Malwarebytes Inc.
Malwarebytes has noticeably better specific privacy practices than comparable US security companies — IP addresses are explicitly not stored, the VPN has a detailed and specific no-logs commitment, text messages are scanned without being retained, cloud storage scan files are deleted immediately after scanning, and usage/threat statistics collection can be opted out of in product settings — but it is a US company (Santa Clara, CA) with no named security certifications in its policy, vague retention periods, and a website advertising tracking stack.
No known public data breaches
Malwarebytes does not appear in the Have I Been Pwned database of publicly disclosed data breaches.
Recommended changes