Privacy

Addresses you test

When a tool asks our server to examine a site or a domain, we use the address for that one check and don’t write it to a database. Like any web server, ours keeps short-lived access logs (IP address, time, page requested) for security and capacity planning.

Things that never reach us

Tools marked as running in your browser do their work on your device. That covers passwords, photos, PDFs, pasted emails, address lists and QR codes. None of it is uploaded.

Rate limiting

To stop abuse, the server counts checks per connection per hour. The count is tied to a one-way fingerprint of the IP address, kept for two hours at most, then deleted.

Visit counting

If you say yes in the consent box, Google Analytics counts page views using cookies named _ga. If you say no, or ignore the box, it never loads. You can change your mind whenever you like with the “Cookie settings” link at the bottom of every page.

Outside services

A few checks query public services on your behalf: Google Safe Browsing and the Chrome UX Report, certificate transparency logs, public DNS resolvers, spam blocklists, and the Have I Been Pwned range API (which receives only the first five characters of a hash, never the password). These services see our server, not you.