Privacy notice
HackProof is designed so we do not need an account, email address, mailbox, or stored security profile to help you.
What stays in your browser
Questionnaire answers and the generated action plan are processed in the current browser tab. HackProof does not save them to local storage, place them in a database, or send them to a HackProof server. A downloaded plan is created locally and is controlled by you after download.
Password exposure checks
When you explicitly submit a password, browser Web Crypto creates a SHA-1 hash. Only the first five hexadecimal characters are sent directly from your browser to the Have I Been Pwned Pwned Passwords range API. Your password and full hash are not sent. HackProof requests padded responses, disables browser credentials for that request, and does not check while you type.
Have I Been Pwned is an independent service and may receive ordinary network data such as your IP address and browser headers. Its own privacy policy applies.
Email exposure checks
HackProof does not provide an email input. The email-exposure link opens Have I Been Pwned in a new tab with a no-referrer policy. If you enter an address there, you provide it directly to that service.
Operational logs and analytics
The static hosting provider may process routine request data such as IP address, requested path, browser headers, timestamps, and security signals to deliver and protect the site. HackProof does not intentionally put questionnaire answers, passwords, hash suffixes, email addresses, or message content in URLs or application logs.
The code defines anonymous product events such as “safety check completed,” but this release does not load an analytics tracker. If analytics is enabled later, this notice must be updated before activation and events must remain free of personal or security input.
What we do not collect
We do not request or store mailbox content, OAuth tokens, account credentials, recovery codes, attachments, contact lists, payment details, or the identity of an account associated with a checked password.
Retention and deletion
There is no HackProof account or saved assessment to delete. Reload or close the page to clear the in-tab assessment; delete any plan file you downloaded. Hosting security logs, if created by the provider, follow that provider’s retention controls. See data deletion.
Children and sensitive use
HackProof is not designed to collect information from children. Do not use it to submit another person’s credentials or private data.
Changes and contact boundary
Material privacy changes will be dated here. This release does not provide an email or free-text submission channel because it does not need customer content to work. A monitored privacy-support channel is required before any future feature accepts accounts, identifiers, messages, or uploaded content.