Privacy Policy
Last updated: 7 May 2026
1. Who we are
BreachEcho ("we", "us") is a security alerting service operated by an indie developer. We are the data controller for personal data collected through breachecho.com. Our servers are located in Finland.
Contact: [email protected]
2. What we collect and why
2.1 Account data
- Email address - required to create your account and send magic-link login emails (valid 1 hour). Legal basis: performance of contract.
2.2 Channel data
- Telegram: your chat ID and username when you connect Telegram. Legal basis: performance of contract.
- Slack / Discord: your webhook URL. Webhook URLs may grant posting access to your workspace - treat them like passwords. We store them encrypted at rest. Legal basis: performance of contract.
- Email delivery channel: an email address (may differ from your login email). Legal basis: performance of contract.
2.3 Preference data
Stack keywords, minimum severity, per-channel filters, persona selection. Legal basis: performance of contract.
2.4 Usage data
- Alert delivery records: which alerts were sent to which channels, timestamps. Retained 12 months. Legal basis: legitimate interest (service operation and debugging).
- Chat conversations: your questions and our answers, scoped to a specific alert. Retained 24 hours. Deleted immediately on account deletion. Legal basis: performance of contract.
2.5 Technical data
IP addresses are processed by Cloudflare (CDN and Turnstile bot-protection). We do not log IP addresses ourselves. Error reports may include user IDs and stack traces; these are processed by our self-hosted error tracking system and do not leave our infrastructure.
3. Third-party processors
We do not sell personal data. We do not use personal data for advertising.
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Anthropic | Alert enrichment summaries; Chat answers | United States | Standard Contractual Clauses |
| Cloudflare | CDN, Turnstile bot protection | US / EU | Standard Contractual Clauses |
| Resend | Email alert delivery | United States | Data Processing Agreement |
4. Data sent to Anthropic
Alert content (title, summary, tags, severity, source URL) is sent to Anthropic to generate enrichment summaries and Chat answers. Your email address and account details are not sent to Anthropic. Anthropic's privacy policy: https://www.anthropic.com/privacy
5. Retention periods
| Data | Retention |
|---|---|
| Account and preference data | Until account deleted |
| Alert delivery records | 12 months |
| Chat conversations | 24 hours |
6. Your rights under GDPR
You have the right to:
- Access a copy of your personal data
- Correct inaccurate data
- Request deletion of your data (right to erasure)
- Restrict how we process your data
- Receive your data in a portable format
- Object to processing based on legitimate interest
- Lodge a complaint with your national supervisory authority
To exercise any right, email [email protected]. We will respond within 30 days.
7. Cookies
We use one functional cookie (session) and one optional security cookie (remember-me, if you opt in). We do not set tracking or advertising cookies. No cookie consent banner is required because we set no non-essential cookies.
8. Changes
We may update this policy at any time. Continued use of the service constitutes acceptance of the current policy.
9. Contact
This document was last reviewed 7 May 2026. It is not a substitute for legal advice.