Privacy
Scan data is public by design. Scan results, including the URL, resource metadata and a screenshot of the scanned page, appear on public report pages and stay there so trends can be charted over time. That is the product. Do not scan a URL you would not want listed.
Accounts. There are no passwords. Sign-in is handled by Google or GitHub, and we store the name and email address they return, plus which pages you track. Sessions use a single first party cookie and expire after two weeks. Your theme choice lives in your own browser and never reaches us.
Addresses and limits. The network address of a request is used to rate limit anonymous scanning. It is held in memory for at most an hour and is not written to the database. Standard server logs exist for operations and rotate away.
What we do not do. No advertising, no tracking pixels, no analytics scripts, no email sending, and no selling or sharing of data.
Infrastructure and third parties. The service runs on Hetzner (Germany) behind Cloudflare, which terminates HTTPS and therefore processes request metadata. Scanned hostnames are checked against the Green Web Foundation public API to determine green hosting status. Sign-in requests pass through Google or GitHub under their own privacy policies.
Removal. To remove a scan or screenshot of a site you control, or to delete your account and everything attached to it, write to [email protected] and it will be done promptly.