Privacy Policy
Last updated: August 2026
What we collect
HTTPS Checker is a free tool. You don’t need to create an account or log in to run a check. When you check a domain, the domain you enter is sent to our servers so we can run the redirect, SSL, and security-header checks.
Report storage: when you run a check, we may store the domain, the check result (e.g. redirect chain, SSL grade, security headers), and the date of the check, so we can show a stable report page at /report/{domain} and include it in our sitemap. We only store a report when the domain is reachable over HTTPS (we do not store results for unreachable domains or when the server returns rate-limiting). Report pages are public and indexable. If you want a report removed, use the Contact page or the "Request removal" link on the report page. We do not link stored reports to an account or login identity.
Public API and abuse prevention: when you call our public check API (for example /api/v1/check), or when traffic is rate-limited, we may store the checked domain, your IP address, a truncated User-Agent, path, and basic outcome flags (error / cache hit / rate-limit hit). If you send an API key, we also store which key was used (not the secret). We use this for rate limiting, abuse prevention, security operations, and aggregate usage statistics. Limited internal operators may review these records (including activity grouped by IP or domain) for those purposes. We do not sell this data, use it for advertising, or share it with third parties for ads. These request records are retained for up to 90 days, then deleted.
Account API keys: if you create a key in the dashboard, we store a cryptographic hash of the key, a short display prefix, a label, usage counts, and timestamps. We cannot recover the full key after you leave the page. Revoking a key stops it from working. Keys are deleted when you delete your account.
Short-lived server or proxy logs may also contain request metadata needed to operate the service. Homepage and in-browser checks that go through the same public API path are subject to the same API request records described above.
Account emails: if you create an account, we send authentication messages (magic links, email-change / delete confirmations) and may occasionally send one-off operational messages about your account or product help (for example a welcome note). These are not a marketing newsletter; you can ask us to stop such outreach via the Contact page.
We use Google Analytics to understand how people use the site (e.g. which pages get visited). That may include your IP address, browser type, and general location. Google’s policies apply to how they handle that data. We’re not in the business of selling or sharing your data with third parties for ads.
Where required by law, analytics cookies are set only after your consent.
Third Parties
Your data may be processed by third-party services like Google Analytics and Cloudflare (for hosting and Functions) according to their own privacy policies. We do not control their data processing practices and encourage you to review their policies. Some data may be processed outside the European Union, subject to appropriate legal safeguards.
Cookies
Analytics may set cookies. We don’t use cookies for advertising networks or tracking pixels. You can block or delete cookies in your browser if you prefer; the checker will still work.
Legal basis & retention
We process data necessary to provide the checker and protect the service (legitimate interest) and, where applicable, with your consent for analytics cookies. Stored reports (domain + result + date) are kept so we can serve the report page and sitemap; each new check for the same domain overwrites the previous report. Report URLs are included in our sitemap only for checks from the last 30 days. Public API request and rate-limit records (domain + IP + User-Agent, and related fields) are kept up to 90 days for security and operations, then removed. Hashed API keys and monthly usage counters are kept for as long as the key or account exists. Other server and proxy logs are kept only as long as needed for security and operations, then removed.
Domain owner? If you want a report for your domain removed or made non-indexable, use the Contact page or the "Request removal" link on the report page. We will process such requests in line with this policy.
Your rights
Depending on where you live, you may have the right to access, correct, or delete your data, object to processing, or lodge a complaint with a supervisory authority. To exercise these rights, use the Contact page or email [email protected]. For API request records keyed by IP, tell us the IP address and approximate time window so we can locate matching rows within the retention period.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. The current version will always be available on this page. Your continued use of the site after any changes means you accept the updated policy.
Contact
If you have questions about this policy, use the Contact page or contact us at [email protected].