Privacy policy
Short, because there is not much to say: Scan.now is designed to learn as little about you as it can while still working. Last updated 20 September 2026.
Who we are
Scan.now is operated by the Scan.now Security Desk. Contact details are on the contact page.
What we collect, by tool
| Tool | Stored | For how long | Not stored |
|---|---|---|---|
| Website, SSL, headers, email, JavaScript scanners | The target address, the results, and a daily-rotating hash of your IP address used only for rate limiting and abuse triage | 30 days | Your IP address itself |
| File scanner and extension analyzer | The file's SHA-256 hash, size, filename and verdict; the report | Hash indefinitely; report 30 days | The file. It is analysed in memory and discarded when the response is sent. |
| Browser check and WebRTC test | SHA-256 hashes of each fingerprint signal and of their combination, with counts | Indefinitely, as aggregate counts | The signal values, your IP address, your User-Agent |
| Phishing URL checker | The URL and the results | 30 days | Anything from your browser: The link is fetched from our server |
| Password checker | Nothing. Strength is computed in your browser; the breach check sends the first five characters of a SHA-1 hash, which we forward to Have I Been Pwned and cache | Prefix responses cached one hour | Your password, its hash, or the prefix tied to you |
| Signing in with Google | Your email address, the Google subject id for that address, whether Google reports it as verified, and the first and last sign-in times. Optional: Nothing on this site requires an account | Until you ask us to delete it | Your name, profile picture, contacts, or any Google data beyond the address. OAuth tokens are used once during sign-in and discarded, never stored |
| Certificate expiry reminder | Your email address, the hostname you asked about, and the certificate's expiry date. Only when you ask for it while signed in — we write only to addresses that signed in with Google | Until you unsubscribe; unconfirmed requests are deleted after 48 hours, and every watch after 400 days | Anything else. The address is never used for anything but this reminder, is never shared, and is deleted rather than flagged when you unsubscribe |
| Home-page activity feed | The scan type, the target with about four fifths of its characters replaced by dots, and the first octet of the source IP address. The censoring happens before the row is written, so no uncensored copy exists | 7 days | The hostname, filename or URL scanned; your IP address |
| Contact form | Name, email, topic, message and a hash of your IP address | Until resolved, at most two years | — |
If you sign in
Signing in is optional. Every scanner works fully without it, and nothing on this site is gated behind an account.
What we store when you do
- Your email address and the opaque account identifier Google gives us, so the same account is recognised next time.
- Whether the account has a paid plan, and when it last signed in.
What we never receive
Your Google password, your contacts, your files, or anything else in your Google account. Sign-in is delegated entirely to Google; we ask only for your email address and see nothing else.
Deleting it
Ask through the contact form and the account row is deleted, along with any certificate-expiry reminders attached to it. Scans you ran are not linked to the account, so deleting it does not affect any report link you already hold, and those expire on their own after 30 days.
The browser extension
The extension collects nothing. It has no accounts, no analytics, no crash reporting and no server of its own.
What stays on your device
- Your settings — keep-list, auto-delete delay, blocker state — in local extension storage, never transmitted.
- The cookies it reads, shown to you in the popup and not logged anywhere.
- The list of your other extensions, read the moment you open the audit tab and never sent.
Tracker blocking is declarative, so the extension is not in the request path and cannot see the requests it blocks even if it wanted to.
The one thing that leaves
The Scan this site button. Pressing it opens a Scan.now tab for the hostname of the site you are on. Nothing happens unless you press it, and only the hostname travels with it. Source, checksums and the permission-by-permission reasoning are on the extension page.
Cookies and tracking
Scan.now sets one session cookie, used to protect forms against cross-site request forgery. It contains no identifier that persists between visits. There is no advertising, and no third-party font or image on any page. Page views are counted by Matomo, which we host ourselves: the data goes to a server we run, is never sold or shared, and the tracker is started with cookies disabled, so it sets none and cannot follow you between visits. It is the only script on the site loaded from another origin. Server logs record request paths and status codes with IP addresses truncated after 24 hours.
Sharing
We do not sell or share personal data. The password checker forwards hash prefixes to Have I Been Pwned; the browser check uses a public STUN server (operated by Google) to discover WebRTC candidates, which is standard for any WebRTC test; the phishing checker may query Google Safe Browsing and public RDAP servers about the URL you submit, never about you.
Your rights
Under the GDPR, UK GDPR, CCPA/CPRA and similar laws you may ask what we hold about you, ask for it to be deleted, or object to processing. Because most data is hashed or aggregate we may be unable to link it to you, in which case we will say so. Contact us through the contact form. We honour Global Privacy Control signals, though there is nothing on this site that they would need to switch off.
Reports about third-party sites
Reports are stored at unguessable links, excluded from search engines and deleted after 30 days. If you own a site and want a report about it removed sooner, use the contact form with the report link.
Changes
Material changes will be dated at the top of this page.