Privacy Policy
PrivacyTestLab is built around transparency, minimal data collection, and browser privacy awareness. This Privacy Policy explains how our tools work, what technical information may be processed during testing, and how we protect user privacy across the platform.
Overview
PrivacyTestLab provides browser-based privacy and security testing tools designed to help users understand IP exposure, browser fingerprinting, DNS leaks, WebRTC behavior, and related privacy risks.
Most tools operate directly inside the user's browser without requiring account creation, downloads, or permanent storage of personal data.
Important: Most diagnostic processing occurs locally inside your browser session and is not stored permanently on our servers.
Information we collect
PrivacyTestLab does not require user accounts or personal profiles to browse the site, read articles, or use any of its diagnostic tools — every leak test, lookup, and scanner is fully usable without signing in. The one exception is the optional developer API, which requires a free account only if you choose to query our tools programmatically. See API Accounts below for what that involves.
To generate accurate privacy diagnostics, certain technical information may be processed temporarily during testing. Depending on the tool being used, this may include IP address details, browser user-agent information, DNS resolver data, WebRTC network details, screen resolution, device capabilities, or approximate geolocation derived from IP connectivity.
This information is used solely to display privacy-related test results and explain potential browser or network privacy exposure.
PrivacyTestLab does not sell personally identifiable information to advertisers or third parties.
Browser-based privacy tools
Many PrivacyTestLab tools run directly in the browser using JavaScript and browser networking APIs. These tools are designed to analyze privacy exposure without requiring software installation or user registration.
Available tools may include IP leak testing, DNS leak detection, WebRTC analysis, browser fingerprinting analysis, and related privacy diagnostics.
Some tests temporarily access browser-provided network information in order to display diagnostic results. In many cases, processing occurs locally inside the browser session.
API accounts
PrivacyTestLab offers an optional developer API that lets you query our tools programmatically. Using the API is the only part of this site that requires an account — browsing, articles, and every browser-based tool remain fully usable without one.
If you create an account with an email and password, we store your email address and a one-way cryptographic hash of your password — never the password itself. If you sign in with Google or GitHub instead, we only receive and store your email address and the account ID that provider assigns you; we never see or store your Google or GitHub password.
To block automated password-guessing, failed sign-in attempts are logged with the originating IP address and timestamp. These entries are temporary and are automatically deleted after 24 hours.
An API key itself is stored only as a one-way hash. The full key is shown to you once, at the moment you generate it, and cannot be retrieved by us afterward — only revoked. We keep a daily count of how many requests each key has made, to enforce the rate limit; we do not log the content or parameters of individual API requests.
You can revoke any API key at any time from your dashboard. To delete your account and its associated data entirely, contact us from the Contact page.
User & business accounts
Creating a full account to write reviews or reply to them is also optional. If you create one, we store your username, name, and email address, along with a password hash created with Argon2id — we cannot recover your password, and neither could anyone who obtained our database. You can add a bio, location, website, and profile picture at any time, and we keep a record of which devices are signed in, roughly what they are, and when each was last active.
Business accounts collect the same details as a personal account, plus the business name, website, domain, category, and description you submit. If we ask for a registration document during verification, we review it, record the decision, and delete the file — we do not retain business identity documents.
IP addresses
Outside of the temporary failed sign-in logs described above, we do not store IP addresses as addresses. Before anything is written down, an IP is passed through a one-way hash with a secret key, so the stored value cannot be turned back into an IP by us or by anyone who obtained the database. These hashes let us spot patterns such as several accounts reviewing one business from the same connection, and are cleared from reviews after 180 days and from account records after a year.
Your session is not tied to your IP address. Many people here use VPNs and mobile connections where the address changes constantly, and IP-bound sessions would sign them out repeatedly for no security benefit.
Cookies & advertising
PrivacyTestLab does not currently use invasive tracking systems or custom behavioral profiling technology for identifying users across the web.
However, third-party advertising providers, embedded content, or analytics services may use cookies, local storage, or similar technologies to deliver advertisements, improve services, measure engagement, or prevent abuse.
Users can choose which optional cookies run at any time via the Cookie Settings link in the site footer, or disable cookies entirely through browser settings — although some website functionality or advertisements may not operate correctly afterward. See our Cookie Policy for the full breakdown of cookie categories.
If third-party advertising is enabled on this site in the future, the provider may use cookies to display personalized or contextual advertisements.
Payments
Nothing on this site is sold, and there is no card form anywhere on it. The verified badge is free. The only money that changes hands is voluntary support, sent over UPI or PayPal, both of which handle the payment entirely outside this site.
For a contribution we store the amount, the method, a reference code we generate, and the transaction number you type in yourself so we can match the payment. If you choose to give a name or email address we store those to thank you and confirm it arrived. Card, bank and UPI account details never reach our servers, because they are never sent to us in the first place.
We send account emails: confirmation, password reset, security alerts, and notifications you have switched on. Security alerts cannot be turned off, because an email telling you about a sign-in you did not make is the point.
Email is sent through our own mail server. Your address is not passed to any marketing platform.
Third-party services
PrivacyTestLab relies on selected third-party providers for hosting infrastructure, domain management, email delivery, DNS services, and website security operations.
These providers may process limited technical information as part of normal infrastructure and operational functionality.
PrivacyTestLab does not directly control how external service providers manage their own internal systems, security practices, or data retention policies.
Security measures
PrivacyTestLab uses reasonable technical and administrative safeguards designed to reduce unauthorized access, abuse, misuse, or service disruption.
Security protections may include HTTPS encryption, firewall systems, server monitoring, spam prevention systems, and restricted file handling procedures.
Although reasonable efforts are taken to improve platform security, no online system can guarantee complete protection against every security threat or cyber attack.
Temporary server logs may be retained for security monitoring, abuse prevention, debugging, and operational reliability.
Passwords are hashed with Argon2id, and two-factor sign-in is available on every account. A content security policy blocks inline scripts, so a single flaw cannot easily become an attack on visitors. Uploaded images are re-encoded on our server, which strips location data and other metadata before anything is stored.
How long we keep data
Retention periods vary by data type. Account details are kept until you delete the account. Reviews are kept indefinitely, anonymised if you delete your account. Hashed IPs on reviews are kept 180 days, and the hashed IP of your last sign-in is kept a year. Device sessions are kept 90 days after last activity. Email and password reset tokens are kept 7 days after expiry. Data exports are kept 48 hours, then overwritten and deleted. Business verification documents are deleted as soon as the decision is made.
Your rights & choices
Settings → Your data lets you build a full export of everything we hold, as a file. You can also change any profile field at any time, make your profile private or remove it from search, and delete your account entirely — self-serve, immediate, with no waiting period. Your email, profile, and login are erased; reviews stay published under "Former member" with nothing connecting them back to you, which is explained on the deletion screen before you confirm.
Depending on your country or region, applicable privacy laws may provide rights related to personal information and data processing.
These rights may include requesting access to submitted information, requesting deletion of certain data, correcting inaccurate information, or managing browser cookie preferences.
Because PrivacyTestLab generally avoids account systems and large-scale personal data storage, many requests may already be inherently limited by platform design.
Contact
Questions about anything on this page: support@privacytestlab.com. If we change this policy in a way that affects how your data is handled, account holders are emailed before it takes effect.
If you find a security problem, email support@privacytestlab.com. We will not take legal action against anyone reporting a flaw in good faith.
Policy updates
PrivacyTestLab may periodically update this Privacy Policy to reflect operational changes, new features, legal requirements, advertising updates, or security improvements.
Updated versions will be published on this page along with a revised “Last Updated” date.