Privacy
This service is built to collect as little data as technically possible. No accounts, no cookies, no third-party analytics or trackers of any kind.
What we process, and why
- Scan target (the IP/domain/email address you submit) — processed in memory and in a short-lived Redis cache to run the checks and show you the result. Deleted automatically after 1 hour.
- Requesting IP address — used for rate limiting (in-memory counter, expires after 10 minutes) and logged together with the scan target and a timestamp for up to30 days, solely to investigate abuse reports (e.g. if this service is used to scan infrastructure without authorization). This log is not used for any other purpose.
- Proof-of-control tokens (if you verify domain ownership for a full port scan) — stored in Redis for 30 minutes (unverified token) or 24 hours (once verified), then deleted automatically.
Legal basis
Processing is based on legitimate interest (Art. 6(1)(f) GDPR) in operating the service securely and preventing abuse of the scanning infrastructure.
No persistent storage
We don't run a database. Everything lives in Redis with an automatic expiry (TTL) and is gone once that TTL passes — there's no long-term profile of who scanned what.
Server logs
The underlying web server / reverse proxy may keep standard technical access logs (IP, request, timestamp, user agent) for operational and security purposes for a limited time, like any web server.
Questions about this policy? See the imprint for contact details.