Privacy Policy
This page describes exactly what this implementation does. Replace the placeholders below (contact email, analytics/ads provider details) before deploying to production, and keep this page in sync with your actual setup.
What we process
When you submit a URL to scan, we make outbound network requests to that URL to check its publicly observable security configuration (HTTPS behavior, response headers, cookie flags on the initial response, TLS certificate details, and the presence of /.well-known/security.txt and /robots.txt).
What we store
Scan results are held in server memory for up to 24 hours so you can view and share the report link, then they are automatically deleted. [Update this if you connect a database or persistent store.] We log basic request metadata (such as IP address) temporarily for rate limiting and abuse prevention.
Why we process it
To run the scan you requested and produce your report, and to prevent abuse of the free scanning service through rate limiting.
Retention
Scan reports: up to 24 hours. Rate-limit counters: up to 1 minute. [Update if your deployment changes these.]
Third parties
[List your actual analytics and advertising (e.g. Google AdSense) providers here, and link to their privacy policies. Do not claim a provider is used unless it is actually integrated.]
Advertising
[Describe your actual AdSense configuration, including whether personalized ads are used, once integrated.]
Your rights
You can request deletion of a specific report via its share link using the delete option, or by contacting us. Since we do not require accounts, we do not hold a persistent profile tied to your identity.
Contact
[Insert a real contact method before launch \u2014 e.g. privacy@yourdomain.example]