Privacy Policy
Last updated: June 2026
Controller
Dominic QuaiserJahnstraße 60
09126 Chemnitz
Germany
Email: dominic@quaiser.dev
Overview
netz.tools is a connection and browser audit tool. It shows you what your IP, HTTP headers, and browser reveal. The service is operated privately and non-commercially on a Raspberry Pi in Germany. I have designed it to collect as little data as necessary.
No third-party scripts, analytics, advertising, or CDNs are embedded. All resources — including fonts and GeoIP databases — are served directly from my server. No data is transferred to any third party during normal use.
Data I process
IP address and connection data
When you visit this site, your IP address is received by my server. I use it to display it to you (the primary purpose of this service), to look up approximate geographic location and ASN using locally installed MaxMind GeoLite2 databases (no data is sent to MaxMind), and to perform a reverse DNS lookup. Your IP address is not stored — it is discarded after your request is handled. Access logging is disabled by default.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating the service.
HTTP headers
Your browser's HTTP headers are displayed to you and are not stored.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating the service.
DNS leak test
If you run the DNS leak test, your browser resolves a unique one-time hostname. My authoritative DNS server records the resolver's IP address (the DNS server that handled the query, not your browser's IP), the EDNS Client Subnet (ECS) prefix — if provided by the resolver and rounded to /24 for IPv4, /48 for IPv6 — and a timestamp. These records are automatically deleted after 10 minutes.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in providing the DNS leak test.
IPv6 leak test
If the IPv6 leak test is enabled, your browser fetches two sub-resources — one forced over IPv4, one over IPv6. These requests go to first-party subdomains of this site and are subject to the same IP processing described above: displayed to you, not stored.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in providing the IPv6 leak test.
Anonymous fingerprint statistics
When you run the audit, your browser submits a set of generalised fingerprint trait values (for example a coarsened language preference, not your raw user-agent string) so the page can show how common your setup is. Only aggregate counters are stored — there is no per-visitor row, no IP address, and no timestamp.
The combined fingerprint is never stored as such. It is folded into a Count-Min Sketch: a fixed-size grid of plain integer counters. This structure cannot be reversed to recover any fingerprint, cannot be enumerated, and holds no per-device entry — it can only return an approximate "how often was this seen" figure to a browser that already holds its own fingerprint. Very rare fingerprints are additionally suppressed (k-anonymity), so the page never confirms that a device is unique.
To ensure the same browser is not counted repeatedly, a short-lived deduplication filter records whether a fingerprint has already been counted in the current 24-hour window. It is a Bloom filter — it stores only opaque bit positions, never the fingerprint and never your IP address, cannot be reversed, and is cleared every 24 hours.
Because these counters contain no information that can single out or re-identify a person, they are anonymous data within the meaning of GDPR Recital 26 and fall outside the scope of the Regulation. To the extent any processing is nonetheless assumed, the legal basis is Art. 6(1)(f) GDPR — legitimate interest in deriving rarity estimates. No information is stored on or read from your device for this feature, so no consent under § 25 TDDDG / the ePrivacy Directive is required.
Browser storage (cookies / localStorage)
I do not set any cookies and do not keep any persistent entries in your browser's localStorage. The audit briefly writes and then immediately deletes a test value to detect whether storage is available to your browser — part of the audit you requested — but nothing is retained afterwards. Nothing is stored to track you across visits or sites.
Data retention
| Data | Retention |
|---|---|
| IP address (per request) | Not stored — discarded after the request |
| DNS resolver IP | ≤ 10 minutes, then automatically deleted |
| Aggregate counters & fingerprint sketch | Indefinitely (anonymous; no personal data contained) |
| Deduplication filter (Bloom bits) | ≤ 24 hours, then automatically cleared |
| Server access logs (if enabled) | Operational use only, no fixed schedule |
Your rights
Under GDPR you have the following rights regarding your personal data:
- Access (Art. 15): request information about data I hold about you.
- Rectification (Art. 16): have inaccurate data corrected.
- Erasure (Art. 17): request deletion of your data ("right to be forgotten").
- Restriction of processing (Art. 18): restrict how I process your data.
- Objection (Art. 21): object to processing based on legitimate interest.
- Data portability (Art. 20): receive your data in a structured, machine-readable format.
To exercise your rights, contact: dominic@quaiser.dev
Note: because I do not store per-visitor records (IP addresses are discarded immediately), I may be unable to locate data associated with a specific individual.
Supervisory authority
If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority for Saxony:
Sächsischer Datenschutz- und Transparenzbeauftragter (SächsDTB)Bernhard-von-Lindenau-Platz 1
01067 Dresden
Germany
www.datenschutz.sachsen.de