Last updated: 18 July 2026
1. Introduction
This policy explains what WHOISleuth processes when you use it, why, and what choices you have. It applies to this deployment. By using the service, you agree to the practices described here.
2. Information processed
Registry data. Looking up a domain returns whatever registrant contact data its registry or sponsoring registrar publishes through RDAP or WHOIS. The service relays this already-public registry-ecosystem data at your request; most sources redact it by default.
Registrar RDAP in deep Lookup. When a registry RDAP object publishes a complete HTTPS link for the same domain at the sponsoring registrar, a deep non-compact Lookup can relay that one public registrar object as a separately attributed source. It is briefly cached in server memory like other registry responses, displayed in the transient Lookup result, and never consulted by availability or scoring. Fast and compact Bulk requests do not perform the follow-up, and registrar RDAP is not copied into browser-local watchlists, cases, or other compact stores. The deliberate raw unified-response view can contain it. The structured Lookup evidence export can retain the normalized portable-field comparison between registry and registrar publications, including both displayed source values and source-health states, but excludes the registrar raw object, contacts, entities, links, notices, and source-specific handles.
Optional archived-verdict search. If the operator explicitly enables the URLscan adapter and you select it for a deep single-domain Lookup, the server sends only the canonical registrable domain to URLscan's Search API. It searches existing public scan history and never submits the domain or URL for scanning. The provider also receives ordinary API request metadata and associates the query with the operator's API credential under its own privacy and retention policy. WHOISleuth keeps no provider cache; the bounded normalized response is displayed transiently, excluded from browser-local stores and the structured Lookup evidence export, and never affects availability. Fast and compact Bulk paths never make this request.
Optional malware-host search. If the operator explicitly enables the URLhaus adapter and you select it for a deep single-domain Lookup, the server posts only the canonical registrable domain to URLhaus's host API. It searches existing malware-distribution records and never submits a URL, sample, or report. The provider also receives ordinary API request metadata and associates the query with the operator's API credential under its own privacy and retention policy. WHOISleuth keeps no provider cache; the bounded normalized response is displayed transiently, excluded from browser-local stores and the structured Lookup evidence export, and never affects availability. Fast and compact Bulk paths never make this request. Community access is subject to not-for-profit fair-use terms; commercial deployments may require a paid provider agreement.
Optional malware-IOC search. If the operator explicitly enables the ThreatFox adapter and you select it for a deep single-domain Lookup, the server sends only the canonical registrable domain in an exact-match search to ThreatFox. It searches retained malware indicators and never submits an IOC, URL, sample, or report. The provider also receives ordinary API request metadata and associates the query with the operator's abuse.ch credential under its own privacy and retention policy. WHOISleuth keeps no provider cache; the bounded normalized response is displayed transiently, excluded from browser-local stores and the structured Lookup evidence export, and never affects availability. Fast and compact Bulk paths never make this request. Older indicators expire from the community API, and commercial deployments may require a paid provider agreement.
Derived external Risk context. Optional provider payloads stay transient and separately attributed. A lone publisher, neutral miss, failed provider, unknown provider, or non-phishing/non-malware category adds no Risk points. When positive qualifying records are corroborated across at least two independent publisher families, Risk model v5 can add one bounded factor. Multiple datasets operated by the same publisher count as one source. Browser-local cases and reports can retain the resulting score, model version, and factor label, but not raw provider findings, references, or payloads.
Technical data. Standard request metadata, including IP address and timestamps, is processed transiently for login and rate limiting. When the operator enables optional distributed operation limits, the configured counter service stores only operation classes, opaque lease identifiers, expiry timestamps, and a one-way hash of the already-opaque session fingerprint. If durable usage accounting is also enabled, it stores bounded operation-feature identifiers, fixed 24-hour/30-day bucket identifiers, and integer counts. It receives no lookup targets, evidence, responses, browser-local records, or session tokens; leases expire after five minutes and usage counters expire shortly after their fixed window ends.
Optional hosted scheduled monitoring. This is disabled by default. When the operator explicitly enables the Netlify worker and a scheduled watchlist is present, it retains the bounded watchlist name, canonical domains, interval, timestamps, compact fast registration evidence, six recent change events, and an opaque resumable run cursor. It never stores raw RDAP or WHOIS payloads, expanded contacts, analyst notes, browser sessions, or deep website content. The complete state is encrypted and authenticated with AES-256-GCM before it is written to the site-wide Netlify Blob store; Netlify stores the ciphertext and ordinary object metadata, while its function runtime necessarily processes the decrypted state transiently to run requested public lookups. The scheduled worker has no public route. A separate authenticated management route lets a signed-in user deliberately schedule a browser-local watchlist, read the bounded hosted projection, pause or resume it, replace its hosted snapshot, restore that compact snapshot into the current browser, or delete the hosted copy. Mutations require a same-origin request and request bodies are capped at 1 MiB. This deployment uses one shared login and has no per-user roles or audit identities, so every person given that login can view and manage the same hosted scheduled-watchlist state. Restoring a snapshot creates or replaces a browser-local watchlist only after explicit confirmation. Disabling the worker stops Blob and lookup work but does not delete existing ciphertext; the operator or an authenticated user must remove hosted state deliberately when its history is no longer required. Replacing or losing the encryption key without migrating the state makes the retained ciphertext unreadable.
Deep lookup evidence. A requested deep lookup can display bounded HTTP metadata and static page-identity fields derived from the homepage response already fetched for analysis. Page identity can include language, canonical and meta-refresh targets, selected Open Graph fields, generator metadata, forms, normalized resource counts, external resource and embedded origins, mail-contact domains, download context, recognized public tracking identifiers, and versioned page fingerprints. Fingerprints cover the exact captured body, noise-reduced normalized HTML, visible text, static tag structure, form structure, external resource hosts, and public tracking identifiers. Intermediate normalized markup and visible text are discarded after hashing. URL credentials, queries, fragments, resource and download paths, form-action paths, and complete email addresses are not retained. When the active Brand Profile has a compatible official-site baseline, Lookup compares these bounded components locally and independently. It creates no combined page-similarity score, does not change the Risk score, and does not persist or export the derived comparison. Bulk can also compare bounded nameserver, IP-address, favicon, public-tracking-identifier, and configured official-asset-host observations within its current result set. Monitor can derive a capped local graph and table from exact nameserver-set and final-origin observations already retained in browser-local case histories. A deliberate local graph download can include filtered case domains, exact relationship values, methods, classifications, sources, observation times, completeness, truncation, limitations, and up to 8 bounded source observations per relationship as versioned JSON, GraphML, or GEXF. It excludes case notes, status, disposition, raw registry or page responses, contacts, credentials, and transient graph view state. These comparisons and downloads make no additional requests and are not saved as relationship records. Fingerprints and shared observations support comparison but do not prove authorship, ownership, coordination, intent, or maliciousness. The complete rich page-identity record is not copied into Bulk, watchlists, or analyst cases.
Audience measurement. The service does not use advertising, behavioural profiling, or cross-site tracking. Any privacy-preserving audience measurement introduced by the operator must stay on public pages and be described in this policy before it is enabled. Protected investigation routes, lookup terms, saved evidence, and session identifiers remain outside that scope.
3. How information is used
- To perform a lookup, scan, posture audit, or search you request.
- To keep you signed in.
- To enforce limits that protect the service and upstream registries.
Published registrant data is not used to build profiles, sold, or shared with advertisers.
4. Legal basis
Where GDPR or similar law applies, operation of requested lookups and anti-abuse controls relies on legitimate interest. Exporting, saving, or acting on displayed data is your decision. Any registrant outreach should remain low-volume, human-reviewed, compliant with applicable law, and stop when requested.
5. Third parties
Requests may reach the relevant registry or registrar, public DNS, a domain's MTA-STS policy host, crt.sh, and the infrastructure hosting this deployment. When the optional archived-verdict adapter is configured and explicitly selected, URLscan receives the canonical registrable domain and ordinary API request metadata for a search-only request under its own terms, privacy policy, and account quota. When an optional abuse.ch adapter is configured and explicitly selected, URLhaus or ThreatFox receives the same bounded domain target and ordinary request metadata for a host or exact-match IOC lookup under its own fair-use terms, privacy policy, account quota, and retention rules. These integrations do not submit a target for scanning or reporting. If distributed operation limits are enabled, their configured REST service processes the minimal lease and optional fixed-window counter metadata described above. If hosted scheduled monitoring is enabled, Netlify Functions performs the bounded lookups and Netlify Blobs retains its application-encrypted state and ordinary object metadata. No advertising or CRM processors are used. Any audience-measurement processor would be identified here before it is enabled.
6. Cookies and browser storage
The service sets one signed session cookie, wrt_session, for up to 30 days. It is HttpOnly, SameSite=Lax, and Secure over HTTPS. It is required for authentication and is not used for tracking.
Appearance preference. The Theme selector can retain one bounded dark, light, or system value in this browser's local storage under whoisleuth:theme:v1. It is not sent to the server. It is included only when you deliberately download a unified workspace archive so the receiving browser can restore the selected appearance. Without a saved value WHOISleuth follows the browser's operating-system preference. Clearing site data removes the preference.
Brand profiles, shortlist entries, ordinary watchlists, analyst cases, campaigns, and bounded Certificate Transparency search baselines stay in your browser's local storage. Only a separately selected scheduled watchlist may enter the optional encrypted hosted store described above. Campaigns contain a bounded label, optional description, and normalised case-domain membership only; they do not copy case evidence, notes, status, or disposition. Watchlists and cases may retain compact HTTP facts from deep checks: the final origin without its path or query, response status, transport, redirect count and flags, MIME type, and which selected security headers were present. Header values are not retained. CT baselines retain normalised search keywords, observed public domains, timestamps, and result counts so later searches can identify new observations; they can be deleted individually or cleared from Discover. A posture audit sends only the selected official domain and configured DKIM selectors to this deployment. Clearing site data removes all saved browser-local state but does not delete separately retained hosted-monitoring ciphertext.
Public synthetic demo. The unauthenticated demo uses fixed fictional fixtures on reserved domains to represent Dashboard, Brands, Discover, Bulk, Lookup, and Monitor without performing a live analysis request. Its bounded stage flags, selected fixture identifier, synthetic case status/note, and follow-up state stay only in the current tab's sessionStorage under whoisleuth:synthetic-demo:v1, never enter production browser-local stores, and are removed by Reset demo or when the tab session ends. Downloaded demo packages are explicitly marked as synthetic and are not live findings or evidence reports.
Guided investigations. An authenticated user can optionally start a fixed brand-sweep, infrastructure-pivot, or new-domain-triage guide for one canonical domain. The versioned storage contract calls the selected guide a recipe; schema version 2 keeps only that recipe identifier and domain, creation/update timestamps, active or paused state, and bounded stage approval, opened, and outcome markers in the current tab's sessionStorage under whoisleuth:investigation-guide:v2. A deployed version 1 navigation record can normalize into the new-domain triage recipe when no current record exists; future records remain untouched. Guide progress is not sent to the server or copied into persistent browser stores, and it is not treated as evidence completion. A network stage requires an explicit approval marker before its workspace link becomes available, but opening that link still never starts a lookup, search, scan, submission, export, or Monitor action. Export summary requires confirmation and deliberately downloads only a versioned compact progress record without raw evidence, notes, credentials, provider responses, or scan results. A read-only local checkpoint derives retained observation and relationship counts from the typed investigation projection without deciding stage completion. End guide removes both current and migrated legacy tab records, and closing the tab session removes them with the rest of that tab's session storage.
CSV, JSON, Markdown, HTML, GraphML, GEXF, and other stated local exports are generated in your browser. Campaign exports contain their labels, descriptions, domain membership, and timestamps, so review them before sharing. Relationship graph exports contain the bounded filtered relationship evidence described above. A deliberate unified workspace archive can contain cases and their analyst notes, campaigns, Brand Profiles, watchlists, shortlist entries, custom detection rules, active-profile selection, and theme preference. It uses a versioned manifest with per-section SHA-256 checksums, previews conflicts before a non-destructive merge, and excludes sessions, passwords, API credentials, hosted-monitor encryption keys, raw upstream payloads, tab state, Certificate Transparency history, and unrelated browser storage. The archive is unencrypted, so secure it like the analyst records it contains. Evidence exports may contain contact data published in raw RDAP or WHOIS responses and the bounded page-identity evidence displayed by Lookup.
7. Retention
Lookup and posture results are discarded after each server request. Browser-local investigation data persists until you remove it or clear site data. Optional hosted scheduled-monitoring ciphertext persists until the operator removes its Blob; disabling the worker does not delete it. You are responsible for securing and deleting downloaded exports.
8. Security
Controls include a shared-password gate, signed HttpOnly cookies, per-IP rate limiting, a restrictive Content Security Policy, and SSRF/DNS-rebinding protections for outbound checks. No system is perfectly secure, and the service is provided as is.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to processing. The service has no individual user-account database. Requests concerning registry-published data should generally go to the responsible registry or registrar; saved lists and exports remain under your control, and an operator who enables hosted scheduled monitoring must also manage its encrypted Blob state.
10. International transfers
Registries and hosting infrastructure may operate in other countries, so requested lookups can involve international processing inherent to RDAP, WHOIS, DNS, and web hosting.
11. Children's privacy
The service is not directed at children and is not knowingly used to collect personal data from children.
12. Changes
This policy may change over time. Material changes will update the date shown above.
13. Contact
Public support requests are not handled through this site. People authorised to use the protected console should contact the operator who provided access; data-subject requests should use the contact designated by that operator. The repository contains the complete privacy documentation.