PRIVACY
What we hold, for how long, and what we never keep
Written in the same plain language as the rest of the site, and describing what the software actually does. Last reviewed 7 September 2026.
The lists you upload
Uploaded files and the results generated from them are temporary. Your latest report stays until a new scan replaces it, you delete it, or you sign out. Free accounts have no report history, by design rather than as a limitation to upsell against.
URLs that fail validation, meaning malformed lines, duplicates and anything rejected before the scan, are never retained at all.
We do not sell, share or publish the URLs you submit. Nothing you upload appears on this website; every row shown in the sample report and in the research pages is synthetic or aggregate.
Your account
Sign-in is through Google. We store the Google account identifier, your name and your email address so the account can be recognised on your next visit, together with your credit balance and its reset date.
Accounts are keyed on the Google account identifier rather than on the email address, because people change email addresses and an account should survive that.
Aggregate data about public pages
We keep a pool of public facts about public pages, such as whether a page had an open comment form on a given day. This is what makes it possible to publish research such as the 1,000-URL run without exposing anyone’s list.
Two deliberate properties of that pool are worth stating, because they are the reason it cannot be used to reconstruct your work:
- A date, never a timestamp. Rows carry the day they were read and nothing more precise.
- Rows are shuffled before they are written. A precise time plus a scan’s worth of URLs would otherwise let someone infer which account submitted which list. Both properties exist to prevent exactly that.
The pages we visit on your behalf
A scan opens the URLs you supply over plain HTTP and reads the page. It never posts a comment, never signs in, never submits a form and never attempts a CAPTCHA. Nothing behind authentication is read; those pages are reported as unread.
Third parties
- Google: sign-in only.
- Ahrefs: Domain Rating lookups, by domain. Most scans answer from a local cache and make no request at all.
- Cloudflare Turnstile: to tell a person from a script when a scan starts.
- Hostinger: hosting for this website and the application.
This website loads its typefaces from Google Fonts, which means your browser requests those files from Google. There is no analytics script, no advertising script and no third-party tracker on this site.
Cookies
The application sets a session cookie so you stay signed in. It also remembers your light or dark theme choice in your browser’s local storage, which never reaches us. Neither is used for advertising or profiling.
Your choices
- Delete your current report at any time from the report screen, or by signing out.
- Ask for your account and its data to be deleted by writing to support@webdiagnosis.net.
- Ask what we hold about you, using the same address.
Changes
If this page changes materially, the review date above changes with it and the change is described rather than made quietly.
Note: this page describes the software’s actual behaviour and has not been reviewed by a lawyer. If WebDiagnosis begins taking payment or operating in a regulated context, have it reviewed before relying on it.