Privacy

What we collect, and what we don't.

The short version. There are no accounts and no tracking cookies. We don't sell or share anything for advertising. If you subscribe to the newsletter we hold your email address to send it to you. If you use the MCP server or a free tool, we hold your IP address briefly to stop one person exhausting a shared quota, and we don't keep a record of what you looked up.

Last updated 17 August 2026.

The website

Analytics. We use Cloudflare Web Analytics, which is cookieless and collects no personal data — that's why you've had no consent banner. It gives us page counts and referrers in aggregate. We cannot see individual visitors and there is no cross-site profile.

Fonts. Typefaces load from Google Fonts, so your browser makes a request to fonts.googleapis.com and fonts.gstatic.com. Google receives your IP address as part of that request, as it would for any site using their font CDN.

Hosting. The site is static, served by Vercel behind Cloudflare. Both process request metadata (IP, user agent) to deliver pages and absorb abuse, as any host does.

No cookies are set by us. Nothing on this site needs them.

The newsletter

If you subscribe, your email address goes to Kit (formerly ConvertKit), who send the newsletter on our behalf and hold the subscriber list. We use it to send you Quiet Failures and nothing else. Every email has a one-click unsubscribe, which removes you from the list — you don't need to ask us. We don't sell the list, rent it, or pass it to anyone else.

The free tools and the MCP server

The free checks on this site and the live check tools on the MCP server work the same way, and this is the part worth reading carefully.

What you submit. When you check a domain, that domain name is sent to our API, which then queries public infrastructure about it: DNS resolvers, WHOIS registries, Certificate Transparency logs, and the endpoints of cloud providers to test for dangling records. Those third parties see the query. This is all public data about public infrastructure — the same lookups anyone can run — but it does leave our systems.

Your IP address. The MCP server keeps your IP in memory only, to enforce its rate limit of three calls per hour per tool. It is not written to a database or a log file, and it is discarded when the process restarts. It exists to stop one client exhausting a shared free quota, and for nothing else.

What we don't keep. We do not store the domains you check, build a history against your IP, or retain the results. Ask about the same domain tomorrow and we will look it up again, because we didn't keep yesterday's answer.

No authentication. The MCP server has no accounts, no API keys and no OAuth. There is nothing for us to associate a request with.

Operational logs

Our services emit logs so we can tell when something is broken — errors, timings, which tool was called. These carry no request bodies and no submitted domains. They go to self-hosted infrastructure we run, not to a third-party logging service, and they age out.

The published datasets

The base rates are aggregate only. They are measured over public infrastructure and no individual company is ever named, in the published data or anywhere else. A slice is only published where it holds at least 100 measured members, which is a statistical floor that also happens to make re-identification impractical. If your domain was in a measured population, nothing published says so.

Your rights

If you're in the UK or EU you have the right to ask what we hold about you, to have it corrected or deleted, and to object to processing. In practice the only personal data we hold is a newsletter email address, so in most cases the answer is "your email address, and you can remove it yourself with the unsubscribe link". Ask us anyway if you'd like it confirmed.

Changes

If this policy changes materially we'll update the date above. We won't quietly start collecting something this page says we don't.

Contact

Anything at all, including security reports: [email protected].