Internet Times is built to be useful without harvesting your data. This page describes exactly what we log, what we do not, and what choices you have. Last updated: May 2026.
Summary
The short version: we run the checks you ask us to run and we keep the results, because a history of what changed is the product. We log the request the way every web server does, set two essential cookies if you sign in, and load no third-party script unless you accept the cookie banner. What we keep, and for how long, is spelled out below.
What we do not do
- We do not load Google Analytics, Facebook pixels, or any other third-party trackers by default.
- We do not sell your data, ever.
- We do not require an account to use the free tools.
- We do not use dark patterns to get you to opt in to anything.
- We do not link what you look up to who you are, unless you verify ownership of a domain yourself.
Advertising
Some pages can carry an ad from a third-party network. Those slots render only if you have accepted the cookie banner, and never for signed-in Pro subscribers. Decline, or simply ignore the banner, and no ad-network code is loaded at all.
What we collect
Web server access logs
Every request to InternetTimes.com is logged like any other website: your IP address, user agent, requested URL, referrer, and timestamp. These logs are kept for 30 days for debugging and abuse detection, then automatically rotated out.
What you look up, and the results
When you run a check, the subject you type (a domain, host, IP or URL) is sent to our server, and both the subject and the result are stored. This is deliberate: repeat lookups are served from that store instead of hammering the registries and resolvers again, and the stored history is what lets an audit tell you that a certificate issuer or a DMARC policy changed last Tuesday.
Concretely, we keep the subject, the result of each check, and a dated record of each time a result changed. We also count how many times a domain has been audited, so we can show which ones are being looked at.
These records are about domains and addresses, which are public infrastructure facts, not about you: they are not linked to your IP or to your account unless you deliberately claim a domain by verifying ownership. WHOIS output is a special case — registrant, admin and technical contact blocks are stripped before anything is cached, because those can carry personal data about third parties.
The one place we store an IP alongside a measurement is the speed test, where the result is meaningless without knowing the country and network it came from. Those addresses are erased after 90 days.
Audit pages are public
An audit at /audit/<domain> is a public URL: anyone who knows or guesses the address can open it. We do not advertise what other people look up — the examples on the audit page are a fixed list of well-known sites, not a feed of recent visitors — and audit pages are marked noindex so search engines do not add them to their results. They are still not secret, so do not audit a hostname you would not want a stranger to open. If you need one removed, contact us.
Account data (only if you register)
If you create an account, we store: your email, a bcrypt hash of your password (never the plaintext), your last-login timestamp, and your subscription tier. That is it.
API key data (only if you create one)
If you create an API key, we store the SHA-256 hash of the key (never the plaintext), the date created, and a per-day call counter for rate limiting. We can never recover a lost key — you generate a new one if you lose it.
Cookies we set
PHPSESSID— an essential session cookie. Set only when you sign in. Used to keep you signed in across pages and to protect form submissions. Expires when you close the browser, or after 2 hours of inactivity.theme— a tiny preference cookie (1–2 bytes) recording your dark/light theme choice. Expires after a year. Not used for tracking.cc_accepted— records whether you have accepted or declined optional analytics, so we do not nag you on every page. Expires after a year.
If you accept optional analytics from the cookie banner, we may set additional cookies for the analytics provider configured by the site admin. The provider is disclosed when you accept.
Third-party services
By default, none. If you accept optional analytics, those requests go to the configured provider. The tools themselves use public DNS resolvers (Google, Cloudflare, Quad9, OpenDNS), public WHOIS servers (registries and registrars), and public RBLs — these third parties see the input you typed but not your IP.
Data retention
- Access logs: 30 days, then deleted.
- Check results (the current state of a domain): kept until superseded by a newer result.
- Change history for a domain: kept for as long as the plan watching it allows — 30 days for domains nobody monitors and for the free tier, longer on paid plans, up to two years. Older history is deleted automatically.
- Speed-test IP addresses: erased after 90 days. The anonymous speed measurement itself is kept.
- Account data: retained while your account is active. Deleted within 30 days of account deletion.
- API call counters: reset daily at 00:00 UTC.
Your rights
You can:
- Request a copy of your data — email [email protected].
- Request deletion of your account and data — same email. We delete within 30 days.
- Withdraw consent for optional analytics at any time — clear the
cc_acceptedcookie, refresh, and decline.
EU/UK GDPR rights
If you are in the EU or UK, you have additional rights under GDPR/UK-GDPR: access, rectification, erasure, restriction, portability, and objection. We honour these on request — same privacy email above. If you believe we have not handled your request properly, you have the right to complain to your local data-protection authority.
Children
Internet Times is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe we have, contact us immediately and we will delete the data.
Changes to this policy
If we materially change this policy we will update the "Last updated" date at the top and post a notice on the homepage for 30 days. Significant changes affecting registered users will be sent by email.
Contact
Privacy questions or data-rights requests: [email protected]