Privacy
Collect, display, discard
| Data | Where | What happens |
|---|---|---|
| Public IP address | Server | Used to answer the request. Kept only in short-lived cache keys and rate-limit counters; not written to logs. |
| IP intelligence (location, ASN, ISP) | Server | Cached by IP for up to 6 hours to avoid repeated lookups. Contains no browser or request data. |
| Request headers | Server | Reflected back to you from an allowlist. Cookies and authorization headers are never shown or stored. |
| Browser fingerprint, canvas, WebGL, audio, fonts | Your browser | Computed and displayed locally. Never uploaded during a normal visit. |
| Last test summary | Your browser | Kept in localStorage for the Test again comparison. Clear it from the comparison panel or your browser settings. |
| Tab session ID | Your browser | Random value in sessionStorage, discarded when the tab closes. Never sent. |
| Cookies | Your browser | None on the public site. Signing in to the console sets a session cookie. |
Share results
Share results creates a text summary with a partially masked IP and hands it to your device’s share sheet or clipboard. Nothing is stored on the server. If saved report links are added in future, a snapshot will only be stored when you explicitly create one, it will expire automatically (default 7 days), and it will never contain proxy credentials.
Verification product
Sites that integrate our verification script send a browser fingerprint and receive your IP and network details on their own backend, through a short-lived encrypted token. We do not store those results; the integrating site does, under its own privacy policy. For console accounts we store your name, email, sign-in method, sessions, projects, hashed API keys, allowed origins and daily usage counts.
Logs
Server logs are structured and record the request path, status, timing and a random request ID. Passwords, tokens, cookies, authorization headers and proxy credentials are redacted before anything is written.
Third parties
IP intelligence is resolved from locally hosted databases by default, so your IP is not sent to a third-party lookup service. The Tor exit list is downloaded periodically from the Tor Project; your IP is not sent to it. The fingerprinting library’s usage ping is disabled.