence from your dashboard.

What we store

  • Your account and encrypted saved-search email addresses
  • Keyed lookup values and audit status
  • Evidence, findings and rule-versioned scores
  • Approved breach names, service domains, dates and exposed-data categories
  • Approved public-profile fields and the evidence supporting each match

What we never store

  • Passwords or password values returned by a source
  • Provider tokens, cookies or authentication material
  • Raw breach records, breach rows or paste contents
  • Stealer logs, raw profile pages or raw provider responses
  • Discarded profile details such as biographies, contact details, addresses or coordinates
External checks

What leaves SeQurance—and what comes back.

We do not name internal tools here, but we explain the data flow for each kind of check.

Domain and registration checks

Service-domain and registration checks receive only the domain portion of the address. The disposable-domain check downloads a fixed public reference list and does not query the full address.

Public-avatar profile checks

A public-avatar check receives the SHA-256 hash of the normalized searched email. We retain only approved public profile fields and discard the returned hash, location, biography, contact information, payment or wallet data, and gallery content. Loading an external avatar can expose browser and network information to the public profile host.

Paid breach intelligence

Paid breach intelligence is not in the Free plan. On an eligible plan, the approved processor receives the normalized searched email over an encrypted connection. We retain approved breach names, service domains, dates, exposed-data categories and whether password data was present; we discard echoed addresses, raw responses, descriptions, passwords, breach rows and paste contents.

Public-profile discovery

When an exact username or approved public profile link is supplied, discovery checks a fixed set of public endpoints. Approved profile fields may enter the report; biographies, contact details, birthdays, gender, occupation, free-form locations, addresses, coordinates and raw pages are discarded. A matching username or link remains a clue, not proof of ownership.

Safety controls
Designed to keep findings in context.
  • Anonymous and unrestricted bulk searches are not supported.
  • A source failure remains a coverage limitation, never a negative finding.
  • Username and profile matches are clues, not proof of ownership.
  • Audit data is not sold or used for covert monitoring, facial recognition or identity verdicts.
Common questions
Can I remove a search from SeQurance?

Yes. You can delete an audit and its derived evidence from the dashboard.

Does a username match prove it is the same person?

No. A matching username or profile link is a clue, not proof that accounts belong to the same person.

What happens when an external check fails?

The failure is shown as a coverage limitation. It is never treated as proof that an account or risk is absent.

Who can I contact about privacy or misuse?

Email Privacy@sequrance.com for privacy requests or Abuse@sequrance.com to report misuse.

Controller & your choices

SeQurance is responsible for this product and its data handling.

SeQurance is the product owner, engineering owner, and data controller. Contact Privacy@sequrance.com to request access, correction, deletion, restriction, portability, or to object to processing.

The registered address and EU establishment details will be added before public launch. The private-beta notice will be completed with lawful-basis detail, retention schedules and regulator information before worldwide public launch.

Ask about your data before you search.

Private-beta privacy questions go directly to SeQurance.