Skip to content
whack.sh whack.sh
How it works Features Pricing FAQ News Sign in

Privacy Policy

Last updated: July 2, 2026

This policy explains what whack.sh collects, why, and your choices. As a defensive security tool we aim to collect only what we need to run the Service.

1. What we collect

  • Account data — your email and name, and, if you sign in with Google, your Google account identifier (we never receive your Google password).
  • Scan data — the URLs you submit and the artifacts we capture for them (HTTP metadata/HAR, screenshots, and a derived cloaking score). Any payload we retain is quarantined server-side for detection, not stored against your account. For a sampled portion of free datacenter scans, we may also load the same URL through a third-party residential network to compare what the site serves to different visitors; that comparison is not billed to you, and only a divergence indicator (whether the results differed) is retained against your account.
  • Usage & billing — credits consumed, plan, and your activity ledger.
  • Technical data — IP address, user agent, and request logs needed for security and abuse prevention.

2. How we use it

To provide and secure the Service, run scans, meter and bill usage, prevent abuse, respond to support, and improve the product. We do not sell your personal data.

3. Cookies

We use a strictly-necessary, httpOnly session cookie to keep you signed in, plus privacy-friendly analytics (Umami and Google Analytics 4) to understand aggregate usage. You can block analytics cookies in your browser.

4. Third parties

We rely on a small set of processors: Google (Sign-in with Google, and GA4 / Search Console analytics), Cloudflare (CDN, TLS, and DDoS protection), MailerSend (transactional email such as verification and password reset), PayPal (payment processing for credit purchases and subscriptions — your payment details are entered directly on PayPal and are never seen or stored by whack.sh), and third-party residential, mobile, and datacenter proxy networks that carry the vantage-point traffic for multi-egress scans, geo-pinned datacenter egress, and free-scan comparison legs (the submitted URL is loaded through them; they are not given your account data), and — for the optional plain-English scan summary — Google (Gemini API), which receives only aggregated finding metadata (verdict, signal categories, and counts), never your personal data or the raw target page content, under a no-retention key tier. Each processes data only to provide its function.

Separately, when a scan captures a file that is confirmed malicious, we contribute that file and its hashes to the public malware-research platforms VirusTotal, abuse.ch (MalwareBazaar) and AlienVault OTX so other defenders can detect the same threat. These contributions carry the malicious file and its technical metadata only — never your personal data, your account information, or the URL you scanned. See the Terms for details.

5. Brand Protection

If you use Brand Protection, we process the domains and brand terms you register and the DNS-TXT verification tokens you publish, and we match them against scans we run — including scans submitted by others and our automated threat sweeps — to detect compromise or impersonation. Alerts are delivered privately to you (email and/or your webhook) and are never published. When a finding originates in another party’s scan, your alert contains only technical indicators (such as observed domains and hashes); it never includes that party’s report or identity. The only data we ask you to publish is the DNS-TXT token.

6. Retention

Scan artifacts are retained while useful for your investigation and then periodically purged. Account data is retained until you delete your account. We may keep limited records as required by law or for security. A malware sample contributed to a public research platform (VirusTotal, abuse.ch MalwareBazaar, AlienVault OTX) is retained by that platform under its own policy and cannot be recalled or deleted by us.

7. Your rights

You can access, export, or delete your account data — contact us via the contact page and we’ll action verified requests. Depending on your location you may have additional rights under GDPR or CCPA.

8. Security

Data is encrypted in transit (TLS). Credentials are stored hashed, never in plaintext. Access to internal systems is restricted and network-isolated.

9. Children

The Service is not directed to anyone under 16 and we do not knowingly collect their data.

10. Contact

Privacy questions or requests? Reach out.

Product

Multi-source scanner Datacenter geo scanner How it works Features Use cases Pricing

Developers

API docs FAQ

Trust & transparency

Sample of the week Captured malware Report a mistake

Company & legal

About News Contact Terms Privacy
© 2026 whack.sh — multi-egress URL threat scanning Owned and operated by Tuxxin LLC · State of Florida, United States

Organizations, domains, IPs, ASNs & software stacks named in results are flagged by automated analysis from a documented history of observed cloaking and/or malware distribution — not a statement of fact about any party. Flagged in error? Request removal or re-review →