Free tool · private by design

Is your password leaked?

Check any password against hundreds of millions of leaked credentials from real data breaches — without the password ever leaving your browser.

Checked with k-anonymity: your password is hashed on this device and only the first 5 characters of the hash are sent. The password itself never leaves your browser.

SHA-1

hashed on your device before anything is sent

5 chars

of the hash are all that leaves your browser

0

passwords stored, logged or seen by us

Frequently asked questions

Is it safe to type my password here?

Yes. The password is hashed on your own device and only the first five characters of that hash are sent to the breach database (Have I Been Pwned’s k-anonymity API). The database returns hundreds of possible matches and your browser does the comparison locally. Neither PrivacyOn nor the database ever sees your password.

My password was found. What should I do first?

Change it on your email account first, since email resets every other login. Then change it anywhere else you reused it, and turn on two-factor authentication. Leaked passwords circulate in “combo lists” alongside your email and often your address and phone, so it’s worth checking what else is exposed.

My password wasn’t found. Am I safe?

Safer, not safe. This checks one password against known breaches. Data brokers and people-search sites publish your home address, phone number, relatives and age without any breach at all — a free exposure scan shows that side.

Where does the breach data come from?

Have I Been Pwned’s Pwned Passwords dataset — hundreds of millions of real passwords from confirmed data breaches, maintained by security researcher Troy Hunt and used by browsers and password managers worldwide.

Passwords are half the picture

People-search sites publish your address, phone and relatives with no breach required. Our free scan checks 25+ of them by name in a couple of minutes.

Run the free exposure scan