Privacy Policy
Version 1.0 · Effective September 1, 2026
We keep every version of this document. When we make a material change we give 30 days' notice by email and in your account, and the version in force when you agreed stays on record.
1. Who we are
Ascendia Group LLC, a Texas limited liability company doing business as Unleaked, 1401 Lavaca St STE 82078, Austin, TX 78701.
This policy describes how we handle personal data. It is part of our Terms of Service (see Section 13.1 there), and it uses the defined terms from Section 2 of that document — Subject, Finding, Protected Content, Approved Source, Enforcement Action.
Privacy questions go to legal@unleakedhq.com.
2. The short version
Four things do most of the work in this document, and they are unusual enough to state before the detail.
We never download or store media from a Finding. Not images, not video, not from a leak site, not on any plan, not for any feature. From those sources we keep only the HTTP status, response headers, HTML, final URL, and cryptographic hashes. This is a structural property of how the system is built, not a setting — see Section 4.3 of the Terms.
We do not train on your content, and we do not sell it. Not to train, fine-tune, or improve any model; not sold, rented, or licensed to anyone. If that ever changes it changes by asking you, not by amending this policy.
We do not collect biometric identifiers. No facial recognition, no biometric matching, and the avatar shown in your dashboard is not used for matching of any kind.
We run no trackers on any page where your data appears. No analytics tool, no advertising pixel and no session-recording tool on your dashboard, your scan results or your claim link — and that is enforced at the route level rather than by policy. On our public marketing pages — the homepage, pricing, the blog — we use analytics and advertising cookies, set through Google, to see which pages people find useful and to reach people who might want the service. Section 8 describes the cookies we set and says which pages set them.
3. What we collect
3.1 What you give us
Account. Your name, email address, a hashed password, and your timezone. If you enable two-factor authentication we store the TOTP secret and your recovery codes. If you subscribe, a customer identifier from our payment processor.
Subjects. For each name you enroll: the stage name, handle or alias itself, a contact email, your scanning preferences, and the lists you maintain — Approved Sources, whitelisted hosts and URLs, and the accounts you have confirmed as your own.
Rights and authorization records. When you authorize us to act on your behalf, we record which document version you agreed to, its cryptographic hash, when you agreed, the IP address, and the browser user agent. If you later revoke, we record that the same way. See Section 6.
Anything else you send us. Support correspondence, rights documentation, and anything you write to us.
3.2 What we collect automatically
IP addresses, at four specific moments: when you register, when you authorize us to act for a name, when you revoke that authorization, and when you request a scan result by email. We resolve each to coarse network information — the network operator and country — through a lookup service. We do not log IP addresses for general page views.
Browser user agent, recorded alongside those same authorization events and for no other purpose.
Email delivery events. When we send you email we record whether it was delivered, opened, clicked, bounced, or reported as spam, together with the address and which template was sent. Bounces and complaints are what keep us from mailing an address that does not want us; opens and clicks are how we can show a scan-results email actually arrived.
3.3 What the Services generate about you
Findings. For each potential unauthorized copy we record the URL, the host, the page title and snippet, which of your names matched and how confidently, the platform and account handle where identifiable, and the state of the item over time — first seen, last seen, removed, reappeared.
Evidence records. To substantiate a notice and to defend it if challenged, we capture: the HTTP status, response headers, the HTML, the final URL after redirects, the redirect chain, the server's IP address and TLS certificate details, and cryptographic hashes of the body and headers. Media is discarded at capture and never written to storage.
Note that the IP address in an evidence record belongs to the site hosting the material, not to you.
Enforcement records. What we sent, to whom, when, on what legal basis, and what the recipient did about it.
3.4 What we never collect
Biometric identifiers of any kind. Government identity documents, unless a specific host demands the rights holder's own identity and you separately authorize that disclosure. Payment card numbers — those go to our payment processor directly and never touch our systems. Media from any Finding.
4. Where it comes from
Most of it comes from you. The rest comes from:
- Publicly accessible web pages, retrieved during scanning and evidence capture. We access only public material: we do not log into private accounts, pay or bypass paywalls, join closed groups, or circumvent access controls (Terms, Section 4.2).
- Search engines, through our search-data provider.
- An Approved Source you identify, for the single purpose of importing an avatar to display in your dashboard.
- Hosts and platforms, when they respond to a notice.
5. Why we process it, and on what legal basis
| What we do | Why | Basis |
|---|---|---|
| Run your account, scan, file notices | To provide what you signed up for | Performance of a contract |
| Take payment | Same | Performance of a contract |
| Capture and keep evidence | To substantiate a notice and defend it if challenged | Legitimate interests; establishment and defence of legal claims |
| Keep authorization records after deletion | To answer a claim about a notice we sent | Legal claims; legal obligation |
| Security, abuse prevention, audit logging | To keep the Services and their users safe | Legitimate interests |
| Service email | To tell you what we found and what we filed | Performance of a contract |
| Marketing email | Only if you opt in | Consent |
| Analytics and advertising on public marketing pages | To see which pages people find useful, and to reach people who might want the service | Consent |
We do not make decisions producing legal effects about you by automated means alone. Scanning and classification are automated, but no Enforcement Action is transmitted without review and approval by a person (Terms, Section 4.5).
6. Authorization records, and why they outlive your account
A DMCA notice is a sworn statement. When we file one for you, we do it on your written authorization, and if that notice is ever challenged we may need to show what you authorized and when.
So each authorization is recorded as: which grant you made, which version of the Agent Authorization you signed, that document's cryptographic hash, the date and time, the IP address, and the user agent. Revoking does not delete this record — it adds a revocation to it. That is deliberate: erasing the record of what you authorized would destroy the only evidence that the notices already sent were properly authorized, which protects you as much as us.
When you delete your account, a record of who authorized what survives, restricted in access and used only to answer a challenge, an audit, or a legal requirement (Terms, Section 13.4(c)). It holds your name and email, the name you enrolled, the document version you signed, when and from where you signed it, and — for each notice sent under it — the URL that notice concerned.
That record is kept for six years from the last notice it covers, not six years from the day you left — if your last notice went out in 2026 and you close your account in 2029, the record expires in 2032. It is deleted automatically when that date passes.
An account that never had a notice sent on its authority leaves no such record at all.
7. Who we share it with
We do not sell, rent, or license your personal data. We share it in four situations only.
Subprocessors. The companies that process data on our behalf are listed, with what each one receives, at unleakedhq.com/subprocessors.
Recipients of an Enforcement Action. Hosts, registrars, platforms and search engines receive what the process requires: the infringing URL, a reference URL for your work, and our own contact details as your agent. We file as Ascendia Group LLC d/b/a Unleaked. Your legal name does not appear on the notices we send.
Read Section 10.3 of the Terms before relying on that. It is a real protection and it is not anonymity: if a dispute becomes adversarial, your identity as the underlying rights holder can be reached.
Where a host will not accept an agent's identity and demands the rights holder's own, we do not disclose it unless you specifically authorize that host.
Legal process. Where we are required by law, or where disclosure is necessary to establish or defend a legal claim. Where we are not prohibited from telling you, we will.
A business transfer. If the business is acquired or merged, data transfers with it, subject to this policy.
8. Cookies
Functional cookies are set anywhere in the Services, and one of them is set by Cloudflare rather than by us. Analytics and advertising cookies are set only on our public marketing pages, never inside the application.
| Cookie | What it does | Where |
|---|---|---|
unleaked-session |
Keeps you signed in | Anywhere |
XSRF-TOKEN |
Protects forms against cross-site request forgery | Anywhere |
appearance |
Remembers light or dark mode | Anywhere |
sidebar_state |
Remembers whether your dashboard sidebar is open | Anywhere |
__cf_bm |
Set by Cloudflare, which sits in front of the Services, to tell human traffic from bots | Anywhere |
Analytics and advertising cookies, including _ga and _ga_* |
Tell us which pages people find useful, and support advertising and remarketing | Public marketing pages only |
The analytics and advertising cookies are never set once you are signed in, and never on a scan result or a claim link. That is a route-level rule rather than a promise about configuration: the pages that can carry your data do not load the tag at all.
9. How long we keep things
| What | How long |
|---|---|
| Account and Subjects | Until you delete your account |
| Findings | Until you delete your account |
| Evidence records | 730 days from capture |
| Dashboard avatar | Until you delete your account |
| Email delivery events | See below |
| Operator audit log | Indefinitely |
| Enforcement records | Indefinitely — the operational record identifies no one |
| Records of who a notice was for | Six years from the last notice they cover (Section 6), longer under a legal hold |
| Domain intelligence | Indefinitely — it identifies no one (Section 10) |
| Billing records | As long as tax and accounting law requires |
Email delivery events are kept rather than aged out, and the reason is practical: bounce and complaint records are our suppression list. Deleting one would mean resuming mail to an address that has already rejected us, which is both a nuisance to you and the fastest way to ruin a sending domain for everyone else. Delivery, open and click records sit alongside them.
The operator audit log records what our own staff did — the request method, path, route and status, and who did it. It holds no creator content: the paths in it contain only opaque identifiers, never a name, an email or a leak URL.
10. What survives deletion, and why
When you delete your account we delete your account, your Subjects, your Findings, your evidence records, and your avatar. This is a real deletion, not a flag on a row.
Three things remain.
Enforcement records. A notice sent to a third party cannot be recalled, and we may need to show what we sent and on what basis. The operational record of a notice — which domain, which legal basis, what the host did — carries nothing identifying you and is kept indefinitely. It is the record every host statistic is built from, and it names no one.
The record of who a notice was for, as described in Section 6, and only where a notice was actually sent. This one does identify you: it holds your name, the name you enrolled, and the URL the notice concerned. We keep it separately from the record above, behind restricted access, for six years after the last notice.
Domain intelligence. We maintain a knowledge base about hosts and networks — where notices go, who complies, how quickly. It is built from enforcement outcomes and contains nothing identifying you, your Subjects, or your content.
11. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, take it elsewhere in a portable format, object to or restrict certain processing, and withdraw consent where consent is the basis.
Two of these have a self-service path today: you can delete your account from your settings, and you can revoke an authorization for any name without closing your account.
For anything else, write to legal@unleakedhq.com. We will respond within 30 days. We will not charge you or treat you differently for exercising a right.
Deletion has a limit, and it is the one in Section 6. We cannot delete the record of who authorized a notice already sent, what it concerned, or the operational record of the notice itself, for as long as a claim about it remains possible. Where a legal hold applies — because a matter involving your account is live — deletion is refused until the hold is released, and we will tell you that a hold exists if you ask to delete.
California. We do not sell personal information, and we have not in the preceding twelve months. On our public marketing pages we use analytics and advertising cookies; under the CCPA and CPRA some of that activity may constitute "sharing" for cross-context behavioral advertising, and we have shared in that sense in the preceding twelve months only to the extent those marketing-page cookies do so.
Creator data — your Subjects, Findings, evidence and enforcement records — is never sold or shared for any advertising purpose, and never leaves the pages that carry it, because those pages load no advertising or analytics tag at all.
You can opt out with the Do Not Sell or Share My Personal Information link in the footer of any public marketing page, which opens your cookie preferences, or by sending a Global Privacy Control signal, which we honor automatically.
EU and UK. You may complain to your supervisory authority. We would rather you told us first.
12. Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of what we hold. Passwords are hashed. Evidence storage is private and written once. Access to production data is limited, and every action taken by our staff in the admin surfaces is logged.
No system is perfectly secure. If a breach affects your personal data we will notify you as required by law and without undue delay.
13. Children
The Services are for adults. You must be at least 18, with no exception and no parental-consent alternative (Terms, Section 3.1). We do not knowingly collect personal data from anyone under 18. If we learn we have, we delete it.
Separately and absolutely: submitting content depicting anyone under 18 results in immediate termination and whatever reporting obligations attach (Terms, Section 9.1(e)).
14. Acting for someone else
Where you use the Services on behalf of a Represented Individual, you are the controller of that person's data and we act as your processor, on your instruction, under our Data Processing Addendum. You are responsible for making this policy available to them and for holding the authorization Section 7.6 of the Terms requires.
15. Changes
We may revise this policy. For material changes we will notify you by email and in your account at least 30 days before they take effect, and we will post the revised version with a new effective date. Every prior version is retained.
16. Contact
- Privacy and data rights — legal@unleakedhq.com
- General and support — support@unleakedhq.com
- Security disclosure — security@unleakedhq.com
Ascendia Group LLC d/b/a Unleaked 1401 Lavaca St STE 82078 Austin, TX 78701