How to choose a leak-check bot
A legitimate breach-check bot only ever needs an email address or phone number to search against known leak databases — it should never ask you to type your actual password into the chat. Reputable checkers (the model here is services like Have I Been Pwned) either check a hashed version of the password locally or don't ask for a password at all; a bot requesting your real password 'to check if it leaked' is itself a security risk, full stop.
What to check before trusting a bot
Check what the bot does after the query: does it claim to store your email/phone for future alerts (reasonable, if disclosed), or is it silent about data retention entirely? If your data does show up as breached, the practical next step is always the same regardless of which bot told you — change the password on that account and anywhere you reused it, and enable two-factor authentication where available. The bot is a warning system, not a fix.
Free vs paid
A basic single-address check is free on nearly every leak-check bot. Paid tiers usually add continuous monitoring (an alert if your email appears in a new breach later) and checking multiple addresses/phone numbers at once. For a one-time check before signing up somewhere important, free is enough; if you manage several accounts or a small team's addresses, ongoing paid monitoring catches new leaks you wouldn't think to check manually.