Free tool · private by design
Is your password leaked?
Check any password against hundreds of millions of leaked credentials from real data breaches — without the password ever leaving your browser.
SHA-1
hashed on your device before anything is sent
5 chars
of the hash are all that leaves your browser
0
passwords stored, logged or seen by us
Frequently asked questions
Is it safe to type my password here?
Yes. The password is hashed on your own device and only the first five characters of that hash are sent to the breach database (Have I Been Pwned’s k-anonymity API). The database returns hundreds of possible matches and your browser does the comparison locally. Neither PrivacyOn nor the database ever sees your password.
My password was found. What should I do first?
Change it on your email account first, since email resets every other login. Then change it anywhere else you reused it, and turn on two-factor authentication. Leaked passwords circulate in “combo lists” alongside your email and often your address and phone, so it’s worth checking what else is exposed.
My password wasn’t found. Am I safe?
Safer, not safe. This checks one password against known breaches. Data brokers and people-search sites publish your home address, phone number, relatives and age without any breach at all — a free exposure scan shows that side.
Where does the breach data come from?
Have I Been Pwned’s Pwned Passwords dataset — hundreds of millions of real passwords from confirmed data breaches, maintained by security researcher Troy Hunt and used by browsers and password managers worldwide.
Passwords are half the picture
People-search sites publish your address, phone and relatives with no breach required. Our free scan checks 25+ of them by name in a couple of minutes.
Run the free exposure scan