Privacy Policy
Last updated: August 2026
AllURLScan processes the public website target you submit so it can perform a bounded diagnostic crawl and generate a report.
1. Information processed
The website URL you submit is processed by the AllURLScan server. The scanner normalizes crawl targets, removes query strings and fragments from internal URLs before they enter the crawl frontier, and observes only publicly reachable website responses within fixed safety budgets. The application does not require a user account or ask for a name, email address or physical location to run a scan.
2. Report data
A generated report can contain public page paths, HTTP status codes, bounded response timing and size measurements, selected response headers, page metadata, and diagnostic findings derived from those observations. Raw page bodies are used for analysis but are not stored in the V5 report ledger.
3. Data retention and sharing
When report persistence is enabled, the diagnostic report is stored so a shareable report URL can be opened without rescanning the target. New reports default to noindex and are not automatically admitted to search indexing. The V5 application report database does not intentionally store visitor IP addresses, browser cookies, authentication credentials or request headers as report fields.
4. Infrastructure logs and abuse prevention
Hosting, reverse-proxy, CDN and security infrastructure may process request metadata such as IP addresses, timestamps and requested paths for operations, rate limiting, security and abuse prevention. Those infrastructure records are separate from the diagnostic report model.
5. Cookies and analytics
The scanner does not require advertising cookies to operate. If analytics or additional optional tracking is introduced, this policy should be updated to describe that processing and any applicable controls.