Privacy Policy
Last updated 10 September 2026
Summary
Using netsh.io’s diagnostic tools requires no account and does not store the domains, IP addresses, or URLs you check — those requests are processed statelessly, and the result is returned to your browser without the query itself being written to a database. Creating a free account is optional and only needed to generate an API key for programmatic access; doing so stores the account and key details described below.
Data processed to run a check
The target you enter (a domain, IP address, or URL) is sent to netsh.io’s servers, used to perform the requested check, and returned to you — it is not logged as searchable history. Your IP address is processed transiently to enforce a per-IP rate limit that prevents automated abuse; this is held briefly in server memory or, if a Redis-backed limiter (Upstash) is configured, under a short, automatically expiring key. If you join the SSL expiry waitlist, the email address you submit is sent only to the operator’s configured webhook endpoint.
Data processed for an API account
Signing in — via Google, or via a passwordless email link — is only needed to create and manage API keys for netsh.io’s public API. Signing in with Google stores the name, email address, and profile photo Google provides; signing in by email stores only the email address. A session cookie keeps you signed in across requests (see Cookies below). Each API key is stored as a one-way (SHA-256) hash — the plaintext key is shown once at creation and never saved anywhere, including by us — alongside when it was created, when it was last used, and a rolling count of daily requests per key to enforce the free-tier limit. Revoking a key or asking us to close your account (contact below) removes this data.
Cookies
netsh.io runs no advertising, so there are no advertising cookies to accept or reject. We use Umami for basic traffic analytics — page views and referrers, in aggregate. Umami sets no cookies, assigns no persistent identifier to your browser, and never links activity back to you individually; it can’t track you across visits or across other sites. On your first visit, a brief notice says as much; dismissing it stores a local storage entry recording that you’ve seen it — it is never sent to a server, and nothing else is set. If you sign in to create an API key, one additional cookie is set — a session token that keeps you signed in. It’s functional, not tracking, and is cleared when you sign out or it expires.
Use Cookies in the footer at any time to reopen that notice, or clear your browser’s local storage for this site to reset it entirely.
Your rights
If you are in the UK, EEA, or California, you have rights to access, delete, or object to processing of your data. If you’ve never signed in, there is essentially no personal data held to act on — the tools themselves keep no accounts, no lookup history, and no advertising or analytics cookies. If you have an API account, contact hello@netsh.io to request a copy or deletion of your account and API key data.
Children’s privacy
netsh.io is a technical tool not directed at children and does not knowingly collect data from children under 13.
Changes
This policy may be updated as the site changes; the date above reflects the latest revision.
Contact
Questions: hello@netsh.io