JOESCAN
JOETECH / YOUR DATA

Your privacy.
Clearly explained.

What JoeScan processes, what stays on your device, and how to manage your information.

PRIVACY & DATA · UPDATED SEPTEMBER 6, 2026

Privacy begins with clarity.

JoeScan is a product of JoeTech. This page describes data handling in the current product, including its scan tools and optional features.

PASSWORD CHECKS

Your password stays private.

The password checker processes the password in your browser. Only the first five characters of its SHA-1 hash are sent to the Pwned Passwords range service. Saved password scans use a generic label rather than the password.

SAVED RESULTS

Scan history is stored.

When signed in, completed scans may be saved with your account. Other than password values, this can include the target you entered and the resulting report.

What is stored, and where?

DataLocation and purpose
Account & profileFirebase Authentication and Firestore hold account details such as your email, display name, profile image, preferences, and academy progress.
Scan historyFirestore stores scan targets and reports associated with your account. Password scans use “Password check” as the target.
Browser preferences & chatsBrowser storage retains language, theme, and scan-attempt timestamps. Assistant conversations remain in page memory and are cleared on reload or account change.
Personal API settingsKeys you enter stay in memory for the signed-in session and are cleared on reload or sign-out. Using a key sends it to the relevant provider or through the configured request path; local storage does not mean the key is never transmitted.
Optional featuresWatchlists, team settings, support requests, activity records, and webhook configuration may store additional information when used. Enabled webhooks can send scan summaries to your configured destination.

Firebase manages authentication and supported two-factor enrollment. Firebase App Check uses reCAPTCHA for abuse protection. Hosting and service providers also process connection information, such as IP addresses, to deliver requests.

When data leaves your browser

Not every check is local. Depending on the tool and settings you use, inputs are sent to external services:

  • Email checks: the email address is sent to XposedOrNot; the domain is queried through Google DNS. Optional report translation may send report text to a model provider. Email scans also send your email through our server to LeakCheck Public API. Returned source metadata is combined with XposedOrNot results and stored in your scan history, including provider status. Reports and exports can include this combined metadata. Providers apply their own retention policies.
  • Password checks: a five-character hash prefix is sent to the Have I Been Pwned Pwned Passwords range API, not the password itself.
  • Link, domain, and IP checks: hostnames or IP addresses are sent to services such as URLhaus, Google DNS, RDAP registries, and geolocation providers.
  • Device checks: public IP discovery and exposure lookups may use ipify and Shodan InternetDB.
  • AI and OSINT tools: submitted prompts, targets, or report details may reach the selected providers and public sources needed for the request.

These providers have their own privacy policies and retention practices. Avoid submitting confidential information that a check does not need.

Keeping and deleting data

Scan history: saved results remain until deleted. There is currently no automatic expiry period for scan history. Use the History page to remove results.

Browser data: preferences remain until cleared; chat history is not persisted. Clearing browser data does not delete cloud records.

Account deletion: the account-delete control requires recent sign-in, blocks further account use, and removes owned scans, watchlists, API key records, profiles, support records, username mappings, invitations and related application records before removing the authentication account. If interrupted, retry to resume. A minimal deletion-status record is retained to prevent stale sessions from recreating data.

Deletion timing: cleanup runs in batches during your deletion request. Backups, provider logs, externally delivered webhooks and reports you downloaded are not removed by this operation; contact JoeTech for requests involving those copies.

YOUR QUESTIONS, ANSWERED

Contact JoeTech about your data.

To request access, correction, or deletion, email us or use the in-app support system. Include enough information to identify your account, but never send your password or API keys.

joetech.dev.systems@gmail.com ↗

This policy may change as the product evolves. The update date is shown at the top of this page.

Back to JoeScan →