Privacy

BreachBook collects no data about the people who read it.

What this site collects

Nothing. There are no cookies, no analytics, no tracking pixels, no advertising, no embedded video, no web fonts, and no third-party scripts of any kind on any page. There are no accounts and no forms. Nothing on this site asks a reader for information, and nothing records what a reader looked at.

This is enforced, not merely intended. Every page is served with a Content-Security-Policy of default-src 'none', which permits only same-origin styles, images, and the site's own manifest. A tracker added by mistake would be blocked by the browser before it could send anything. The site also ships no executable JavaScript at all: the build fails if a script tag other than a static metadata block reaches a page.

What the server necessarily sees

This site is served as static files by Cloudflare Pages. Like any web server, Cloudflare's edge handles the network request itself and may keep short-lived operational logs, which are subject to Cloudflare's own privacy policy. BreachBook does not add to those logs, does not receive analytics from them, and does not combine them with anything.

What the site publishes

The record itself: breaches disclosed in filings made to government agencies, which name reporting organizations. Every page names an organization, never an individual, and no page identifies any person affected by a breach. Sources and method are set out on the sources page.

Links to other sites

Pages link to government sources, court records, and federal consumer-protection guidance. Those sites set their own terms and are not covered by this policy.

If that ever changes

Alerts by email are a planned feature and do not exist yet. No subscription form is live, and no email address has ever been collected by this site. If that feature ships, it will not launch before this page states exactly what is stored, why, how long it is kept, and how to remove it — and it will require confirmed opt-in before a first message is sent, with a one-click unsubscribe in every message afterwards. Subscriber records would hold an address and delivery preferences and nothing else: no profiling, no enrichment, no sale or sharing.

Your rights

Because no personal information is collected, there is nothing held about a reader to access, correct, delete, or port, and nothing to sell or share — including under the California Consumer Privacy Act as amended by the CPRA. If that ever ceases to be true, this page changes first.

Corrections and contact

To report an error in a published record, see the corrections policy, which sets out how to report one and how corrections are logged.