Privacy Policy
PrivacyTestLab is built around transparency, minimal data collection, and browser privacy awareness. This Privacy Policy explains how our tools work, what technical information may be processed during testing, and how we protect user privacy across the platform.
Overview
PrivacyTestLab provides browser-based privacy and security testing tools designed to help users understand IP exposure, browser fingerprinting, DNS leaks, WebRTC behavior, and related privacy risks.
Most tools operate directly inside the user's browser without requiring account creation, downloads, or permanent storage of personal data.
Important: Most diagnostic processing occurs locally inside your browser session and is not stored permanently on our servers.
Information we collect
PrivacyTestLab has no user accounts or personal profiles. Browsing the site, reading articles, and using every leak test, lookup, and scanner works without signing in.
To generate accurate privacy diagnostics, certain technical information may be processed temporarily during testing. Depending on the tool being used, this may include IP address details, browser user-agent information, DNS resolver data, WebRTC network details, screen resolution, device capabilities, or approximate geolocation derived from IP connectivity.
This information is used solely to display privacy-related test results and explain potential browser or network privacy exposure.
PrivacyTestLab does not sell personally identifiable information to advertisers or third parties.
Browser-based privacy tools
Many PrivacyTestLab tools run directly in the browser using JavaScript and browser networking APIs. These tools are designed to analyze privacy exposure without requiring software installation or user registration.
Available tools may include IP leak testing, DNS leak detection, WebRTC analysis, browser fingerprinting analysis, and related privacy diagnostics.
Some tests temporarily access browser-provided network information in order to display diagnostic results. In many cases, processing occurs locally inside the browser session.
Former accounts
PrivacyTestLab no longer offers member accounts or a developer API. Records from accounts created before October 2026 — the email address, username, a one-way password hash, and any profile details that were added — are still held in our database, but they are not used, shown, or shared. If you had an account and want those records deleted, ask us from the Contact page.
Community email list
The signup box on our articles is optional. If you join, we store your email address, a one-way hash of the password you choose, and whether you ticked the boxes for occasional offers or for sharing your email with partners — both stay off unless you tick them. Every email we send to the list has a one-click unsubscribe link, which deletes your address from the list; you can also reply to any email and we will remove you.
To block automated abuse, signup attempts are logged with the originating IP address and timestamp. These entries are temporary and are deleted after 24 hours.
IP addresses
Outside of the temporary signup logs described above, we do not store IP addresses as addresses. Before anything is written down, an IP is passed through a one-way hash with a secret key, so the stored value cannot be turned back into an IP by us or by anyone who obtained the database. These hashes let us spot abuse coming from the same connection.
Cookies & advertising
PrivacyTestLab does not currently use invasive tracking systems or custom behavioral profiling technology for identifying users across the web.
However, third-party advertising providers, embedded content, or analytics services may use cookies, local storage, or similar technologies to deliver advertisements, improve services, measure engagement, or prevent abuse.
Users can choose which optional cookies run at any time via the Cookie Settings link in the site footer, or disable cookies entirely through browser settings — although some website functionality or advertisements may not operate correctly afterward. See our Cookie Policy for the full breakdown of cookie categories.
If third-party advertising is enabled on this site in the future, the provider may use cookies to display personalized or contextual advertisements.
Payments
Nothing on this site is sold, and there is no card form anywhere on it. The only money that changes hands is voluntary support, sent over UPI or PayPal, both of which handle the payment entirely outside this site.
For a contribution we store the amount, the method, a reference code we generate, and the transaction number you type in yourself so we can match the payment. If you choose to give a name or email address we store those to thank you and confirm it arrived. Card, bank and UPI account details never reach our servers, because they are never sent to us in the first place.
We only email you when you have given us a reason to: a reply to a message you sent, a confirmation for a contribution, or updates from the community email list if you joined it.
Email is sent through our own mail server. Your address is not passed to any marketing platform.
Third-party services
PrivacyTestLab relies on selected third-party providers for hosting infrastructure, domain management, email delivery, DNS services, and website security operations.
These providers may process limited technical information as part of normal infrastructure and operational functionality.
PrivacyTestLab does not directly control how external service providers manage their own internal systems, security practices, or data retention policies.
Security measures
PrivacyTestLab uses reasonable technical and administrative safeguards designed to reduce unauthorized access, abuse, misuse, or service disruption.
Security protections may include HTTPS encryption, firewall systems, server monitoring, spam prevention systems, and restricted file handling procedures.
Although reasonable efforts are taken to improve platform security, no online system can guarantee complete protection against every security threat or cyber attack.
Temporary server logs may be retained for security monitoring, abuse prevention, debugging, and operational reliability.
Passwords are stored only as one-way hashes. A content security policy blocks inline scripts, so a single flaw cannot easily become an attack on visitors.
How long we keep data
Retention periods vary by data type. Records from former accounts are kept until you ask us to delete them. Community email list entries are kept until you ask to be removed. Signup attempt logs are deleted after 24 hours.
Your rights & choices
You can ask for a copy of anything we hold about you, or for it to be deleted, from the Contact page or at support@privacytestlab.com. That covers records from a former account and your entry on the community email list.
Depending on your country or region, applicable privacy laws may provide rights related to personal information and data processing.
These rights may include requesting access to submitted information, requesting deletion of certain data, correcting inaccurate information, or managing browser cookie preferences.
Because PrivacyTestLab generally avoids account systems and large-scale personal data storage, many requests may already be inherently limited by platform design.
Contact
Questions about anything on this page: support@privacytestlab.com. If we change this policy in a way that affects how your data is handled, the change is posted here with a new "Last Updated" date before it takes effect.
If you find a security problem, email support@privacytestlab.com. We will not take legal action against anyone reporting a flaw in good faith.
Policy updates
PrivacyTestLab may periodically update this Privacy Policy to reflect operational changes, new features, legal requirements, advertising updates, or security improvements.
Updated versions will be published on this page along with a revised “Last Updated” date.