Breach Check

Breach Check is a one-off check of a single email address against known data breaches. It answers one question: has this address been exposed. It is the quickest way to look up an address without setting anything up.

It is separate from continuous monitoring of personal data. Breach Check looks once and reports what it finds; it does not keep watching the address afterward and sends no alerts. To be told about new breaches as they appear, the address needs to be added as a watched item. See Monitoring personal data.

Breach Check is opened with the Breach Check quick action on the You screen.

Running a check

  1. The screen is headed "Breach check" and reads "Check your email for breaches".
  2. Enter an address in the "Email" field. Any address can be checked, not only the one used to sign in.
  3. Tap Scan for breaches. The button stays inactive until the address is complete and valid.
  4. The screen changes to "Checking for breaches..." while the check runs. Cancel stops it and returns to the start.

Reading the result

The result screen is headed "Results".

  • No breaches: a green icon with "All clear" and the line "We haven't found any breach with this email at this moment."
  • Breaches found: a red icon with "We found # breach" or "We found # breaches", followed by the list.

Each row in the list shows a summary of what was exposed, such as email, password, username, address, phone number, or name, together with the breach name, its date, and a severity badge reading Critical, Moderate, or Minor. The most serious findings are listed first.

The rows on this screen cannot be opened. The full details of a breach, meaning what was exposed and the steps to take about it, are part of Kiren Plus. The screen notes this. Adding the address to be watched is what makes those details and future alerts available.

Check another email at the bottom starts a new check. The back arrow does the same.

Recent checks

Earlier checks are listed under "Recent checks" below the input. Each row shows the address, partly hidden, when it was checked, and a badge that is red if that check found breaches and green if it was clear. The list is not shown while a check is running or while a result is on screen, and it does not appear at all before the first check.

Tapping a row does not reopen the old result. It runs the check again for that address and shows a fresh one. Results can change between checks, because new breaches keep being discovered and published.

The three-dot More options menu on a row offers Delete, which removes the entry from the list.

If the check does not complete

A message appears above the button explaining what went wrong. Most of these are temporary and running the check again is enough, for example "The scan took too long. Please try again." when the check timed out, or "The service is busy right now. Please try again." when the service is under load.

A few need something more than a retry. "No internet connection. Try again." means the device has no working connection, which Breach Check needs. "Your session has expired. Please sign in again." means signing in again is needed before the check can run.

A note on the results

A clear result means the address has not been found in the breaches known at the time of the check. It is not a guarantee that it has never been exposed: breaches are often discovered and published long after they happen, and some are never published at all. This is why watching an address continuously is more useful than checking it once.