Privacy Policy

Last updated: 24 September 2026

Hosting Details exists to do one thing well: give you fast, accurate, raw answers about domains, DNS and security configuration - WHOIS, RDAP, DNS records, SSL certificates, DNSSEC, HTTP security headers, e-mail authentication, all in one place, built from scratch, with a DNS lookup tool underneath that does its own raw protocol work instead of leaning on someone else's library. It's the tool we wanted for ourselves and couldn't find without ads, a login wall, or a tracking script bolted on - so we built it, and we're not shy about that.

No field on this site accepts an e-mail address as input, on any tool. Nothing about an e-mail address was ever stored even when this restriction wasn't yet in place, but accepting one at all reads as processing personal data whether or not anything is kept - an impression worth avoiding outright, not just explaining away.

That same instinct extends to how we treat you as a visitor. We don't track you, we don't profile you, and we don't build a history of what you look up - not because it's technically difficult to avoid, but because we've deliberately chosen not to build any of that in.

Security by Design

This site enforces a strict Content-Security-Policy, HTTP Strict Transport Security (HSTS), and other hardened security headers on every response. We do not load any third-party analytics, tracking pixels, or advertising scripts - there is nothing on this site set up to profile your visit.

What We Store (and What We Don't)

To be completely direct about it: a few of the checks below are cached on our server for a short time, for the specific technical reasons explained under each one, never to build any picture of who is asking. Every cache entry is keyed only by what was looked up, a domain name or an IP address, never by anything about the visitor making the request, and every entry is deleted automatically within days regardless of whether it was ever reused. Item by item:

WHOIS, DNS and DNSSEC lookups: When you look up a domain's WHOIS record, DNS records, or DNSSEC status, the query is sent live to the relevant service and the result is shown directly to you. Nothing about these lookups is written to disk on our end.

IP address lookups: IP geolocation queries are sent live to our upstream provider, then cached here for up to 10 minutes, keyed only by the IP address being looked up. That's purely to reduce how often we hit our upstream provider's own rate limit, which is shared across every visitor's lookups since they all go out from this server's one outbound address, not to build any history tied to you. The cache holds only the geolocation result itself, never anything about who requested it, and is deleted automatically after a maximum of three days regardless.

DNS Lookup Tool: The DNS Lookup Tool queries nameservers directly, on your instruction - including, if you choose, third-party servers you type in yourself, or a domain's own authoritative nameservers. Sending a query to whichever nameserver you've selected is inherent to how DNS itself works, not a choice we make on your behalf; we don't route it through any intermediary of ours, and we don't log which queries you ran. Our default choice for external DNS is DNS4EU, and we made that choice solely because it is not US-based.

RDAP responses: RDAP lookups are temporarily cached on our server, purely to reduce repeated load on domain registries and speed up repeat lookups - not to build a history tied to you. This cache holds only the public RDAP data for a domain (the same information the registry itself would return to anyone), never anything about who requested it. Cached entries are automatically deleted after a maximum of three days, whether or not they were looked up again.

Security scan results (SSL Health Check and HTTP Security Headers): These two checks are temporarily cached on our server as well, for the same reason as RDAP above and for a much shorter time - up to 5 minutes - since a security scan should stay reasonably fresh. This cache holds only the scan result itself (score, grade, and findings - the same result anyone re-running the same check moments later would get), never anything about who requested it. As with RDAP, cached entries are automatically deleted after a maximum of three days regardless.

Standard server logs: Like virtually every website, our web server keeps short-lived technical access logs (the kind any hosting provider generates by default) that can include your IP address and the page you requested. We do not mine these logs, we do not use them for analytics or profiling, and we do not correlate them with what you searched for. We keep them only as long as needed for abuse prevention and technical troubleshooting, and delete them on a regular schedule - this is our choice, not a default we've left unexamined.

Rate-limit trigger log: If a visitor exceeds the hourly request limit on a given tool, we log that event - a timestamp, which tool was involved, and a hashed (not raw) identifier derived from the IP address, never the IP address itself. Nothing is logged for ordinary use; only the moment a limit is actually hit. This exists solely to help us notice abuse patterns after the fact, is never used to alert or notify anyone automatically, and any entry is automatically deleted after a maximum of seven days.

Cookies

We don't serve tea, so there is hardly a need for cookies. We use cookies only for essential website functionality, such as remembering your preference for light or dark mode. We do not use tracking or advertising cookies.

Your Rights

Under the GDPR, you have the right to: access any personal data we hold about you; have inaccurate data corrected; have your data erased; restrict or object to how it's processed; receive a copy of it in a portable format; and lodge a complaint with your national data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens) if you believe we've handled it wrongly. In practice, since we collect so little tied to any individual, most of these requests will have a short answer - but the right to ask is yours regardless, and we will answer honestly.

Contact Us

If you have any questions about this Privacy Policy, please contact us at info@hostingdetails.eu. We don't sell data. We don't have any to sell.