Privacy

What we keep, and for how long.

Checkover is operated by the team behind checkover. This page says what happens to the information you give us. It is short because there is not much of it.

When you scan a site

We fetch the address you typed, its home page, the files that page loads, and public records about the domain. The result is a report, stored for thirty days under a random identifier so you can come back to it or share it. After thirty days it is deleted.

The report contains what the site showed to any visitor. It does not contain anything about you. We do not record your own address, and the site being scanned is not told who asked.

If you give a business profile (monthly visitors, order value), it is stored with the report so the arithmetic can be shown. It is not used for anything else.

When you open an account

We store your email address, a scrambled form of your password that cannot be turned back into the password, the date you joined, your plan, and the sites you have added. Passwords are hashed with scrypt.

Signing in sets one cookie, checkover_session, which the browser cannot read and which expires when you sign out. There are no other cookies. There is no analytics script, no advertising pixel, and no session recording.

You can download everything we hold about you, change your password, or delete the account and every site on it from the account page. Deletion is immediate and not reversible.

When a site is watched

A watched site is scanned once a day. Each scan is kept as a report for thirty days; the timeline of what changed is kept with the site until the site or the account is removed. If you set a webhook address, we send a short message there when something new and serious appears, and nowhere else.

Who else sees anything

Nobody is sold or given your data. A scan does ask public services about the site being checked, one question each, and none of them are told who asked: certificate transparency logs (crt.sh, Cert Spotter), domain registries over RDAP, public DNS resolvers including the filtering resolvers run by Quad9, Cloudflare and CleanBrowsing, Shodan InternetDB, the OSV vulnerability database, the Google Safe Browsing service where an operator has enabled it, and the cloud storage providers a site references. Each receives the hostname or a public address, and nothing about you.

The site runs on Vercel, which handles the request and keeps ordinary server logs for a short period under its own policy.

Your rights

Under UK and EU data protection law you can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. The account page does all three without asking us. For anything else, the address in security.txt reaches the people who run the service.