This service never stores the email or domain you submit. They're used only for the duration of the request — sent to the HaveIBeenPwned API (for the email) and looked up via public DNS (for the domain) — then discarded.
Only an anonymous statistic is kept: a hash derived from your IP address (one-way, not reversible), the date, and the number of breaches found — with no way to link it back to the actual email or domain checked. This is used solely to rate-limit abuse (5 checks per hour per IP) and to display the public counter.
No tracking cookies, no account, no data resale.