Privacy Policy
Last updated: September 2026
Information We Collect
When you use NerdTools, we may collect:
- Query data: The domains, IPs, and URLs you scan are processed in real-time to provide results.
- Usage data: Anonymised analytics such as page views, feature usage, browser or device details, referrers, approximate location derived from IP address, and session replay data, including public scan result pages, to improve our service.
- Account data: If you register, we store your email address, password hash, verification state, account membership and developer API-key metadata. Full API key secrets are shown once and stored only as hashes.
- API usage metadata: We record account and key identifiers, endpoint, date, request counts and success or failure state for quotas and product operation. Detailed queried domains and result payloads are not stored in API usage aggregates, and API or MCP requests are not included in public leaderboard or recent-scan listings.
- Billing data: If you upgrade, Stripe processes payment details. We store Stripe customer and subscription identifiers, plan state and billing-event metadata, but not full card details.
How We Use Your Information
- To provide and improve our network diagnostic tools
- To use anonymised analytics and masked session replay to understand product usage, diagnose broken flows, and improve the interface.
- To display aggregated statistics from public browser scans (e.g., most scanned domains); API and MCP activity is excluded from these public listings.
- To authenticate developer access, enforce quotas, manage subscriptions and respond to support or account requests.
Data Retention
Scan queries may be logged temporarily for performance monitoring. Shared snapshots are retained for the period shown when a share link is created. Account, subscription, security and usage records are retained for as long as needed to operate the service, meet legal obligations and prevent abuse. You may contact us to request account deletion, subject to required retention.
Third-Party Services
We use third-party services for hosting, infrastructure, email delivery, payment processing, analytics, and session replay. Stripe processes subscription payments. PostHog EU Cloud may process anonymised product analytics, public scan result page content, and replay data with form inputs and sensitive controls masked or blocked. We do not intentionally send passwords, API tokens, payment details or Turnstile tokens to analytics services.
Cookies
We use essential cookies to maintain sessions and preferences. Analytics cookies or local storage may be used to support anonymised analytics and masked session replay.
Your Rights
You may contact us with privacy-related questions or data requests. EU users have additional rights under GDPR.
Contact
For privacy-related questions, please visit our Contact page.