SHADOW.me — See What The Internet Kept About You

Every signup leaves something behind.

A breach happens. Data gets copied, indexed, traded — and most people never know what remains attached to their identity.

We wanted to make that invisible footprint visible.

Instead of showing users another table of leaked credentials, we built SHADOW.me: an interactive digital shadow that represents what the internet has exposed about an email address.

The idea

The concept was simple:

See your shadow. Face it. Clean it.

A user enters an email and SHADOW.me checks it against two independent breach archives — XposedOrNot and LeakCheck — and scans the open web through Tavily. The results are combined by a deterministic scoring engine that explains exactly why a risk score exists.

No black-box AI decides whether something is dangerous.

If a password was exposed, it contributes a defined amount.
If plaintext data was exposed, it contributes another.
If the breach is recent, that matters too.

Every point has a reason.

The result becomes a living particle organism — your digital shadow. The more exposed information there is, the more complex the shadow becomes. You can then collapse it into a single point: a visual representation of taking control back.

What we learned

The biggest lesson was that security information doesn’t have to look like a security dashboard.

People understand visual systems faster than raw breach tables. Turning abstract metadata into something spatial and interactive made the result easier to understand — and much harder to ignore.

We also learned where AI should not be used.

SHADOW.me deliberately separates facts from interpretation. The scoring engine determines the facts. AI only explains anonymized metadata. The model never receives the user’s email and never decides the underlying risk.

That distinction became one of the core principles of the project.

How we built it

SHADOW.me is built as a modern web application with a real data pipeline:

Email → breach intelligence → cross-check → open-web traces → deterministic scoring → AI interpretation → 3D digital shadow

The visual layer is powered by Three.js / React Three Fiber, including a custom GLSL particle system with roughly 14,000 particles. GSAP and ScrollTrigger drive the cinematic transitions and interaction.

For the data layer, we use XposedOrNot, LeakCheck and Tavily. The scoring engine is deterministic and explainable. Gemma through Ollama Cloud is used only for narrative interpretation.

Privacy was designed into the architecture: the email is hashed for a short-lived in-memory cache, never logged or permanently stored, and only anonymized breach metadata reaches the AI layer.

The hardest part

The challenge wasn’t simply connecting APIs.

It was making security data feel like an experience without compromising trust.

We had to balance three things at once:

  • Accuracy — independent sources and deterministic scoring.
  • Privacy — minimal handling of the user’s actual email.
  • Visual storytelling — turning invisible data into a living 3D object.

The final result is intentionally somewhere between a security tool and a digital art piece.

SHADOW.me doesn’t just tell you that your data is exposed.

It shows you what that exposure looks like.

Built With

Share this project:

Updates

Submission history