Privacy policy
Last updated: 23 September 2026
I Love Protection (iloveprotection.com) is a free tool that checks the security of websites their owners have proven they control, and a free check of any domain’s public email records (SPF and DMARC). This page says what we collect, why, where it lives, how long we keep it, and how you get it back or deleted.
Who is responsible
The service is run from Switzerland (“we”). Contact for anything about your data, including every request below: hello@iloveprotection.com. A person reads it.
We apply the Swiss Federal Act on Data Protection (FADP) and, for people in the EU/EEA, the GDPR.
What we collect, and why
| Data | Why | Legal basis |
|---|---|---|
| Your email address | To sign you in (a one-time link, no password) and to send you your scan reports | Providing the service you asked for (GDPR Art. 6(1)(b)) |
| Workspace name and the emails of people you invite | To run a shared workspace; invited people receive one invitation email | Providing the service; for invitees, our legitimate interest in delivering the invitation you asked for (Art. 6(1)(f)) |
| Sites you add (address, domain, how you proved ownership, when) | To make sure we only ever scan sites their owner controls, and so you only prove it once | Providing the service; our legitimate interest in preventing misuse |
| Scans and their results (findings about your site, any note you typed) | To show and email you the report | Providing the service |
| Feedback you send (your message, your email if signed in, which report it is about) | To improve the tool | Legitimate interest |
| Waitlist entries (name, email) | To tell you when the scan opens | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Technical data: IP address, requested page, time, browser user agent | Operating and securing the service (our server and our network provider see every request) | Legitimate interest |
| Abuse-protection counters keyed by your email (for example how many sign-in links in the last hour) | To stop anyone flooding someone’s inbox or our service | Legitimate interest |
The public SPF/DMARC check needs no account. We use the domain you type to read two public DNS records, keep the answer in memory for up to 5 minutes so repeated checks are fast, and store nothing about you. We count how many checks happen per day, as a number only.
We do not use analytics, advertising or tracking. The site sets one cookie, ilp_session, only when you sign in; it keeps you signed in (strictly necessary, HttpOnly). In your browser we also store your language choice, whether you closed the waitlist window, and, for 30 minutes at most, the website address you pasted before signing in, so you do not have to type it twice. None of this leaves your browser.
What we do on a website you scan
Only after you prove you control it (a file on the site or a DNS record). The scan sends read-only requests (GET, HEAD, OPTIONS) from our server, identified as iloveprotection/1.0; methods that change data are refused in the code. We keep the findings, not copies of your pages. To list your domain’s public hostnames we look it up in public Certificate Transparency logs (crt.sh) and in DNS, so your domain name is sent to those services.
Who processes data for us
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services EMEA SARL | Database (DynamoDB), sending email (SES), secret storage | Frankfurt, Germany |
| Hetzner Online GmbH | The server that runs the API and the scans | Nuremberg, Germany |
| Cloudflare, Inc. | Hosting the website, DNS, email forwarding, network protection; sees every request’s IP address | Global network; transfers covered by the EU–US and Swiss–US Data Privacy Frameworks and standard contractual clauses |
| Sectigo Limited (crt.sh) | Public certificate-log lookup of a domain you scan (the domain name only) | United Kingdom (adequacy decisions of the EU and Switzerland) |
We do not sell or share your data with anyone else. We take no payments.
How long we keep it
| Data | Kept |
|---|---|
| Account, workspace, sites, scans and reports | Until you delete them or your account (no automatic expiry yet) |
| Sign-in links | 15 minutes, single use |
| Sessions | 30 days, or until you sign out or are removed from the workspace |
| Abuse-protection counters | Minutes to a few days, then deleted automatically |
| Daily check counts | 400 days; they contain no personal data |
| Server access logs (IP, path, time) | Up to 90 days |
| Waitlist | Until we have told you the scan is open and you have had the chance to sign up, or until you ask |
| Feedback | Until it has been read and acted on, at most 12 months, or until you ask |
Your rights
- See and download your data: on your account page, “Download my data” gives you everything we hold about you as a file.
- Delete it: on your account page, “Delete my account and data” erases your workspace, sites, scans, reports, sessions, feedback and waitlist entry, and removes you from other people’s teams. If a workspace you own is still used by others, you remove them first; we never delete someone else’s data.
- Correct it, object to it, or restrict it: write to hello@iloveprotection.com.
- Complain: to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to the data protection authority where you live in the EU/EEA.
We answer requests within 30 days.
Security
Sign-in links are single use and stored only as a hash. Sessions are HttpOnly cookies. Data is encrypted in transit (HTTPS) and at rest. The scanner can only reach sites that resolve to public addresses.
Changes
When this policy changes we update the date above and, for meaningful changes, tell signed-in users.