Privacy Policy
Unbreachable.dev - Last updated: 21 July 2026
1. Who We Are
Unbreachable.dev is operated by MXC ENTERPRISES LLC (30 N Gould St, Ste N, Sheridan, WY 82801, USA) in collaboration with BPAGADTI LTD (20 Wenlock Road, London, England, N1 7GU). For the purposes of data protection law, MXC ENTERPRISES LLC is the primary controller of personal data processed through the Service. Contact: support@unbreachable.dev.
2. Information We Collect
- Account information: name, email address and password (stored hashed) when you create an account.
- Payment information: processed by Dodo Payments. We receive limited transaction details (such as the last four digits of your card, amount and status) but never your full card number.
- Scan data: the URLs you submit, technical information about the target application gathered during scans, and the resulting findings and reports.
- Usage data: log data such as IP address, browser type, pages visited and actions taken in the Service.
- Communications: messages you send to our support channels.
3. How We Use Information
- To provide the Service: run scans, generate reports, process payments and manage your account.
- To verify authorization: confirm you own or are authorized to test submitted targets, and investigate suspected misuse.
- To improve the Service: debug, develop features and improve scan accuracy, using aggregated or de-identified data where practicable.
- To communicate with you: service messages, receipts, security notices and (with your consent where required) marketing emails, which you can opt out of at any time.
- To comply with law: respond to lawful requests and enforce our Terms of Service.
Where UK or EU data protection law applies, our legal bases are performance of a contract (providing the Service), legitimate interests (securing and improving the Service, preventing misuse), consent (where required, e.g. marketing), and legal obligation.
4. Scan Data
Scan findings can be sensitive. We treat scan results and reports as confidential, restrict internal access to them, and do not publish information that would enable a third party to identify or exploit a specific vulnerability in your application. We may use anonymized, aggregated statistics derived from scans (for example, the percentage of scanned applications with a given class of issue) for research and marketing.
5. How We Share Information
- Service providers: hosting, infrastructure, analytics and email providers who process data on our behalf under contractual safeguards.
- Payment processing: Dodo Payments, which processes your payment data under its own privacy policy.
- Within the venture: between MXC ENTERPRISES LLC and BPAGADTI LTD as needed to operate the Service, under the confidentiality terms of our collaboration agreement.
- Legal reasons: where required by law, to protect our rights, or to investigate unauthorized scanning or other misuse, which may include disclosure to affected system owners or authorities.
- Business transfers: if the Service or the venture is sold or reorganized, data may transfer to the successor subject to this policy.
We do not sell your personal information.
6. International Transfers
We operate from the United States and the United Kingdom, and our service providers may process data in other countries. Where UK or EU data protection law applies to a transfer, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or standard contractual clauses.
7. Data Retention
We keep account data while your account is active and for a reasonable period afterwards. Scan results and reports are retained so you can access purchased reports; you may ask us to delete them at any time. Payment and transaction records are kept as required for tax and accounting purposes. Log data is retained for a limited period for security and debugging.
8. Security
We apply technical and organizational measures appropriate to the sensitivity of the data we hold, including encryption in transit, access controls and restricted access to scan results. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and any relevant regulator as required by law.
9. Your Rights
Depending on where you live, you may have rights to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your local authority; in some US states, your state attorney general). To exercise any of these rights, email support@unbreachable.dev. We will respond within the timeframe required by applicable law.
10. Cookies
We use essential cookies to operate the Service (such as keeping you signed in) and, where permitted, analytics cookies to understand how the Service is used. Where required by law, we will ask for your consent to non-essential cookies, and you can manage cookies through your browser settings.
11. Children
The Service is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be notified via the Service or by email, and the “Last updated” date above will change.
13. Contact
Privacy questions and rights requests: support@unbreachable.dev, or write to MXC ENTERPRISES LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, USA.