Privacy policy
What this site stores, what it deliberately does not store, and how to have anything of yours removed. Short, because there is not much of it.
The short version
If you browse this site or report a problem, we hold no personal data about you beyond a one-way hash used to stop the same connection reporting a hundred times. If you sign in with Google to comment, we hold your email address, display name and avatar URL, and nothing else.
What is stored, in detail
Everyone
- A session cookie, set only once you do something that needs one - Signing in, or submitting a form that carries a cross-site request token. It is HTTP-only, SameSite=Lax and contains no personal information.
- Standard web server logs for the requests you make, retained short-term for operational and abuse-prevention purposes.
If you report a problem
- Which service, which problem type, and the time.
- The country and region you optionally typed in. This is what you told us; we do not derive location from your IP address.
- A salted SHA-256 hash of your IP address. The address itself is never written to the database. The hash exists only to enforce the rate limit, cannot be reversed, and becomes meaningless if the salt is rotated.
A report is not linked to an account even if you are signed in.
If you use the website checker
- The hostname you checked and the result. Not the path, not the query string.
- A salted hash of your address for rate limiting, deleted after seven days.
The list of recently checked hostnames shown on the checker page is hostnames only, with no association to who checked them.
If you sign in with Google
- Your email address, display name and avatar URL, received from Google's OpenID Connect endpoint.
- A stable Google subject identifier, used to recognise you on return.
- Your comments, votes and the services you have chosen to watch.
We never receive your Google password. We request only the openid, email and profile scopes, we cannot read your mail or contacts, and we cannot post anything anywhere on your behalf.
What is deliberately not stored
- Raw IP addresses in the application database.
- Inferred location from IP geolocation.
- Cross-site tracking identifiers, advertising cookies or fingerprinting of any kind.
- Any third-party analytics that sets cookies. There are no third-party scripts on this site at all.
Who it is shared with
Nobody. We do not sell, rent, trade or share personal data with advertisers, data brokers or partners. The only third party involved in your data is Google, and only if you choose to sign in with it - In which case Google's own privacy policy governs what Google does at its end.
Cookies
One, and only when it is needed: The session cookie described above. There are no analytics cookies, no advertising cookies, and no consent banner, because there is nothing to consent to.
Your rights
If you have an account, you can see everything attached to it on your account settings. To delete your account and every comment on it, email us from the address you signed up with and it is done within seven days. To request a copy of what we hold, ask the same way.
Reports and on-demand checks cannot be attributed back to an individual, so they cannot be selectively deleted on request - There is no way for us to know which were yours, which is rather the point of hashing.
Children
This site is not directed at children and we do not knowingly collect data from anyone under 13. Signing in requires a Google account, which carries its own age requirements.
Changes
If this policy changes materially, the change will be described here rather than buried in a version bump. The review date at the top of this page reflects the last substantive revision.