Privacy policy (Datenschutzerklärung)
This site is a private, non-commercial project. It uses no tracking, no analytics, no advertising and no cookies. The little personal data that is processed is described completely on this page.
1. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Daniel Buckenmaier
Mailänder Platz 7
70173 Stuttgart
Germany
2. Hosting and server logs
This website is hosted on a virtual server operated by netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany, in data centers within the European Union. netcup processes data on our behalf as a processor (Art. 28 GDPR).
When you visit the site, the web server automatically records access log entries containing your IP address, the date and time of the request, the requested URL, the HTTP status code, the transferred data volume, the referrer URL and your browser's user-agent string.
- Purpose: secure and stable operation of the service, detection and defense of abuse (e.g. mass scanning), and error analysis.
- Legal basis: legitimate interest, Art. 6 (1) (f) GDPR.
- Retention: log files are rotated daily and automatically deleted after 10 days (at most 11 days including the rotation cycle).
In addition, the application keeps a short-lived, in-memory rate-limiting counter per IP address (retained for at most one hour, never written to disk) to enforce fair-use limits.
3. Cloudflare Turnstile (abuse protection)
To protect the scan API against automated abuse, this site uses Cloudflare Turnstile, a CAPTCHA-less verification service provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
When you start a scan, your browser loads the Turnstile widget from
challenges.cloudflare.com and Cloudflare receives your IP address and
technical browser characteristics to assess whether the request is human. Our server
additionally forwards your IP address to Cloudflare once per scan session when verifying
the Turnstile token.
- Purpose: preventing automated mass scans and protecting the service and third parties from abuse.
- Legal basis: legitimate interest, Art. 6 (1) (f) GDPR. Because the verification is strictly necessary to provide the service securely, no consent is required for the associated access to your device (§ 25 (2) no. 2 TDDDG).
- Third-country transfer: Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework. Details: Cloudflare privacy policy.
4. The scan itself
The domain name you enter is used solely to perform the requested checks: the server sends DNS, TLS, HTTP and SMTP queries to the public infrastructure of that domain. Scan results are kept in a short-lived in-memory cache (up to one hour) to avoid duplicate probing, then automatically discarded — they are never written to disk or stored permanently. The cache is keyed by the domain name only and is not linked to your IP address. A manual refresh can force a new check (rate-limited). No scan history is kept, and submitted domains are not linked to your IP address beyond the server logs described above.
5. Local storage (theme preference)
If you switch between light and dark mode, your choice is saved in your browser's
localStorage. This value never leaves your device and can be removed at any
time by clearing your browser data. No cookies are set by this site.
6. Your rights
Under the GDPR you have the right to:
- access to your personal data (Art. 15),
- rectification (Art. 16) and erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20), and
- object to processing based on legitimate interest (Art. 21).
To exercise these rights, contact the controller at the postal address given above. Note that IP addresses in the server logs are not attributed to identified persons and are deleted automatically after the retention period stated above.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for the controller is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, baden-wuerttemberg.datenschutz.de.
7. Final remarks
Providing personal data is neither legally nor contractually required; the data described above is the technical minimum needed to operate the service. No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
Last updated: June 2026.