Free check, no account

Before you leave your data in someone else's app

Paste the address. We will tell you who this app shares data with, who is behind it and what cannot be established from the outside. Plain language, no scare tactics and no single-number score.

What we check

For example tool.com. The address of the page everyone sees, not the one after sign-in.

We open the page the same way your browser would. We do not try to sign in anywhere, we do not bypass any security controls and we do nothing a regular visitor does not do. Only you will see the result.

Have a key, token, .env file or headers instead of an address? Paste them here. Recognition runs in your browser and sends nothing.

01

What we check

Six things that can be established without asking the owner for permission.

  • Who gets your data

    Third-party companies the site sends your browser to, and what for.

  • Who is behind it

    Whether there is an entity with a name, address and registration number, or just a website. How old the domain is.

  • Where what you type goes

    The address a form with a password or payment details is sent to.

  • Whether it says what happens to your data

    Whether a privacy policy and terms of service exist, or are an empty page with a heading.

  • Whether the connection is secured

    Encryption, the certificate and the cookies the service uses to recognize you.

  • Whether anything was left exposed

    Keys left in the page code, a technical panel open to everyone, an open directory of files.

02

What it costs

The check from a link is free and will stay free. Only checking more pages is paid.

  • Check from a link

    free

    The tool's home page, seen the way any visitor sees it.

    • Who is behind it and how old the domain is
    • Who the tool shares data with
    • Whether there is a privacy policy and terms of service
    • Whether the connection and cookies are secured
    • Five checks a day, no account
  • Deeper check

    49 PLN

    We look beyond the home page at the pages where forms and third parties usually sit: sign-in, sign-up, pricing and contact.

    • Up to nine additional pages of the same tool
    • The full list of companies the tool shares data with, from each of those pages
    • The addresses forms are sent to, including those with a password or payment
    • Result available at your link for thirty days

Deeper does not mean we go inside. Nobody but the owner can see the code and settings of someone else's app, so we do not sell something that cannot be delivered. Deeper means we look at more pages of the same tool, because forms and third parties are rarely on the home page. Only the app owner can order a check from the inside, and that is a separate service.

The deeper check cannot be bought yet. The free check works as usual.

03

What this is not

We put this at the top, not in the fine print at the bottom.

This is not a ruling that the app is secure. We see the surface, not the inside. The best possible result is no red flags in what is public, with a date and a scope.

This is not an accusation of fraud. We see what the site does, not the intentions of whoever runs it.

We do not try to break in anywhere. We open the site the same way your browser does. We do not bypass sign-in, we do not touch security controls and we do not test anything on someone else's server.

The result is yours. Only you see it, through the link you get. We do not publish findings about companies that did not ask us for anything, and we keep no list of shame.