Privacy Policy
Last updated: July 2, 2026
This policy explains what whack.sh collects, why, and your choices. As a defensive security tool we aim to collect only what we need to run the Service.
1. What we collect
- Account data — your email and name, and, if you sign in with Google, your Google account identifier (we never receive your Google password).
- Scan data — the URLs you submit and the artifacts we capture for them (HTTP metadata/HAR, screenshots, and a derived cloaking score). Any payload we retain is quarantined server-side for detection, not stored against your account. For a sampled portion of free datacenter scans, we may also load the same URL through a third-party residential network to compare what the site serves to different visitors; that comparison is not billed to you, and only a divergence indicator (whether the results differed) is retained against your account.
- Usage & billing — credits consumed, plan, and your activity ledger.
- Technical data — IP address, user agent, and request logs needed for security and abuse prevention.
2. How we use it
To provide and secure the Service, run scans, meter and bill usage, prevent abuse, respond to support, and improve the product. We do not sell your personal data.
3. Cookies
We use a strictly-necessary, httpOnly session cookie to keep you signed in, plus privacy-friendly analytics (Umami and Google Analytics 4) to understand aggregate usage. You can block analytics cookies in your browser.
4. Third parties
We rely on a small set of processors: Google (Sign-in with Google, and GA4 / Search Console analytics), Cloudflare (CDN, TLS, and DDoS protection), MailerSend (transactional email such as verification and password reset), PayPal (payment processing for credit purchases and subscriptions — your payment details are entered directly on PayPal and are never seen or stored by whack.sh), and third-party residential, mobile, and datacenter proxy networks that carry the vantage-point traffic for multi-egress scans, geo-pinned datacenter egress, and free-scan comparison legs (the submitted URL is loaded through them; they are not given your account data), and — for the optional plain-English scan summary — Google (Gemini API), which receives only aggregated finding metadata (verdict, signal categories, and counts), never your personal data or the raw target page content, under a no-retention key tier. Each processes data only to provide its function.
Separately, when a scan captures a file that is confirmed malicious, we contribute that file and its hashes to the public malware-research platforms VirusTotal, abuse.ch (MalwareBazaar) and AlienVault OTX so other defenders can detect the same threat. These contributions carry the malicious file and its technical metadata only — never your personal data, your account information, or the URL you scanned. See the Terms for details.
5. Brand Protection
If you use Brand Protection, we process the domains and brand terms you register and the DNS-TXT verification tokens you publish, and we match them against scans we run — including scans submitted by others and our automated threat sweeps — to detect compromise or impersonation. Alerts are delivered privately to you (email and/or your webhook) and are never published. When a finding originates in another party’s scan, your alert contains only technical indicators (such as observed domains and hashes); it never includes that party’s report or identity. The only data we ask you to publish is the DNS-TXT token.
6. Retention
Scan artifacts are retained while useful for your investigation and then periodically purged. Account data is retained until you delete your account. We may keep limited records as required by law or for security. A malware sample contributed to a public research platform (VirusTotal, abuse.ch MalwareBazaar, AlienVault OTX) is retained by that platform under its own policy and cannot be recalled or deleted by us.
7. Your rights
You can access, export, or delete your account data — contact us via the contact page and we’ll action verified requests. Depending on your location you may have additional rights under GDPR or CCPA.
8. Security
Data is encrypted in transit (TLS). Credentials are stored hashed, never in plaintext. Access to internal systems is restricted and network-isolated.
9. Children
The Service is not directed to anyone under 16 and we do not knowingly collect their data.
10. Contact
Privacy questions or requests? Reach out.
whack