Privacy statement
Last updated on 7 October 2026. Applies to snelle.tools. privacyschandpaal.nl has a statement of its own. This is a translation of the Dutch statement; where the two differ, the Dutch version prevails.
In short
- · Most tools run entirely in your browser. What you type there never leaves your device.
- · There are no advertising or tracking cookies on this site, and no advertising company is involved.
- · Visits are counted with a self-hosted counter that uses no cookies and builds no profiles.
- · The Leak Test, the Hosting Checker and the Email Test do keep reports — about the domain that was measured, not about you. Those reports are public: anyone who checks the same address sees the same result.
- · You never need to create an account, and nothing is sold or shared for advertising.
Who is responsible
Snelle.tools is a personal project of Theo van der Sluijs (the Netherlands), who is the controller within the meaning of the GDPR. Questions about privacy, or a request for access or erasure, go to security@privacyschandpaal.nl. Security reports are preferably sent via security.txt.
Tools that never leave your device
The calculator, the notepad, the password generator, the Markdown Converter, the Text Diff, the Text Meter and the Data Inspector run entirely in your browser. What you type or drop into them is not sent to the server and is therefore not stored anywhere. You can verify this by watching your network traffic while you use them.
A few things are stored locally in your browser — on your own device, not with us:
| What | Where | Why |
|---|---|---|
| snelle-tools-theme | localStorage | remembers whether you chose light or dark |
| snelle-tools-taal | localStorage | remembers a language you picked yourself in the language switcher, or that you dismissed the suggestion to view the site in another language; not a cookie, and it is not sent to the server |
| snelle-tools-kladblokken | localStorage | your saved notes |
| snelle-tools-admin-auth | sessionStorage | for the administrator only, after logging in |
Clear your browser data and they are gone — no copy exists on the server.
Tools that use the server
Five tools cannot run in your browser and use the server. What you enter there does travel over the internet.
Leak Test
The server opens the address you enter in a real browser. The resulting report — including one screenshot of the page as it looked when it was opened — is stored, so that a recent scan can be reused and you can see what has changed since. These reports are not secret: anyone who scans the same address or opens a shared link sees the same report. No visitor IP address is stored with a report, and personal data the scanner finds in outgoing traffic is masked before it enters the report.
So don’t enter addresses that are confidential in themselves — a link containing an invitation code or a token does not belong in a report that can be shared.
If the scanned address is listed on privacyschandpaal.nl, the report may also end up in the public ranking there. That only applies to sites already registered there.
Hosting Checker
The domain you enter is looked up in public sources: DNS records, the TLS certificate and the home page. These results are stored as well and are visible to anyone who checks the same domain. Only the domain and the public answers are stored, no visitor data.
Email Test
The domain you enter is looked up in public DNS data, and the server connects to that domain’s mail servers to see whether and how they encrypt. No email is sent and no email address is looked up — so enter a domain name, not an address. The result is stored and visible to anyone who tests the same domain; only the domain and the public answers are stored, no visitor data.
What is my IP?
Your IP address is looked up at that moment in GeoLite2 databases that sit on the server itself; no request goes to MaxMind or any other party. The result is shown and not stored.
Is it down?
This check takes two measurements, and the second is the only place on this site where your own browser contacts the address you enter directly. That is precisely the point of the tool — otherwise there is no telling whether the problem is your connection — but it does mean the checked site sees your IP address, just as if you had visited it. The check only looks at whether a connection is made; a page on another domain is not allowed to read what comes back, so it is not read. Nothing about this check is stored: no address, no result, no visitor data. Only an identical answer within one minute is reused from memory.
Redirect Follower
The server follows the redirects of the address you enter and shows the route. The requested addresses are not stored.
Cookies
There are no advertising, analytics or tracking cookies on this site. There are two functional cookies, and they only appear when you do something that needs them:
| Cookie | When | How long |
|---|---|---|
| donation_payment_id | when you start a donation, so the payment can be recognised | 1 hour |
| snelle-tools-admin | only after logging in to the admin panel | 12 hours |
Visitor statistics
To see which tools are used, this site counts page views with its own Umami installation (at teller.snelle.tools), running on its own server at Hetzner in Finland. So no visit data goes to an external analytics company. Umami sets no cookies, builds no profile and does not recognise visitors across websites. What is counted: the requested page, the referring page, the type of browser and device, the screen size, the language setting and the country. The IP address is only used to recognise repeat visits within one day and is not stored.
Contact and error reports
If you report a mistake in a report via “spotted a mistake?”, your message, the address it concerns and the report ID are stored. Your name and email address are optional: without an address the report is anonymous, but you won’t get a reply either. This data is only used to look into and answer the report, is not shared and is deleted once the report has been dealt with, after one year at the latest. If you email directly instead, the same applies to that message.
Donations
Payments are handled by Mollie B.V. (Amsterdam). Your payment details end up with Mollie, not here: this site only receives the amount, a payment reference and whether the payment succeeded. No name, address or account number of the donor is stored. Mollie’s own privacy policy applies to its processing.
Logs and abuse
The web server keeps ordinary access logs, containing among other things the IP address, time and requested page. They are meant for investigating outages and abuse and are not used to track visitors.
Because a scan costs the server work, there is a limit per IP address: at most eight leak test scans per ten minutes, a separate limit per ten minutes for the other checks, and at most five submitted forms per hour. For this, only timestamps per IP address are kept in memory; they disappear by themselves and are never written to disk.
Who else has access
As few parties as possible. This site runs on its own server at Hetzner in Finland — on the same machine as the counter above. No fonts, scripts or images are loaded from Google or any other external network; everything is on that server. Apart from that, only Mollie (for donations) and the mail server that forwards reports are involved. No data is sold or shared for advertising, and there are no transfers to countries outside the European Economic Area.
In fairness, there is one exception, and it is not about you but about the domain you have checked. The Hosting Checker and the Email Test ask two questions that only someone else can answer: whether a domain name is signed (via Cloudflare’s DNS service) and whether the network behind an IP address is authorised to announce it (via RIPEstat, run by the RIPE NCC in Amsterdam). What goes there is the domain or IP address being checked — never your IP address or anything else about you.
How long things are kept
| What | How long |
|---|---|
| Leak Test reports and screenshots | at most 1 year, and no more than 20 per address |
| Hosting checks | at most 1 year, and no more than 20 per domain |
| Email tests | at most 1 year, and no more than 20 per domain |
| “Is it down?” checks | not stored; at most one minute in memory |
| Error reports and contact messages | until dealt with, at most 1 year |
| Visitor statistics | aggregated, not traceable to a person |
| Server logs | briefly, only for outages and abuse |
Your rights
You have the right to access the data processed about you, and to rectification, erasure, restriction and to object to the processing (Articles 15 to 21 GDPR). Because there are no accounts and no visitor data is stored with reports, such a request will in practice concern a report or an email you sent. Send it to security@privacyschandpaal.nl; you will receive a reply within four weeks.
If you want a scan report of your own website removed, or want it to no longer be scannable, you can ask at that address too. If you disagree with how your request was handled, you can lodge a complaint with the Autoriteit Persoonsgegevens (the Dutch data protection authority, Article 77 GDPR), or with the supervisory authority in the EU country where you live.
Changes
If anything changes in the tools, the storage or the counter, this page is updated and the change is also listed in the version history. Nothing is added silently: a new cookie or a new external party belongs on this page before it exists.