Checks run on what you type and give you a result; a password is never transmitted in full and is never stored.
A security tool asks you to hand over exactly the kind of thing you are trying not to hand over. That deserves a straight answer rather than a policy page.
The short version: the tools are built to answer and forget. There is no stored history of your checks, because history is a feature of the account area, and the account area is not open.
What is sent, and what is not
- Links, domains, email addresses and phone numbers are sent to the relevant check so that a result can be returned.
- A password is never sent. Only a partial hash is transmitted for the breach check, which is enough to compare against a database and not enough to reconstruct the password.
- Messages you paste for the scam checker are analysed for their text signals and are not kept as a message history.
- There is no stored list of your checks to sign into, because no account exists for it yet.
Where the results come from
Breach-exposure results come from public and licensed sources — XposedOrNot for email monitoring, Pwned Passwords (operated by Have I Been Pwned) for the password check — and each is credited with the data it supplied. Link, domain and phone checks combine publicly available signals with the patterns described in the reports, and each result lists the reasons it was reached so that you can disagree with it.
Questions people actually ask
- 1Do you keep what I paste? Assume not. Anything that needs memory — history, alerts — belongs to the account area, which is closed.
- 2Does checking a password tell you my password? No. A partial hash is not reversible into a password.
- 3Will you email me? Only if you contact us first; there is no sign-up flow to be added to while accounts are closed.
- 4Are my results shared? Results are returned to you and are not published. Nothing personal appears on any public page.
- 5How do I get something corrected or removed? Contact us; corrections to a described behaviour are more useful than a new feature.
The full statement of how personal data is handled is in the privacy policy, and the limits of what the checks can determine are in the reports. Both are written to be read, not to be survived.
Frequently asked questions
Is my password ever sent anywhere?
No. Only a partial hash of it is transmitted for the breach check. That is sufficient for a comparison and insufficient to recover the password, and the password itself is never stored.
Do I need to create an account to check something?
No. Every check works without signing in, and no account is needed to read a result or its explanation.
Where can I read the full policy?
The privacy policy describes what is collected and why, and the reports state the boundaries of the checks. If something there is unclear, ask and it will be rewritten.
Written by The BaitScan team
Last updated September 16, 2026
Results are automated risk estimates based on public indicators and heuristics.