Privacy
Privacy
The service is designed to collect as little data as possible while still supporting checks, abuse prevention and public corrections.
What is stored by default
- By default, the service stores only the normalized main domain, such as example.com.
- Full URL paths, query strings, fragments and tracking parameters are not kept long term.
- Hashed rate-limit identifiers are kept for 7 days to prevent abuse.
- The service does not use third-party advertising tracking.
External sources used during checks
Taiwan 165 public datasets are mirrored daily. User checks query the local mirror first and do not send each checked URL to 165.
RDAP is used to retrieve domain registration data. The system first reads IANA's TLD bootstrap table; that step does not include the domain you checked.
- When RDAP data is needed and the local cache is missing or expired, the main domain is disclosed to the authoritative RDAP service for that TLD.
- The service does not send full paths, query strings, fragments, user IP addresses or browser fingerprints to RDAP endpoints.
- rdap.org and similar third-party RDAP aggregators are not used by default.
Public reports
A public report shows the main domain, source, source date, rule version, risk score and evidence that can be checked.
If a report is corrected, the correction record remains visible so users can see what changed.