Privacy & how checks work
What happens when you run a check
Our server resolves public DNS records and may connect to the submitted website, follow up to five public HTTP redirects, inspect its TLS certificate, and request /robots.txt and /sitemap.xml. The destination sees our server IP address and diagnostic user agent.
What we retain
The application does not save submitted domains, response bodies or reports. Results remain in your browser until you leave or run another check. Cookie and authentication response values are omitted. Temporary rate limits use a process-local keyed hash of a connection identifier; entries expire after one minute.
In-memory limits apply to one server process. Production checks on Vercel stay disabled until deployment-wide firewall rate limiting has been verified.
Hosting providers may retain standard infrastructure and security logs, including visitor IP addresses. Their retention and controls are separate from this application. Avoid submitting secret URLs, credentials or confidential query parameters.
Analytics
No third-party analytics or advertising is active. Local browser event hooks contain the tool identifier and event type, with no submitted target. Any future analytics integration must document retention and assess consent before activation.
Check limitations
Reports are point-in-time observations, not continuous monitoring or a security audit. Public websites only; custom ports and credentials are rejected. Large responses, slow sites and unsupported compression may prevent inspection.
Contact: help@labpuff.com