Privacy · updated 4 September 2026
What we keep, and for how long.
Short, because there is not much. The scanner has no accounts, no analytics, and no third-party trackers — but a scan does send the address you enter to Google, and that is set out below.
What a scan stores
4 thingsThe URL you submitted
The findings and the score
A one-way hash of your IP address
An email address, only if you give one
How long it is kept
not longA report is deleted the moment it reaches your browser. Scans live in the memory of the running process, are never written to a database, and the findings and the screenshot of your site are erased in the same request that hands them to you. After that the only copy is the one in your browser tab.
What briefly outlives it on our side is the address you scanned and the list of links found on it, because a crawl needs them if you unlock one. That goes as soon as the crawl finishes, and a scan nobody comes back for is swept within fifteen minutes.
The hashed rate-limit record lasts one hour, because that is the window the limit is measured over. The one thing we deliberately keep is an email address you chose to give, which is forwarded to Netlify Forms and held until you ask us to delete it.
Who can see a report
Only the browser that ran the scan
It lives in that tab, not on our servers
Who else sees the address you scan
2 companiesA scan does not stay entirely between your browser and us. To measure things that need a real rendering engine, we ask Google to load the address you entered, and we ask a public DNS resolver about its domain. We send the address and nothing else — no email, no IP, nothing that identifies you.
Google PageSpeed Insights and the Chrome UX Report
Cloudflare or Google public DNS
The site you scanned
What we do not do
none of itNo analytics or tracking scripts
We do count how often the scanner ran
No advertising cookies
No selling or renting of email addresses
No accounts
Scanning a site you do not own
The scanner requests pages the way any browser would, identifying itself in its user agent, and stays within a strict budget: the entered page free under a sixty-second budget, up to ten more if a crawl is unlocked under ninety, following only same-origin links. On the free scan it reads the page and a capped sample of the stylesheets, scripts and images it declares. It does not attempt to log in, submit forms, or reach anything a normal visitor could not.
If you operate a site and want it excluded, or you want a report deleted, or you want an email address you gave us erased, write to [email protected] with the URL or the report link.