PRIVACY
Privacy policy
What this site collects, what it asks you first, and what happens to it. Written to match what the code actually does.
Last updated
The short version
- One thing sets cookies: Google Analytics, and only if you accept it. Decline and your browser never contacts Google.
- No advertising tags, no tracking pixels, no session recording, and Google's advertising features are switched off.
- Nothing else is loaded from anyone else. Fonts are served from this domain.
- No accounts, so nothing to sign up for and nothing to delete.
- The free tools keep your work in your own browser. It is never uploaded, whatever you choose about cookies.
Who we are
Trufend is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], New Zealand. For anything in this policy, write to hello@trufend.com.
This policy is written to the New Zealand Privacy Act 2020 and its information privacy principles. Visitors in the European Union and the United Kingdom have further rights under the GDPR and UK GDPR, and visitors in California under the CCPA; both are covered below.
Analytics, and the choice you are given
We use Google Analytics 4 to see which pages people read and roughly where they arrive from. It is ordinary traffic measurement: how many visits, which articles, which tools. We do not use it to build advertising audiences, and Google Signals and ad personalisation are both switched off.
Analytics needs cookies, so you are asked first. The tag is not on the page until you accept:
- Decline, or ignore the banner, and the Google tag is never loaded. Your browser makes no request to Google, and no analytics cookie is set.
- Accept, and Google Analytics sets two first-party cookies: _ga, which lasts two years, and _ga_ZV5QY9DVE8, which lasts two years. Both hold a randomly generated identifier so repeat visits can be recognised as the same browser. Neither contains your name or your email address.
You can change your mind at any time using cookie settings, which appears in the footer of every page. Withdrawing consent clears those cookies immediately and stops anything further being sent.
What Google receives, when you have accepted, is the page you are on, the page you came from, your approximate location from your IP address, and general device and browser information. Google Analytics 4 does not log or store IP addresses. Google acts as our processor for this and may handle it outside New Zealand, including in the United States, under its own terms and standard contractual clauses. Google's own explanation is at policies.google.com/technologies/partner-sites. You can also block it everywhere with Google's opt-out add-on.
The domain you type into the scanner is not sent to Google. Checks run as a background request, so the domain never appears in a page address or in an analytics event.
What is stored in your browser
Aside from the analytics cookies described above, which are yours to refuse, these stay on your device and are never transmitted to us:
- Your work in the free tools. The SPF and DMARC generator, security headers generator, CSP builder, incident response plan and vendor register each save what you type so you can close the tab and come back. This is held in your browser's local storage under keys beginning tf_. Clearing your browser data removes it, and so does the reset control in each tool.
- The domain you type on the home page, held for a few seconds in session storage so the report page knows what to check. It is discarded when you close the tab.
- Your cookie choice, so you are asked once rather than on every page.
None of those three requires consent under the Privacy Act or the European ePrivacy rules, because each is strictly necessary for something you asked the site to do. They are stored by the browser, not as cookies, and are never sent anywhere.
What happens when you run a check
A check is passive. The scanner requests the pages and DNS records your domain already publishes to anyone, the way an ordinary visitor or a search engine would. It does not log in, submit anything, or attempt to alter what it finds.
When you run one, the server holds:
- The domain you entered, for as long as it takes to produce the report.
- A copy of the report for one hour, in a file named after a hash of the domain, so that checking the same domain again returns the same result instead of re-scanning it.
- A counter entry: a shortened SHA-256 hash of the domain, kept only so that the same domain is not counted twice in the public scan total. The domain itself is not written down in readable form.
- A rate-limit record in a file named after a hash of your IP address, holding nothing but timestamps, which expires after ten minutes. It exists to stop the scanner being used to flood a target.
Our web host keeps standard server logs, which normally include IP addresses, for [RETENTION PERIOD, PER YOUR HOST]. We do not use those logs for analytics or profiling.
Reports are not published, not shared and not sold, and they are not sent to Google or anyone else. The only figure ever made public is the aggregate count of checks shown on the home page, which contains no domains.
If you give us your email address
The email form on this site is not connected to a mailing list yet, and nothing is transmitted when you use it. If that changes, this policy will be updated first, and your address will be used only to send what you asked for, with an unsubscribe link in every message.
Scanning a domain you do not own
Everything a check reads is already published to anyone who asks for it, so a report contains no private information about any person. If a domain's public pages happen to contain personal information, that information was already public; we do not extract, index or retain it beyond the one-hour report cache described above.
Where your information goes
The site and the scanner are hosted with [HOSTING PROVIDER AND COUNTRY]. Where that is outside New Zealand, information is only held there subject to comparable safeguards, as principle 12 of the Privacy Act requires. The only other party that receives anything is Google, for analytics, and only from visitors who have accepted it. Nothing else is disclosed to anyone, in New Zealand or overseas, except where the law requires it of us.
Your rights
Under the New Zealand Privacy Act you may ask what personal information we hold about you, ask for it to be corrected, and complain if you think we have handled it badly. Because we hold no accounts and no readable record of who checked what, in practice there is usually nothing to return. Write to hello@trufend.com and we will answer within 20 working days.
In the EU or UK you additionally have rights of access, rectification, erasure, restriction, portability and objection under the GDPR. For running the service safely, producing the report you asked for and preventing abuse of the scanner, the lawful basis is our legitimate interest. For analytics, the lawful basis is your consent, which you give or refuse on the banner and can withdraw at any time from the footer.
In California, we do not sell personal information, and we have not done so in the preceding twelve months. Because analytics can count as "sharing" under the CPRA when it feeds cross-context advertising, we have switched off Google Signals and ad personalisation, and declining the banner opts you out entirely. We do not offer financial incentives for personal information.
Children
This site is aimed at people running websites and is not directed at children. We do not knowingly collect information from anyone under 16.
Complaints
If we have not put something right to your satisfaction, you can complain to the Office of the Privacy Commissioner in New Zealand. Visitors in the UK may complain to the Information Commissioner's Office, and visitors in the EU to their national data protection authority.
Changes
If this policy changes in any way that matters, the date at the top changes with it and the first-visit notice is shown again.