Credits

How do credits work?

A search costs 1 credit, however many sources it queries. Searching an email asks several sources at once (up to 55 for the widest kind of value, see the guide below) and it is still one credit. Calling a single source directly, from the API or the API Explorer, is 1 credit per call.

Every account has one balance of credits, topped back up to the daily allowance of its plan every 24 hours. The free plan gives 5 credits a day. A search that no source could answer is refunded.

When you need more each day, take a monthly plan: it raises the daily allowance and is billed every month (see the plans). Credits above the allowance (a promo code, a referral) are never taken away by the refill, and you can cancel a plan whenever you like from your account.

The same balance pays for searches on this site and for calls made with your API key (curl, a script, the API Explorer).

Am I charged when a source is down?

Only if none of the sources could answer. A search is charged 1 credit when it starts; if every source it asked failed on its side (timeout, server error, retired endpoint...), the credit is refunded automatically and the status line says so. As soon as one source answered, even to say it has nothing, the search did its job and stays charged.

The classic /api/<source> endpoints refund their single credit when their source fails and add an X-Credit-Refunded: 1 header to the response.

What if I run out of credits in the middle of a search?

A search needs 1 credit to start. Without one it is refused before any source is queried, so nothing is charged and nothing is half-done: a search that started always finishes.

Can I be warned before I run out?

Yes. Under Account → Low-credit alert you choose the balance that triggers a notice (a fifth of your daily allowance by default, 0 turns it off). You then get a banner in the dashboard and, if your email is verified, one email — and one more if you reach zero. The next daily top-up arms it again. If you run a Personnal Searcher page, its visitors are served from the same balance, so this alert matters there too.

Does repeating a search cost again?

An identical search repeated within 120 seconds replays the stored answer for free — but only if every source answered the first time. If some failed, the search runs again so those sources get another chance.

Searching

What can I search for?

Emails, usernames, IP addresses, phone numbers, domains, hashes, Discord IDs, URLs, UUIDs and names. The guide lists what each one gets you and which sources answer.

How does auto-detect work?

Leave Type on Auto-detect and just paste the value: it looks at the shape (an @ and a domain is an email, four dotted numbers an IP, 17–20 digits a Discord ID, a 32/40/64-character hex string a hash, and so on) and shows what it picked. Pick a type by hand whenever the guess is wrong — a bare john.doe looks like a domain, for instance.

The same rule is available to the API: omit type or send type=auto on /api/search, or ask /api/detect-type?value=… (free, no key needed).

Why was my search refused before it started?

The value is checked against the format of the chosen type before anything is queried: an email needs an @ and a domain, an IP must be a real IPv4/IPv6 address, a Discord ID is 17–20 digits, a domain has no http:// or path, and so on. A refused search costs nothing, and the message says what was expected.

Can I query only some sources?

Through the API, yes: /api/search accepts sources=Snusbase,LeakCheck (source names, as listed by /api/sources) and max_sources=5 to cap the number queried. Only the sources actually queried are charged.

Results

Why do I only see some of the sources?

Each source that found something gets its own section, with its name, how many records it holds and the records themselves as a table (the first ten, then Show more records). A source that has nothing on your value, or that failed, is not shown: the note under the results says how many were left out. A section marked Duplicate holds the same data as a source that already answered, so you can ignore it. The { } button of a section shows the raw response.

The strip at the top sums the search up: how many sources answered, how many records, how many identifiers were found, and how many sources hold a password. The rail on the left lists the sources (click one to see only that source) and, on its other tab, the emails, usernames, IP addresses, phones and Discord IDs found inside the results: click one to keep only the records that contain it; the magnifier searches it.

How do I filter and sort the results?

Once results arrive, a toolbar appears above them. Type a word to keep only the records that contain it (a word that names a source keeps all of that source’s records), or keep only the records that hold a password. Sort the sources by arrival, by most records, by newest leak date (when the source provides one) or by name. Inside a table, click a column title to sort its records, and click a record to open all its fields. Hover a value to copy it, or to search it when it is an email, an IP address, a phone number or a username. Filtering only shows or hides what you already have — it never runs a search or spends a credit.

What is the Correlation panel?

It pulls the identifiers out of the results — emails, public IP addresses, usernames, phone numbers and Discord IDs — and shows them two ways, switched with the Graph and List buttons.

The graph draws each identifier as a dot and joins two dots when they appear in the same record of a result (the same leaked account, the same profile), so a cluster of linked dots is likely one person. The value you searched sits in the centre, in white. A number on a dot is how many sources reported it. A dashed line only means “found by the same search”: no single record holds both. Scroll to zoom, drag the background to pan, drag a dot to move it, and use the expand button to give the graph the whole window. The list groups the same identifiers by kind, with the same source count.

Click a dot (or an identifier in the list) to show only the results that contain it. Search ↗ runs a new search on it (it asks first, because it costs credits) and Add to a case copies the graph, or one dot and what shares a record with it, into one of your cases. Extraction is automatic, so treat what you see as leads to verify, not proof.

What are Cases?

A case is a private workspace for one investigation, in the Cases tab of the dashboard. It is a graph you draw yourself: add items (people, emails, usernames, phones, IP addresses, Discord IDs, domains, addresses, companies, accounts or plain notes), link them and say how they are related, write notes on each one and mark the key ones. Cases cost no credit, you can keep up to 50, and every change is saved as you make it.

The quickest way to add something is the bar above the graph: paste an email, an IP, a phone number, a @username, a domain or a name and press Enter. It works out what it is, and if an item is selected the new one is linked to it (separate several values with ;). Drag the round + handle of a selected item onto another one to link them, or let go on empty space to create a new linked item. Double-click the background to add an item there. You can export a case as an image or as a JSON file.

Work on many items at once: draw a loop around them with the lasso (M), or hold Shift and click or drag. A selection can be moved, deleted, copied and pasted (also into another case), duplicated with Ctrl+D, or grouped into a cluster that folds into one dot. Ctrl+Z and Ctrl+Y undo and redo every step. Right-click an item for its menu, and press ? in a case for every shortcut.

Say how far you trust something: every item and every link has a reliability (unrated, unverified, probable or confirmed) shown as three arcs under an item and as the thickness of a link. What a search adds to a case is rated from how many sources agreed.

Search from an item. Right-click an email, username, phone, IP address, domain, Discord ID or a person and choose Search this…. It asks you first (it costs the same credits as a normal search of that kind), then adds what it finds around the item and links it to it, without duplicating anything already in the case.

Sharing. Open Share in a case. You can invite other Seeleaks accounts by email or username as viewers or editors (editors change everything except who has access; only you can delete the case; a collaborator can leave at any time), and you can create a read-only link that opens the case without an account. A link expires after the time you choose, can be revoked at any moment, follows your edits, and leaves out your notes and description unless you tick the box. Open it yourself while logged out to see exactly what people get.

Nobody else can open a case you did not share. Cases are stored on our servers next to your account, and are deleted with the account's key. You can also send a Correlation or Multi-criteria graph into a case with Add to a case.

How do I export or share results?

Export to JSON, CSV, TXT or PDF from the bar above the results. Share link creates a page anyone can open without an account or credits; it expires after 24 hours, 3 days or 7 days, your choice. Exports always contain every result, whatever filter is active.

Account & API

How do I use the API?

Send your key in the X-API-Key header. Every endpoint, with ready-to-paste code, is on the documentation page.

I lost or leaked my API key.

Regenerate it from Account → Regenerate my API key. The old key stops working immediately, and your dashboard session stays signed in.

What is a Personnal Searcher?

A white-label public search page (/p/your-name) that we set up for a client. The client brands it, picks which fields and sources visitors can use within the grants we gave them, and pays for the searches from their own credits.

Data & privacy

Do you keep what I search for?

The search history we keep for statistics records the kind of search, how many sources were queried and each source's outcome — not the value you typed. What you choose to keep, like Favorites or a share link, is stored until you delete it or the link expires. Usage logs are purged automatically after a set time. The Privacy Policy has the full detail.

How do I ask for my data to be removed?

Use the data removal form. See also the Terms of Use and Global Compliance pages.

Which source for what

Pick what you have in hand. This list is generated from the sources a search really queries: a search asks all the sources below at once, for a single credit.

Email

Breaches, stealer logs, the services an address is registered on and the identities tied to it.

41sources · 1 credit
BreachBase Breach database
BreachDirectory Breach intel
BreachVIP Multi-type breach search
DataHound Email OSINT · Breach lookup · Full breach lookup · Stealer-log search
DataVoid Universal OSINT search, 845+ sources streamed live (1 call per 10 s)
GitHub Profile, repos, orgs, gists, keys, emails
HackCheck Breach checker
Hudson Rock Compromised machines by email
Inf0sec Multi-module (leaks, npd, ip, domain, hlr, cfx)
Instagram Public profile, bio, followers
IntelVault Breach database
LeakCheck Breach search with pagination
LeakOSINT OSINT leaks
LeakSight Breach intel platform (32 types)
Melissa Global data enrichment
Oathnet Breach search · Stealer logs · Stealer victims · Holehe (email -> sites) · GHunt (Google account)
OSINTcat Database search
OSINTKit Multi-category OSINT
People index People and records matching this email
PropertyRadar US property search · Skip-trace
Search Universal search · Deep search · Stealer logs
SeekNow Email verification · Global search · Stealer logs
Seekria Email OSINT · Email breach
SEON Email intelligence · Email verification
Snusbase Global search
StealerLogs Stealer-log search
Wentyn Domain/email extractor