Last updated: 28 July 2026
Contents
Smudge's Cyber Security Club ("we", "us", "our") operates smudgescybersecurityclub.com, a consumer data-protection service that helps people find out what the internet knows about them and, where possible, get it removed. We are the data controller for the personal data described in this policy.
If you have any questions about this policy or how we handle your data, contact us at support@smudgescybersecurityclub.com.
We collect the minimum amount of data needed to run a breach check, deliver a report, or provide the service you've asked for. Depending on which part of the site you use, this can include:
To check whether your data has been exposed, we query specialist breach-intelligence and OSINT providers, including Have I Been Pwned (HIBP), EmailRep, DeHashed, BreachDirectory, Intelligence X (Intelx.io), and Epieos. When you submit an email address for a free or paid check, that address is sent to the relevant provider(s) to be checked; we do not control what those providers do with a lookup request beyond returning a result to us, and we choose reputable providers with their own privacy commitments.
We also use the following processors to run the business:
We rely on the following legal bases:
We keep personal data only for as long as we need it for the purpose it was collected. Lead and order records are generally kept for as long as your account or membership is active, plus a reasonable period afterwards to meet our legal and accounting obligations. You can ask us to delete your data sooner, subject to the exceptions in section 9.
We share personal data with the processors listed in section 3, each of whom is only given the data they need to do their job. We do not sell your personal data. We may disclose data where required by law, to protect our rights, or in connection with a business transfer.
Some of the providers we use (including Stripe, Netlify, Google, and Resend) are based outside the UK, primarily in the United States. Where we transfer personal data internationally, we rely on the providers' standard contractual clauses or equivalent safeguards recognised as providing an adequate level of protection.
We use technical and organisational measures appropriate to the sensitivity of the data we handle, including encrypted connections, restricted access to lead and case data, and working only with reputable third-party processors. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
If you are in the UK or EU, you have the right to:
To exercise any of these rights, email support@smudgescybersecurityclub.com.
Our services are intended for adults. Our education content is designed to be useful to families and, in places, aimed at helping parents teach children about online safety, but our reports, clean-up, and membership services are not directed at children, and we do not knowingly collect personal data from children under 13.
We use only the minimal cookies and local storage needed to make the site work, for example, remembering where you are in the free scan flow. We do not use third-party advertising or tracking cookies.
We may update this policy from time to time. If we make material changes, we'll update the date at the top of this page.
Smudge's Cyber Security Club
Email: support@smudgescybersecurityclub.com