Privacy Policy
Last updated: September 16, 2026 · Version 2026-09-16
This Privacy Policy explains how Eduardo Airaudo, operating the CheckLeaked service from Uruguay ("CheckLeaked", "we", "us"), processes personal data. It covers our website, APIs (including when accessed through RapidAPI or Apify), bots, SDKs, bulk tools and datasets (the "Service").
It concerns two groups of people: (A) our customers and website visitors, and (B) people whose phone numbers are looked up through the Service, who usually have no relationship with us. Section 3 onwards explains, for each group, what we collect, why, who receives it and what rights they have.
1. Who is responsible
The controller (in Uruguayan law, the "responsable de la base de datos") is Eduardo Airaudo, trading as CheckLeaked, Uruguay. Contact for all privacy matters: [email protected].
Customers who obtain personal data through the Service decide what they do with it and are independent controllers of that data. Our Terms of Service require them to have a lawful basis, and consent where the law requires it, for every lookup.
2. Data about customers and visitors
- Account data: email address, authentication identifiers from sign-in providers (Google, X/Twitter, Discord through Firebase Authentication), password hash (held by Firebase), account preferences.
- Terms acceptance records: which version of the Terms you accepted, when, and the IP address and browser used.
- Subscription and payment data: plan, amounts, transaction and invoice identifiers and the email used at checkout. Card or wallet details are handled by the payment provider (for example PayPal, RapidAPI, Apify or a cryptocurrency processor) and are not stored by us.
- Usage data: phone numbers you look up, the results returned, your search history, API keys, request logs (endpoint, time, status, IP address, user agent), quotas and rate-limit counters.
- Bot data: Telegram or Discord user and chat identifiers when you use our bots.
- Device and website data: IP address, approximate location derived from it, browser and device information, pages viewed, referral and campaign parameters, cookies and similar technologies (see section 11).
- Communications: messages you send us and emails we send you (for example lookup reports you request, quota and key notices).
3. Data about people whose numbers are looked up
When a customer looks up a phone number, or when a number is part of our database, we may collect and store:
- the phone number and data derived from it, such as country, region, carrier and line type;
- whether the number is registered on WhatsApp and the profile information visible under the owner's WhatsApp privacy settings: profile picture, "about" text, business profile details (business name, category, description, address, email, website, opening hours), account type and the number of linked devices, together with earlier versions of the picture and "about" text observed over time;
- information from other public or third-party sources: presence of a Telegram account and its public profile, search engine results, caller-identification and spam-list data, reverse image search results, and for businesses, public reviews and domain registration data;
- information associated with the number in previously published data breaches and leaked datasets and in breach-indexing services — for example a Facebook identifier, first and last name and profile photo from the 2019 Facebook scraping dataset, email addresses, device names and the dates they were observed;
- information inferred automatically from profile pictures by AI models: approximate age range, gender presentation, apparent emotion and apparent ethnicity, and AI-generated reports summarizing the data above. These are estimates, not facts about the person, and are often wrong.
Sources: WhatsApp and Telegram public profile lookups performed by our systems, search engines and other public websites, third-party data and breach-indexing providers, datasets that have been published after data breaches, and lookups submitted by our customers. Lookups do not send any message or notification to the number.
This data can include information about children if a child's profile is public; we have no way to identify them. Parents or guardians can use the opt-out page.
4. Why we use the data and on what legal basis
Customers and visitors
- Providing the Service, managing accounts, billing and support — performance of our contract with you.
- Security, abuse and fraud prevention, rate limiting, enforcing our Terms and keeping records of terms acceptance — our legitimate interests and legal obligations.
- Analytics, measuring advertising and improving the Service — our legitimate interests, or your consent where the law requires consent for cookies (for example in the EEA, UK and Switzerland).
- Service emails about your account, and promotional emails where permitted — contract, legitimate interests or consent. You can ask us to stop promotional emails at any time.
- Complying with the law, tax and accounting duties, and responding to lawful requests — legal obligation.
People whose numbers are looked up
- Answering lookups, bulk checks, searches and exports requested by customers, maintaining our database, and providing dataset copies on plans that include them.
- Producing aggregated statistics (for example by country) that do not identify anyone.
- Detecting and preventing abuse of the Service, and honoring opt-out and deletion requests.
Where the GDPR or a similar law applies, we rely on legitimate interests for this processing — our interest in providing the Service and our customers' interests in verification, fraud prevention and security. You can object to this processing at any time, and we honor objections through the opt-out process in section 9. Where the law requires consent for a specific use by a customer, obtaining it is the customer's responsibility under our Terms.
6. AI and automated processing
Profile pictures are analyzed by third-party AI models to produce the estimates described in section 3, and AI models can produce summaries of the data available about a number. We do not use these outputs to make decisions that have legal or similarly significant effects on anyone, and our Terms prohibit customers from doing so or from using them to target people by sensitive characteristics.
7. International transfers
We and our providers process data in several countries, including countries outside the European Economic Area, the United Kingdom and Uruguay that may not provide an equivalent level of protection. Where the law requires it, we rely on the transfer mechanisms our providers offer, such as standard contractual clauses. Data about looked-up numbers is available to customers worldwide.
8. How long we keep data
- Data about looked-up numbers: for as long as the Service operates, refreshed when a number is looked up again, until the owner opts out or we delete it for another reason. The opted-out number itself is kept on a suppression list so the request keeps being honored.
- Account data: while your account is active and up to 3 years after its last use, unless you ask us to delete it earlier.
- Terms acceptance, payment and invoice records: for as long as needed to prove the agreement and to meet tax and accounting obligations, and until related legal claims are time-barred.
- Request logs and security logs: up to 12 months.
- Your search history: until you delete it or your account is deleted.
Copies that customers have already downloaded, exported or stored are under their control. Our Terms require them to delete data about numbers that opt out when we notify them.
9. Your rights and how to use them
Depending on where you live, you may have the right to access your personal data, correct it, delete it, object to or restrict its processing, receive a portable copy, withdraw consent, opt out of the sale or sharing of personal information and of targeted advertising, limit the use of sensitive personal information, and not be discriminated against for using these rights.
- Phone number owners: use whatsapp.checkleaked.cc/opt-out. After you confirm by email, we delete the profile data we store for the number and block future lookups on our website, APIs, bots and integrations.
- Access, correction, portability or other requests, and requests from customers about their account data: email [email protected]. We may ask for information to confirm the request comes from the person concerned or an authorized agent.
- If we decline a request, you can ask us to reconsider by replying to our answer or writing to [email protected].
We answer within the time limits set by applicable law. You can also complain to a data protection authority — in Uruguay, the Unidad Reguladora y de Control de Datos Personales (URCDP); in the EEA or UK, the authority where you live or work; in California, the California Privacy Protection Agency or the Attorney General.
10. Security
We use encrypted connections (HTTPS) for the website and APIs, restrict administrative access to authorized credentials, and monitor the Service for abuse. No system is completely secure, and we cannot guarantee the security of data. If a breach affects your personal data, we will notify you and the authorities where the law requires it.
12. Children
The Service is not directed to anyone under 18 and we do not knowingly allow them to open accounts. If you believe a child has an account, or that data about a child is in the Service, contact [email protected] or use the opt-out page.
13. Changes to this policy
We will update the date and version at the top when this policy changes, and notify account holders by email or on the website before material changes take effect.
14. Contact
Eduardo Airaudo (CheckLeaked), Uruguay. Email: [email protected].
WhatsApp is a trademark of WhatsApp LLC. CheckLeaked is an independent service and is not affiliated with, endorsed by, or sponsored by WhatsApp LLC or Meta Platforms, Inc.
This policy is written in English. If we provide a translation, the English version prevails.
Що кажуть наші користувачі
Реальні відгуки від наших задоволених клієнтів
Поки що немає відгуків