Last updated: March 1, 2026
WhoExposedMe.com is a free privacy scanner that checks whether your personal information appears on data broker websites and in known data breaches. We built this tool to help people understand and reduce their online exposure.
When you run a scan, you provide:
When you run a scan, we store the name, email address, phone number, and any optional details you provide, along with your scan results (risk score, brokers found, breaches detected), in a secure database. We use this data to:
Your scan results are stored securely and are never shared with third parties. We use industry-standard encryption and access controls.
After scanning, you will receive:
Every email includes a one-click unsubscribe link. Once you unsubscribe, you will receive no further emails from us.
We never sell, rent, or share your email address with third parties. That would be deeply ironic given what we do.
We may use:
You can block these trackers with any standard ad blocker. The scanner works fine without them.
To perform scans, we query:
These queries are made server-side. Your information is sent to these services only as needed to perform the scan and is not stored by us afterward.
WhoExposedMe is an independent service that shows you where your personal information is exposed. We do not remove your data ourselves — removal is performed by the third-party services we recommend.
We recommend third-party privacy and identity-protection services, including Aura and DeleteMe (via the Commission Junction network), and we earn a commission if you sign up through our links. This is how we keep the scanner free. Clicking one of these links does not share your scan data with the provider — it simply passes an anonymous click identifier so the referral can be credited to us. Our recommendations do not change the price you pay.
You can request deletion of any data we hold about you (primarily your email, if you submitted it). Contact us at the email below and we will delete your information within 30 days.
All connections to WhoExposedMe.com are encrypted via HTTPS. We follow security best practices including content security policies, rate limiting, and server-side API key management. No API keys or sensitive credentials are ever exposed in client-side code.
For privacy questions or data deletion requests, email: privacy@whoexposedme.com