Privacy Policy
Last updated: August 2026. Plain-English version — no legal jargon, no dark patterns.
The short version
- We don't run ads and we don't sell data — there is nobody to sell it to.
- We don't require an account. There is no user profile to leak.
- Client-side tools (hashing, JWT, QR, password strength) never send your input to us.
- Server-side tools (DNS, WHOIS, IP, SSL and email checks) forward the value you enter to Cloudflare Workers and, for some checks, to the third-party lookup providers listed below. We don't store the query payload beyond standard short-lived logs.
What we collect
Standard web-server logs: IP address, User-Agent, timestamp, requested URL, HTTP status and response time. These are used for abuse prevention, capacity planning, and debugging. Logs are retained for up to 30 days and are never joined to a personal identity because we don't collect one.
Cookies & local storage
We don't use tracking cookies. Your theme preference (light/dark) is kept in your browser's localStorage and never sent to us. No third-party cookies, no advertising cookies, no cross-site tracking.
Analytics
We use privacy-friendly, cookieless analytics that record aggregate pageviews and referrers only. Individual sessions cannot be reconstructed and IP addresses are hashed before being written to disk.
Third parties
Hosting: Cloudflare (edge network, DDoS protection). Depending on which tool you run, the value you enter (a domain, IP, or URL) is forwarded to the relevant upstream provider so the lookup can be answered:
- DNS: Cloudflare, Google and Quad9 DoH resolvers.
- WHOIS / domain age / availability: rdap.org, Verisign RDAP, and InstantDomainSearch.
- IP & ASN: ipwho.is, ipapi.co, ip-api.com, and bgpview.io.
- SSL / Certificate Transparency: crt.sh and CertSpotter.
- AI SPF/DMARC Fixer (only if you use it): the domain and its email DNS records are sent to the Lovable AI gateway (which routes to Google Gemini) to generate suggestions.
Have I Been Pwned queries use k-anonymity so only the first five characters of a SHA-1 hash leave your browser. We don't control these providers' own logging — see their respective privacy policies.
Your rights
Because we don't build user profiles there's very little data to request, correct or delete. If you believe an IP-linked log entry needs removing under GDPR / CCPA, email contact@dnsblade.com with the approximate timestamp and we'll purge it.
Changes
If we make material changes to this policy we'll bump the date at the top and note the change in the changelog.