Privacy policy

Short, because there is not much to say: Scan.now is designed to learn as little about you as it can while still working. Last updated 20 September 2026.

Who we are

Scan.now is operated by the Scan.now Security Desk. Contact details are on the contact page.

What we collect, by tool

ToolStoredFor how longNot stored
Website, SSL, headers, email, JavaScript scannersThe target address, the results, and a daily-rotating hash of your IP address used only for rate limiting and abuse triage30 daysYour IP address itself
File scanner and extension analyzerThe file's SHA-256 hash, size, filename and verdict; the reportHash indefinitely; report 30 daysThe file. It is analysed in memory and discarded when the response is sent.
Browser check and WebRTC testSHA-256 hashes of each fingerprint signal and of their combination, with countsIndefinitely, as aggregate countsThe signal values, your IP address, your User-Agent
Phishing URL checkerThe URL and the results30 daysAnything from your browser: The link is fetched from our server
Password checkerNothing. Strength is computed in your browser; the breach check sends the first five characters of a SHA-1 hash, which we forward to Have I Been Pwned and cachePrefix responses cached one hourYour password, its hash, or the prefix tied to you
Signing in with GoogleYour email address, the Google subject id for that address, whether Google reports it as verified, and the first and last sign-in times. Optional: Nothing on this site requires an accountUntil you ask us to delete itYour name, profile picture, contacts, or any Google data beyond the address. OAuth tokens are used once during sign-in and discarded, never stored
Certificate expiry reminderYour email address, the hostname you asked about, and the certificate's expiry date. Only when you ask for it while signed in — we write only to addresses that signed in with GoogleUntil you unsubscribe; unconfirmed requests are deleted after 48 hours, and every watch after 400 daysAnything else. The address is never used for anything but this reminder, is never shared, and is deleted rather than flagged when you unsubscribe
Home-page activity feedThe scan type, the target with about four fifths of its characters replaced by dots, and the first octet of the source IP address. The censoring happens before the row is written, so no uncensored copy exists7 daysThe hostname, filename or URL scanned; your IP address
Contact formName, email, topic, message and a hash of your IP addressUntil resolved, at most two years

If you sign in

Signing in is optional. Every scanner works fully without it, and nothing on this site is gated behind an account.

What we store when you do

What we never receive

Your Google password, your contacts, your files, or anything else in your Google account. Sign-in is delegated entirely to Google; we ask only for your email address and see nothing else.

Deleting it

Ask through the contact form and the account row is deleted, along with any certificate-expiry reminders attached to it. Scans you ran are not linked to the account, so deleting it does not affect any report link you already hold, and those expire on their own after 30 days.

The browser extension

The extension collects nothing. It has no accounts, no analytics, no crash reporting and no server of its own.

What stays on your device

Tracker blocking is declarative, so the extension is not in the request path and cannot see the requests it blocks even if it wanted to.

The one thing that leaves

The Scan this site button. Pressing it opens a Scan.now tab for the hostname of the site you are on. Nothing happens unless you press it, and only the hostname travels with it. Source, checksums and the permission-by-permission reasoning are on the extension page.

Cookies and tracking

Scan.now sets one session cookie, used to protect forms against cross-site request forgery. It contains no identifier that persists between visits. There is no advertising, and no third-party font or image on any page. Page views are counted by Matomo, which we host ourselves: the data goes to a server we run, is never sold or shared, and the tracker is started with cookies disabled, so it sets none and cannot follow you between visits. It is the only script on the site loaded from another origin. Server logs record request paths and status codes with IP addresses truncated after 24 hours.

Sharing

We do not sell or share personal data. The password checker forwards hash prefixes to Have I Been Pwned; the browser check uses a public STUN server (operated by Google) to discover WebRTC candidates, which is standard for any WebRTC test; the phishing checker may query Google Safe Browsing and public RDAP servers about the URL you submit, never about you.

Your rights

Under the GDPR, UK GDPR, CCPA/CPRA and similar laws you may ask what we hold about you, ask for it to be deleted, or object to processing. Because most data is hashed or aggregate we may be unable to link it to you, in which case we will say so. Contact us through the contact form. We honour Global Privacy Control signals, though there is nothing on this site that they would need to switch off.

Reports about third-party sites

Reports are stored at unguessable links, excluded from search engines and deleted after 30 days. If you own a site and want a report about it removed sooner, use the contact form with the report link.

Changes

Material changes will be dated at the top of this page.