What we collect: nothing
We don't have accounts, cookies, analytics trackers, or ad pixels. We don't log the policies you scan, the URLs you enter, or anything that identifies you. When your scan finishes, the text is gone.
We don't have accounts, cookies, analytics trackers, or ad pixels. We don't log the policies you scan, the URLs you enter, or anything that identifies you. When your scan finishes, the text is gone.
The policy text you submit is analyzed in memory: rule matching runs on our server, and a language-model pass runs via Groq's API. The text exists only for the seconds the scan takes. It is never written to a database, never used for training, never shared.
When you submit a URL, our server fetches the page directly using a plain HTTP request — no headless browser, ever. Before the request is made, the hostname is resolved and the resulting IP address is validated: private, loopback, link-local, and cloud-metadata ranges are blocked, and the resolved IP is pinned for the actual fetch to prevent DNS-rebinding.
To keep the service free and standing, we hold a short-lived, in-memory count of scans per IP address. It expires automatically, is never stored to disk, and is never connected to what you scanned.
Sell or share your data (there is none). Track you across sites. Change this policy silently — any change lands here with a new date, in plain English, worst news first. If we ever fail that standard, run this page through the scanner and hold up the receipt.
This statement describes the Red Flags scanner tool and its data practices. It is not a commercial privacy policy, does not govern a business relationship, and is not legal advice. If you have questions about a specific privacy policy you scanned, consult the company that published it — or a qualified attorney.