Privacy Policy
Draft, pending legal review. Not yet in effect. Placeholders are in [BRACKETS].
Effective date: [DATE]
Uncloaked by Casper's Cloak ("Uncloaked") is operated by [COMPANY LEGAL NAME] ("we", "us"). This policy explains what we collect when you use the Uncloaked website and apps, why, who we share it with, and the choices you have. We try to collect as little as we can, and some features are designed so that we never see your data at all.
The short version
- We check your own email address against known data breaches, and we keep the results so we can show them to you and (with Plus) tell you about new ones.
- Passwords you check and photos you inspect never leave your device. Links you check send us only the site's address, never the rest of the link.
- Your phone's security checkup runs on your phone, and its results stay there. That includes your location (used only so your phone lets the app read your Wi-Fi's security), the devices on your local network, and storage and battery readings.
- We don't sell your personal information, and we don't use it for advertising.
- You can delete your account and your data at any time from your profile, in the app or on the web.
What we collect
Account information. Your name, email address and, if you sign up with one, your phone number. We use them to create your account and to send you sign-in codes.
Sign-in codes. When you sign in, we generate a one-time code and send it to your email or phone. We store the code, when it was requested and the IP address that requested it, so we can check the code and stop abuse. We delete these records 24 hours after the code is created.
Your breach results. When you verify an email address, we check it against breach data from Have I Been Pwned (see below). We store which known breaches include your email, what kinds of data each exposed, when we found them and what you've marked as resolved or dismissed.
Subscription records. If you subscribe, we store the store's transaction identifier, product, status and renewal dates so we know what you're entitled to. We never receive your card details. Payment is handled by Apple, Google or our payment processor.
Device information for notifications. If you allow notifications in our apps, we store a device identifier, the notification token your phone gives us and the platform (iOS or Android), so we can send you alerts.
Sessions and security logs. To keep you signed in, we store a session record with your IP address and browser details. Our servers keep technical logs, which may include IP addresses and email addresses entered at sign-in, for security and troubleshooting. Logs are deleted after 14 days.
What never reaches us
- Password check: the password is converted into a hash on your device, and only the first five characters of that hash are sent to the Pwned Passwords service. Neither we nor that service can tell which password you checked.
- Photo privacy: your photo is read and cleaned entirely on your device. It is never uploaded.
- Link check: only the website's address (for example
example.com) is sent to our server to compare against our threat list. The rest of the link, which can contain personal details, stays on your device. - Device security checkup (apps): the scan runs on your phone and its results, history and "changes since last scan" are stored only on your phone. We never receive them.
- Location: if you allow it, the app uses your location only because iOS and Android require location permission before an app can read your current Wi-Fi network's name and security type. The app doesn't record, store or send your location, and it uses the Wi-Fi name only on your phone (for example, to tell you when you've joined a new network).
- Local network: if you allow it, the app looks for devices that announce themselves on your Wi-Fi (such as printers, TVs and speakers). What it finds stays on your phone.
- Device health: storage, battery, temperature and similar readings are read on your phone and stay there.
- Security update check: to tell you whether your phone is missing security fixes, the app sends us only your operating system version, phone model identifier (for example
iPhone17,1) or Android security patch level. This lookup doesn't include your account and isn't stored with anything about you. - Connection check: to show you what websites can see, the app and the website ask our server which IP address and network your connection comes from. We send that back to you and don't store it.
Who we share information with
We share only what each service needs to do its job:
- Have I Been Pwned receives your verified email address, to look up which known breaches include it.
- [EMAIL PROVIDER] receives your email address and the message, to deliver sign-in codes and alerts.
- [SMS PROVIDER] receives your phone number and the message, to deliver sign-in codes by text if you use a phone number.
- Apple and Google receive purchase and notification details, to process subscriptions and deliver notifications.
- [HOSTING PROVIDER] hosts our servers and so holds the data we store.
We may also disclose information if the law requires it, or to protect the rights and safety of our users or others. If Uncloaked is sold or merged, your information may transfer to the new owner under this policy.
Creating your Casper's Cloak account (only if you ask)
If you tap Create my Casper's Cloak account, we send your verified email address to Casper's Cloak, our VPN service, so it can create your account. We record when you asked. If you already have an account there, nothing changes. Casper's Cloak's own privacy policy applies to that account. We don't share anything with Casper's Cloak unless you tap that button.
How long we keep it
- Account, breach results and subscription records: until you delete your account.
- Sign-in codes: 24 hours.
- Server logs: 14 days.
- Backups: our database backups are kept for up to [BACKUP RETENTION, e.g. 6 months], after which deleted data is gone from them too.
Your choices and rights
- Delete your account: go to your profile and choose Delete account. We'll email you a code to confirm. This removes your account, breach results, monitored emails and notification tokens. If you subscribed through the App Store or Google Play, cancel the subscription there as well; deleting your account can't cancel it for you.
- Access or correct your information: most of it is visible and editable in your profile. For anything else, contact us.
- Notifications: you can turn off notifications in your device settings at any time.
- Depending on where you live (for example California, under the CCPA/CPRA, or the EU/UK, under the GDPR), you may have additional rights to access, correct, delete or port your information, and to object to certain processing. Contact us to exercise them. We won't treat you differently for doing so.
Security
We encrypt data in transit, restrict access to our servers and verify every sign-in with a one-time code. No service is perfectly secure, so we can't promise absolute security, but we work to protect your information and will notify you as the law requires if a breach affects it.
Children
Uncloaked isn't directed to children under 13 (or under 16 in the EU/UK), and we don't knowingly collect their information. If you believe a child has given us information, contact us and we'll delete it.
Changes
If we change this policy, we'll update the effective date above. If a change materially affects how we use your information, we'll tell you in the app or by email before it takes effect.
Contact
[COMPANY LEGAL NAME] [MAILING ADDRESS] [CONTACT EMAIL]
Breach data is provided by Have I Been Pwned.