Skip to main content
Legal · Last updated 30 September 2026

Privacy Policy

SlowCheck is designed to be private by default. No accounts, no cross-site tracking, no data selling.

1. Page URLs and analysis results

  • Page URL you submit: fetched to measure that single public page. Not crawled as a site. Stored with the scan job and analysis result. A completed result is reused for about 60 minutes so the same URL is not rescanned immediately; the rows stay in the database until the operator removes them.
  • Analysis results: scores, aggregate metrics (bytes, counts, timings), derived diagnostics, date and time of the analysis, and resource URLs found on that page (up to 500 per scan — images, scripts, styles, and other assets the page loads). No account or personal data in results.

2. IP addresses and technical logs

  • IP for rate limiting: temporary in-memory count (10 checks/hour) held ≤2 hours, then purged. Rate limiting does not use the page URL.
  • Operational log lines: used for troubleshooting, abuse detection, security, and reliability. These may include a page URL or an IP address and are kept for about 6 months.
  • Product events: first-party product events (page views, scan start/complete/fail, tool page views) are written to application logs without cookies, IP addresses, or email addresses.

3. Contact form messages

If you contact us through the contact form, we collect your name, your email address, an optional subject, and the contents of your message. We use them only to handle your enquiry, and they are stored in the database so the operator can reply. Sending is limited to 5 messages per hour per connection.

4. What we do not collect

  • No account, profile, or password. Name and email are stored only if you choose to submit them through the contact form.
  • No cross-site tracking, no ad profiling, and we do not sell personal data.
  • No private network access — requests to localhost and private IP ranges are blocked.

5. How we use information

  • Provide the website analysis and display the results;
  • Operate, maintain, and improve the Service;
  • Apply rate limits and prevent abuse and misuse;
  • Protect the security and integrity of our systems;
  • Troubleshoot errors and technical problems;
  • Respond to enquiries sent through the contact form;
  • Understand aggregate Service usage from first-party product events; and
  • Comply with applicable legal obligations.

6. Cookies, ads and analytics

Essential cookies only (CSRF token for the analyze form). No analytics cookies and no third-party analytics scripts are currently used. If advertising (e.g. Google AdSense) or third-party analytics is introduced, this policy will be updated and consent will be requested where required. Third-party ad providers may use cookies under their own policies once ads are enabled.

7. Data retention

  • Rate-limit IP counts: memory-only, purged within about 2 hours.
  • Operational log lines (may contain a page URL or IP): about 6 months.
  • Product analytics events: no IP addresses or email addresses; kept with the logs (about 6 months).
  • Scan jobs and analysis results: reused for about 60 minutes by page URL and scan mode; otherwise they remain in the database until the operator removes them.
  • Contact form messages: kept until the request is handled, then deleted by the operator.

We may delete or anonymize information earlier where it is no longer reasonably necessary. Retention periods may change as the Service and legal obligations develop.

8. How we test

We measure your page under consistent conditions (fast connection). Your visitors may see different speeds depending on their device, location and internet connection. We do not make up numbers — anything we couldn't measure is shown as “Not available”.

9. Measurement services

To capture performance metrics, the public page URL you submit may be sent to a trusted measurement provider over HTTPS (for example, Google PageSpeed Insights). Only the public URL is shared — no account data, no private pages. Providers process the request under their own terms and privacy policies, and we are not responsible for their handling of it.

10. Sharing of information

We do not sell personal data. We share information only with service providers that process it on our behalf where reasonably necessary to operate the Service — for example, hosting and measurement providers. We may also disclose information where reasonably necessary to comply with applicable law or legal process, respond to lawful requests, protect our rights, property, or security, investigate abuse, fraud, or security incidents, or protect the Service or other persons.

11. Security

  • HTTPS only: the site is served over encrypted connections (HSTS in production).
  • Private networks blocked: scans refuse localhost, private, and internal IP ranges so the tool cannot be used against your network.
  • Safety headers: content-security, frame, and content-type protections are applied to SlowCheck itself.
  • Rate limiting: per-IP limits reduce abuse; temporary IP counts are memory-only and purged within 2 hours.
  • Isolated measurement: each check runs for that one URL only — not a standing session against your site.
  • No secrets in results: reports contain only metrics and diagnostics for the public page you asked us to check.

We use reasonable technical and organizational measures to protect information, but no internet-based service can guarantee absolute security. Please take reasonable precautions when submitting information over the internet.

12. Your rights

Subject to applicable law, you may have rights relating to your personal data, including rights to request access to, correction of, or deletion of personal data. Send a privacy-related request through the contact form. We may need to verify a request before acting on it where reasonably necessary to protect privacy and security.

13. Children's privacy

The Service is not specifically directed toward children, and we do not knowingly request personal information from children for purposes unrelated to providing the Service.

14. External websites

The Service may contain links or references to third-party websites. We are not responsible for the privacy practices, content, security, or policies of those websites — review their policies before providing them with personal information.

15. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, data practices, technology, or legal requirements. When we make changes, we update the “Last updated” date at the top of this page. The policy is effective as of that date and may be revised as features (e.g., whole-site scanning, analytics) evolve.

16. Contact

For privacy questions, concerns, or requests, send a message through the contact form. See also the Terms of Use.