Dark Monitor
Legal

Privacy Policy

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, how long we retain it, and the rights available to individuals under applicable laws in the EU/UK (GDPR/UK GDPR), United States (CCPA/CPRA and state laws), MENA (including UAE PDPL), and Asian data protection laws (e.g., Singapore PDPA, Japan APPI, India DPDP, China PIPL).

1. Who we are, and our two roles

Dark Monitor is a breach & leak monitoring service operated by PWN-ALL Auditing, Reviewing & Testing Cyber Risks CO. L.L.C (“PWN-ALL”, “we”, “our”, “us”). Our registered address is: 145, Al Mustaqbal street, Iris Bay Tower 2101-11, Business Bay, Dubai, United Arab Emirates. Website: pwn-all.com.

We act in two capacities:

2. The short version

3. Data we collect, and why

3.1 Anonymous breach-check emails (not collected)

When you check an email on the home page, your browser normalizes and cryptographically blinds it before anything is sent. Our server applies its secret key to the blinded value without being able to see the address, and your browser derives the final lookup token locally. We receive and match only that token. A signed-in check is added to your history only when its token matches your verified account email; the stored history contains the token, result (found / not found) and timestamp — never a plaintext address.

3.2 Account emails (individual accounts)

If you subscribe or request a sign-in link, we process the email address you provide, together with account creation time and subscription state, to provision the account, send one-time sign-in (magic link) messages, and provide account features. Sign-in links are stored only as a keyed hash and expire after a short period or on first use.

3.3 Monitoring target (individual accounts)

When a subscriber activates monitoring, we derive an OPRF token from the already-verified account email and store that token as the account’s monitored target. The monitoring endpoint accepts no email address or caller-supplied token. If a monitored token later matches a newly imported breach source, we email an alert to the account address; the alert names the breach source and safe metadata but never contains the token. Pausing monitoring disables future matching while retaining the verified target state until the account is deleted.

3.4 Payments and subscriptions

Paid plans are handled by our payment processor, Stripe. When you start a checkout, we send Stripe the email to bill and receive back a subscription/customer identifier and status. We do not receive or store your card number — card data is handled by Stripe under its own terms and privacy policy. We store the Stripe customer and subscription identifiers, plan, seat count (for organizations), status, and renewal date to determine your entitlement. Stripe notifies us of lifecycle events (payment, renewal, cancellation) via signed webhooks.

3.5 Technical data

3.6 The breach index

When breach datasets are imported, each email address is converted server-side into an OPRF-derived token and the plaintext is discarded. The index stores tokens, the breach source name, description, import date and row count — nothing else. By default, addresses on corporate/organizational domains are skipped; the exception is domains that an organization has verified it controls (section 3.7), whose tokens are indexed so that organization can be alerted about its own employees. We never store the plaintext of any indexed breach address.

3.7 Organization (business) accounts

An organization can create an account, verify one or more domains it controls (by publishing a DNS TXT record we specify), and monitor mailboxes on those verified domains. Here the organization is the controller and we act on its instructions. For an organization account we process:

4. How data leaves our servers

We keep third parties to a minimum. The following receive personal data, each for the limited purpose described:

Web fonts are served from our own servers; we use no third-party font CDN, so no font request discloses your IP address to another party.

Some of these providers (for example, Stripe and our email provider) and the endpoints or identity providers an organization configures may be located outside the United Arab Emirates, so personal data may be transferred across borders. Where such a transfer requires it, we rely on appropriate safeguards: for EU/UK data, EU Standard Contractual Clauses and the UK IDTA/Addendum; transfer mechanisms permitted by the UAE PDPL; and, for personal information of individuals in China, PIPL-compliant mechanisms including separate consent and CAC standard contractual clauses, where applicable.

We disclose data otherwise only when required by law or to protect our rights. We do not sell personal data, and we run no advertising or analytics trackers.

5. Purposes and legal bases

We process the data above to provide the breach-check service, operate individual and organization accounts, process payments, secure the service against abuse, and comply with legal obligations. Where a legal basis is required:

6. What we never do

7. Retention

8. Security

TLS in transit; OPRF blinding so anonymous-checker emails never reach us in readable form; keyed hashing (HMAC-SHA256) for session tokens, sign-in links, API keys, SCIM tokens and IP-derived rate-limit keys; HttpOnly, SameSite cookies with browser-bound SSO login state; proof-of-work and rate limiting against abuse; signed webhook deliveries with strict server-side validation that blocks requests to internal addresses; verified-email enforcement on single sign-on; and server secrets kept in dedicated secret storage with key versioning.

9. Your rights

Depending on where you live, you have some or all of the rights below. Individual-account holders can export their account data or delete their account at any time from the account page; deletion removes your account records and best-effort cancels any active subscription. To exercise any other right, or if you cannot use the self-service tools, write to privacy@pwn-all.com. We verify requests before acting on them and respond within the timeframe required by the applicable law (e.g., one month under GDPR, 45 days under CCPA/CPRA). Note that we cannot link breach-check tokens back to email addresses — by design — so requests can only apply to account data and your own check history.

Employees monitored under an organization account: for that data the organization is the controller. Please direct access, correction, or deletion requests to your organization; we will support it as its processor and will refer individual requests we receive to the relevant organization.

9.1 EU / UK (GDPR / UK GDPR)

Right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection, withdrawal of consent at any time, and the right to lodge a complaint with your supervisory authority (in the EU) or the ICO (in the UK).

9.2 United States (CCPA/CPRA and other state laws)

Right to know/access the personal information we hold about you, right to delete, right to correct, right to data portability, right to opt out of “sale” or “sharing” of personal information (we do not sell or share), right to limit use of sensitive personal information (we do not use it beyond providing the service), and right to non-discrimination for exercising your rights. You may use an authorized agent to submit requests.

9.3 MENA — UAE PDPL

Right to access your personal data and obtain a copy, right to rectification, erasure and restriction, right to object to processing (including for direct marketing — which we do not perform), right to data portability, and the right to complain to the UAE Data Office.

9.4 Asia

10. Cookies and local storage

We use first-party cookies only: a session cookie (lm_session) and, during a single-sign-on login, a short-lived state cookie (dm_sso_state) — both described in section 3.5. We also use one localStorage key (lm_consent) to remember that you dismissed the consent banner. No third-party cookies, no advertising or analytics trackers.

11. Children

The service is not directed at children (under 16 in the EU/UK, under 13 in the US, or the equivalent age of consent in your jurisdiction) and we do not knowingly process their data.

12. Changes

We may update this Policy as the service evolves. The “Last updated” date above always reflects the current version; material changes will be announced on the site.

13. Contact

PWN-ALL Auditing, Reviewing & Testing Cyber Risks CO. L.L.C
145, Al Mustaqbal street, Iris Bay Tower 2101-11, Business Bay, Dubai, United Arab Emirates
https://pwn-all.com
Privacy requests: privacy@pwn-all.com
Corporate inquiries: corp@pwn-all.com