Data Retention Policy

Last updated: 15 August 2026

Our default is to store as little as possible. Retention periods below are configurable by the operator.

Request inputs

Values submitted to tools (IPs, domains, URLs, pasted text and headers) are processed in memory and are not persisted by default.

Operational logs

Server and security logs contain request paths, status codes and transient IP addresses. They are retained for a short period (typically up to 7 days) for abuse prevention and operations, then automatically deleted or anonymized. IP addresses in logs may be truncated or hashed where technically possible.

Aggregated metrics

Anonymous usage and error metrics are retained indefinitely in aggregate form only; they cannot identify an individual.

Cache

Public lookup results (DNS, WHOIS, geolocation) may be cached in memory or in Redis with a short TTL (seconds to minutes) to keep the service fast. Cached values are public data and expire automatically.

Deletion requests

Because almost nothing is stored, deletion requests are honored immediately and confirmed in writing.