Privacy policy

Last updated: 23 September 2026

I Love Protection (iloveprotection.com) is a free tool that checks the security of websites their owners have proven they control, and a free check of any domain’s public email records (SPF and DMARC). This page says what we collect, why, where it lives, how long we keep it, and how you get it back or deleted.

Who is responsible

The service is run from Switzerland (“we”). Contact for anything about your data, including every request below: hello@iloveprotection.com. A person reads it.

We apply the Swiss Federal Act on Data Protection (FADP) and, for people in the EU/EEA, the GDPR.

What we collect, and why

DataWhyLegal basis
Your email addressTo sign you in (a one-time link, no password) and to send you your scan reportsProviding the service you asked for (GDPR Art. 6(1)(b))
Workspace name and the emails of people you inviteTo run a shared workspace; invited people receive one invitation emailProviding the service; for invitees, our legitimate interest in delivering the invitation you asked for (Art. 6(1)(f))
Sites you add (address, domain, how you proved ownership, when)To make sure we only ever scan sites their owner controls, and so you only prove it onceProviding the service; our legitimate interest in preventing misuse
Scans and their results (findings about your site, any note you typed)To show and email you the reportProviding the service
Feedback you send (your message, your email if signed in, which report it is about)To improve the toolLegitimate interest
Waitlist entries (name, email)To tell you when the scan opensYour consent (Art. 6(1)(a)), which you can withdraw at any time
Technical data: IP address, requested page, time, browser user agentOperating and securing the service (our server and our network provider see every request)Legitimate interest
Abuse-protection counters keyed by your email (for example how many sign-in links in the last hour)To stop anyone flooding someone’s inbox or our serviceLegitimate interest

The public SPF/DMARC check needs no account. We use the domain you type to read two public DNS records, keep the answer in memory for up to 5 minutes so repeated checks are fast, and store nothing about you. We count how many checks happen per day, as a number only.

We do not use analytics, advertising or tracking. The site sets one cookie, ilp_session, only when you sign in; it keeps you signed in (strictly necessary, HttpOnly). In your browser we also store your language choice, whether you closed the waitlist window, and, for 30 minutes at most, the website address you pasted before signing in, so you do not have to type it twice. None of this leaves your browser.

What we do on a website you scan

Only after you prove you control it (a file on the site or a DNS record). The scan sends read-only requests (GET, HEAD, OPTIONS) from our server, identified as iloveprotection/1.0; methods that change data are refused in the code. We keep the findings, not copies of your pages. To list your domain’s public hostnames we look it up in public Certificate Transparency logs (crt.sh) and in DNS, so your domain name is sent to those services.

Who processes data for us

ProviderWhat forWhere
Amazon Web Services EMEA SARLDatabase (DynamoDB), sending email (SES), secret storageFrankfurt, Germany
Hetzner Online GmbHThe server that runs the API and the scansNuremberg, Germany
Cloudflare, Inc.Hosting the website, DNS, email forwarding, network protection; sees every request’s IP addressGlobal network; transfers covered by the EU–US and Swiss–US Data Privacy Frameworks and standard contractual clauses
Sectigo Limited (crt.sh)Public certificate-log lookup of a domain you scan (the domain name only)United Kingdom (adequacy decisions of the EU and Switzerland)

We do not sell or share your data with anyone else. We take no payments.

How long we keep it

DataKept
Account, workspace, sites, scans and reportsUntil you delete them or your account (no automatic expiry yet)
Sign-in links15 minutes, single use
Sessions30 days, or until you sign out or are removed from the workspace
Abuse-protection countersMinutes to a few days, then deleted automatically
Daily check counts400 days; they contain no personal data
Server access logs (IP, path, time)Up to 90 days
WaitlistUntil we have told you the scan is open and you have had the chance to sign up, or until you ask
FeedbackUntil it has been read and acted on, at most 12 months, or until you ask

Your rights

  • See and download your data: on your account page, “Download my data” gives you everything we hold about you as a file.
  • Delete it: on your account page, “Delete my account and data” erases your workspace, sites, scans, reports, sessions, feedback and waitlist entry, and removes you from other people’s teams. If a workspace you own is still used by others, you remove them first; we never delete someone else’s data.
  • Correct it, object to it, or restrict it: write to hello@iloveprotection.com.
  • Complain: to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to the data protection authority where you live in the EU/EEA.

We answer requests within 30 days.

Security

Sign-in links are single use and stored only as a hash. Sessions are HttpOnly cookies. Data is encrypted in transit (HTTPS) and at rest. The scanner can only reach sites that resolve to public addresses.

Changes

When this policy changes we update the date above and, for meaningful changes, tell signed-in users.