Preview Tombstone is in private preview: Gmail sign-in only works for approved test accounts. Send a message to join the waitlist and we'll add your email.
Tombstone
FAQ

Common questions

Can Tombstone read my emails? +

No. Tombstone connects with Google's gmail.metadata permission, the narrowest read scope: it exposes sender, subject, and date headers but not message bodies or attachments. Reading bodies isn't just something we choose not to do; the permission itself can't return them.

What is a zombie account? +

A service that hasn't emailed you in over six months. You've likely stopped using it, but it still holds your personal data: name, email, and sometimes payment details. Every dormant account is breach surface you don't need.

What's the difference between Quick scan and Deep scan? +

Quick scan reads your most recent ~5,000 emails: fast, and enough to surface the services you actively use. Deep scan walks your entire inbox for the full history. Either way you watch live progress, and you can stop at any time, keeping whatever was found so far.

Where does the breach data come from? +

LeakCheck's public API identifies which breach corpuses contain your email, and HaveIBeenPwned's catalog maps each breach to the exact data classes exposed (passwords, addresses, and so on). Your email is only checked with your explicit consent.

Does Tombstone delete accounts automatically? +

Never. Deletion requests are generated as drafts that cite the relevant law (CCPA Section 1798.105 or GDPR Article 17). Nothing is sent until you review the letter and give explicit approval, and that consent is timestamped and audited.

What happens to my Google access when I log out? +

Logout revokes the OAuth token with Google itself, not just your session, and wipes the encrypted token from our database. Reconnecting requires going through Google's consent screen again.