No account, no tracking
There is no signup and no account you can create. There is no advertising and no social widget, and nothing here asks who you are.
There is one measurement script. This site is served through Cloudflare, and Cloudflare adds its Web Analytics beacon to each page as it passes through. It counts page views and how quickly pages loaded. Cloudflare states that it uses no cookies and no client-side storage for this, and does not build a profile of individual visitors; that is their description of their product, and their privacy terms are the place to check it.
It is worth being plain about one thing: the site chose to allow this. The content policy here blocks anything not explicitly named, and the beacon was blocked by it until this host was named on purpose.
One exception. Every tool that asks another service about a domain -- WHOIS, DNS, location, safety, ranking, social counts, indexed pages, HTTP headers -- along with the search suggestion tool and the form for adding a domain to the catalog, uses Cloudflare Turnstile to tell people from scripts. Those tools spend somebody else's request quota every time they run, and without a check they are a free proxy for whoever automates them first.
That means a small piece of Cloudflare's code runs on those pages, and it is the only thing on this site loaded from another company's server. Turnstile was chosen over the better-known alternatives because it does not profile you or follow you to other sites. The tools that work entirely on this server ask nothing: the password and hash generators, the HTML encoder, the text tools, and the pages about your own connection.
Cookies
This site sets no cookies. Not one, on any page, including the pages carrying Cloudflare's check.
Cloudflare's check runs inside a frame served by Cloudflare, so whatever it stores is stored under Cloudflare's own name, not this site's, and this site cannot read it. Turnstile is built not to use cookies to track people; what it does is Cloudflare's to describe, and worth reading there if it matters to you.
That is also why there is no cookie banner: there is nothing to ask you about.
What you type into a tool
Text tools such as the password generator, the hash generator, the text length counter and the duplicate remover work on what you give them and keep none of it. The HTML encoder does the work in your browser when JavaScript is available, so the text does not reach this server at all.
Domain tools are different and it is worth being exact. When you look up a domain, the answer is kept in a shared cache so that the next person asking about the same domain does not cost the provider another request. What is stored is the answer about the domain: its WHOIS record, its DNS records, where its server is. It is not connected to you, and the fact that you in particular asked is not recorded.
Domains added to the catalog are shown publicly on the catalog page. That is the point of the catalog, and adding one is a deliberate act behind a check.
The contact form
Contact is the exception to everything above. What you write there, and the address you give so there is somewhere to reply, are sent to an inbox and kept there until the conversation is finished. They are not added to a mailing list, not passed to anyone else, and not used to write to you about anything but your own message.
Your name is optional. Your address is not, because a message with nowhere to reply is not a conversation.
The form is checked by Cloudflare Turnstile before it sends, the same check the catalog uses, and it is rate limited more tightly than anything else here. Both are there for the same reason: a form that sends mail is a form worth abusing.
Your IP address
Your address is used to count requests against the rate limit, which is what stops one visitor from turning this site into somebody else's scanner, and by the My IP Address tool, to look up where it is.
Neither of those keeps the address. The rate limit counter and the geolocation cache are both stored under a keyed hash of the address, so they can recognise an address they have seen without holding one that can be read back.
With Cloudflare's check in use there is a third: when you submit any of the forms carrying it, your address is sent to Cloudflare along with the answer, which is what lets Cloudflare judge whether the answer came from a person. Cloudflare already has your address at that point, because your browser fetched the check from its server; sending it again tells them nothing new about you.
The honest limit: to find out where an address is, it has to be sent to a service that knows. The My IP Address tool sends it to freeipapi.com, and to ip-api.com if the first does not answer. Your own browser also reveals your address to any site you visit, including this one, and the web server keeps ordinary request logs.
Services this site contacts
The domain tools ask other people's services and pass on the domain you asked about. Nothing about you goes with the question. Depending on which tool you use, that means:
- Registry WHOIS servers, for the registration record
- The system's DNS resolver, for DNS records
- Google Safe Browsing, Norton Safe Web and ESET, for the safety check
- Website Informer, UriRank and SimilarWeb, for ranking estimates
- Facebook and Pinterest, for engagement counts
- freeipapi.com and ip-api.com, for geolocation
- Google's suggestion service, for the suggestion tool
- The Internet Archive, for the capture count
- pagepeeker.com, for the screenshot on a catalog domain's page. The picture is fetched by this server and served from here, so your browser never contacts them and they learn nothing about who is looking. A fetched screenshot is kept for a month rather than asked for again.
- Google, Cloudflare and NextDNS public resolvers, for the resolver comparison. That tool exists to compare what three resolvers say, so the name you type necessarily goes to all three.
- The site itself, for the HTTP headers tool
The text tools contact nobody. What you paste into the email header analyser, the character inspector, the encoders and the rest is read while the page is being built and is not written anywhere. Message headers carry addresses and sometimes an internal server name, which is why that one is named here specifically.
Each of those sees a request from this server's address, not from yours.
Changes
If the behaviour above changes, this page changes with it. It describes the code rather than standing in for it.