Privacy policy · effective 6 September 2026
What this site knows about you
Short version: aggregate traffic measurement, and nothing else. A site that argues about who is watching you owes you a plain account of what it watches itself, so here it is without the usual hedging.
What we do not collect
- No advertising or profiling scripts. No ad-network pixels, no tag managers, no embedded social widgets, no web fonts fetched from outside this domain, and no data sold or shared with advertisers.
- No tool results. The IP, leak, speed, fingerprint and other tools compute their results in your browser. Results are shown to you and not sent to us. The IP tool reads your address from our own edge network's trace endpoint, which is how the page is served anyway.
What we do collect
- Server logs. Our host, Cloudflare, keeps standard access logs (IP address, request path, user agent) for security and abuse prevention, retained for a short period under Cloudflare's own policy.
- Google Analytics, with your permission. Loaded through Firebase, it tells us which pages are read, which links are clicked, how far down a page people get, and which tools are used. It sets cookies in your browser and Google processes the data on its own terms, which is the honest cost of knowing what to write next. We do not upload anything that identifies you, and we do not run Google Signals, advertising features or audience sharing.
- Consent before loading, in the EEA and the UK. If you are in one of those countries, nothing is fetched from Google until you press Accept on the banner. Declining is one click, the same size as accepting, and the site works identically either way. Your choice is kept in your browser's local storage — not a cookie — so no cookie exists unless you accepted. To change it later, use Analytics choice in the footer of any page. Your country is determined from our own edge network, which is already handling the request; no third party is told anything to work it out.
- Never, if you opt out. If your browser sends Global Privacy Control or Do Not Track, the analytics script is never loaded and you are never asked — not blocked after loading, never fetched. Most privacy-focused browsers and extensions send one of these by default, and any content blocker also stops it.
- Newsletter. If you subscribe, we store your email address and the date you confirmed, and nothing else. Double opt-in. Every email has a working one-click unsubscribe that deletes the address.
- Email you send us. Kept as long as the conversation is useful, then deleted.
Affiliate links
Some outbound links to VPN providers carry an affiliate tag. When you click one, the provider knows the visit came from this site. That is the extent of it; we do not see who you are.
Breach checker
The email breach tool uses the Have I Been Pwned k-anonymity model where possible: your browser sends a hashed prefix, not your address. Where the full address is required by the upstream API, the request passes through our own edge function, which does not log it. Details on the tool page.
Your rights
Under GDPR, the UK GDPR, CCPA and similar laws you can ask what we hold about you and have it deleted. For analytics, withdraw consent from the footer link on any page, or send Global Privacy Control, which stops collection at source; for the newsletter it is the unsubscribe link. Otherwise email hello@vpnandprivacy.com.
Changes
If this policy changes in a way that collects more, the date at the top changes and the newsletter says so.