checkbox.tools
Tools Blog About Contact
English Deutsch Español Français Italiano Nederlands Polski Українська
Home / Legal / Privacy Policy
Legal

Privacy Policy

How we collect, use, and protect your personal data, written in plain English.

Last updated: 2026-05-18
Effective: 2026-06-01
On this page
  • Overview
  • Data we collect
  • How we use it
  • Cookies & tracking
  • Third parties
  • Data retention
  • Your rights
  • Contact

Overview

This Privacy Policy describes how checkbox.tools ("we", "us", "our") collects, uses, and shares information about you when you use our website.

Short version: we don't sell your data, we don't profile you, and we collect only what is needed to run the service.

Jurisdiction: checkbox.tools is operated from the European Union and applies the standards of the General Data Protection Regulation (GDPR) to all visitors, regardless of their location. The data controller is the operator of checkbox.tools — see the contact page for inquiries.

Data we collect

We collect two types of data: what you give us by interacting with the site, and what is collected automatically when you load a page.

Information you provide

  • Inputs to our tools — the IP address, domain, URL, or text you enter into any lookup form. These inputs are processed in memory to compute a result and are not persisted unless explicitly stated (Webhook Tester is the exception, see below).
  • Contact messages — when you email us through the contact form, we receive your name, email address, and message content. We keep these for as long as needed to respond and, where applicable, to maintain audit history.

Information collected automatically

Data Purpose Retention
IP address (hashed with HMAC-SHA256) Rate limiting, abuse prevention, anonymous analytics 30 days
Country / ASN (derived from IP via local geolocation database) Aggregate analytics, regional content Aggregated; not linked to a person
User-Agent string (hashed) Browser compatibility, bot detection Session only
Tool slug, duration, status Performance monitoring, error tracking 90 days
Cookie preferences Remember your consent choice 12 months

We do not store the raw IP addresses you query, nor the results returned to you. Raw IPs are hashed with HMAC-SHA256 (a server-side salt) before they ever touch disk.

How we use it

  • Run the tools you request and return results to your browser.
  • Prevent abuse by applying per-IP rate limits.
  • Understand which tools are most used so we can improve them.
  • Show contextually relevant advertising (only after you consent) through Google AdSense.
  • Respond to your emails and support requests.
  • Comply with legal obligations (e.g. responding to lawful requests from authorities).

Cookies & tracking

We use cookies and similar technologies sparingly. The first time you visit, the consent banner asks for your choice — accept, reject, or customize. You can revoke or change your choice at any time via the "Cookie settings" link in the footer.

For the full cookie list, see the Cookie Policy.

Third parties

We work with the following processors. Each one processes only the data strictly required for the named purpose, under a written data-processing agreement (where applicable).

Processor Purpose Location
Hetzner Online GmbH Hosting (application + database servers) Germany (EU)
Cloudflare, Inc. CDN, DDoS protection, TLS termination Global (EU edge POPs preferred)
Google Ireland Ltd. (Analytics 4) Aggregate analytics — only after consent EU / US (SCC + adequacy)
Google Ireland Ltd. (AdSense + Funding Choices CMP) Contextual advertising and consent management — only after consent EU / US (SCC + adequacy)
Sentry (Functional Software, Inc.) Error monitoring with PII off; IPs not sent EU (Frankfurt region)

Data retention

We keep personal data only as long as it is needed for the purposes described above, or as required by law.

Webhook Tester

If you use the Webhook Tester, captured HTTP requests are stored against a single anonymous bin (a v4 UUID). Bins auto-delete 24 hours after the last activity (sliding TTL). Each bin keeps at most the 10 most recent requests (FIFO). Text bodies are stored up to 10 KB; binary bodies are replaced with a 1 KB stub and an SHA-256 hash of the original. Source IP addresses (both the bin creator and senders) are stored as HMAC-SHA256 hashes only — raw IPs are never written to disk. The bin URL is a bearer token: anyone with the link can see all requests, so do not send production secrets there.

Your rights under GDPR

You have the following rights regarding your personal data. To exercise any of them, email us through the contact page; we respond within 30 days.

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — request deletion of your data, subject to our legal obligations.
  • Restriction — ask us to limit how we process your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests, including profiling.
  • Withdraw consent — at any time, with no effect on processing before withdrawal.
  • Complaint — lodge a complaint with your local data-protection authority.

Contact us

For privacy-related questions, visit the contact page.

checkbox.tools

Made with care.

Tools

IP Whois DNS Lookup SSL Checker Base64 Encoder All tools

Categories

IP & Network Domain & DNS Security Encoders & Utilities

Company

About Blog Contact

Legal

Privacy Terms Cookies
© 2026 checkbox.tools. All rights reserved.
GitHub

We use cookies and Google Analytics to understand how our tools are used. No tracking happens until you accept. Privacy policy