CheckURL Privacy Policy
Product-specific notice for scan.pwn-all.com — Effective and last updated 13 July 2026
Public scanner — do not submit secret-bearing URLs
A submitted URL and the resulting raw report are public during the raw-scan retention period. Permanent domain history and privacy-preserving threat fingerprints can remain after the raw report expires. This notice explains those layers; the Terms of Service govern use.
1. Controller and scope
PWN-ALL Auditing, Reviewing & Testing Cyber Risks CO. L.L.C operates CheckURL and is the controller for the processing described here. Registered address: 145, Al Mustaqbal Street, Iris Bay Tower 2101-11, Business Bay, Dubai, United Arab Emirates. Product privacy requests: privacy@pwn-all.com; legal and data-rights requests: legal@pwn-all.com.
This notice applies to the public CheckURL URL-reputation service at scan.pwn-all.com. It supplements PWN-ALL's corporate Privacy Policy. For CheckURL-specific processing, this more specific notice controls if the two differ.
2. Public records and persistent security data
Raw scan report — public for 40 days. The public report, screenshot route and APIs can disclose the submitted, normalized and final URLs (including their paths and query values), hostname, scan time, page title, screenshot, stored rendered HTML, redirects, response headers, technologies, scores, classifications and analysis results. They also expose browser request URLs and any best-effort, text-only, truncated request or response bodies captured from POST/PUT/PATCH traffic. The recent-scans API lists the most recent reports. Individual report pages carry noindex, but that is a search-engine instruction, not access control.
Permanent domain history — public and potentially indexable. Domain reports retain the registrable domain, a redaction-filtered hostname and path, a marker that a query existed (not its value), a hash of that sanitized display URL, scan dates, scores, verdicts, classifications, compact security signals and limited registry/reputation facts. They do not retain the raw query, page HTML, request/response bodies or screenshot. Redaction is heuristic, so do not rely on it to make a sensitive hostname or path safe. A domain report may be submitted to search engines through sitemaps or IndexNow.
Persistent threat fingerprints — internal. CheckURL retains fixed-size hashes derived from page structure, script/style resource shape, screenshots and favicons, together with a source scan identifier and an official, clean, phishing or malware review label. The hash layer contains no raw page prose, form values, query strings or image bytes. It is used to recognize official visuals and reviewed phishing/malware kits when they reappear.
Never submit a URL containing credentials, tokens, password-reset or signed links, session or invitation IDs, private documents, or personal data unless you are authorized to make that material public and have a lawful basis to do so. A screenshot or page/network capture can also incidentally contain personal or sensitive information published by the target site.
3. Data, sources and purposes
From you: the URL you submit; account email and an Argon2 password hash for an existing account; or a Telegram identifier and username for an already-linked account. There is no public self-service registration.
From publicly accessible target sites: rendered HTML and visible text, title, screenshot, redirects, resources and network behavior, limited text request/response bodies, headers, TLS and DNS facts, technologies, legal identifiers displayed by the page, content and visual hashes, and signals derived from those facts. This can include data about people other than the person who requested the scan; its source is the submitted public site and the services it loads.
From our systems and reviewers: timestamps, scan status, component and overall scores, confidence, phishing/malware/scam indicators, administrator labels and label sources, audit events, proof-of-work records and session state.
Network and anti-abuse data: for anonymous scan quotas, proof of work and login protection, the application stores a keyed HMAC-SHA256 value derived from the requester IP rather than the raw IP. Public GET throttling uses the IP in process memory for a rolling 60-second window. Reverse proxies, hosting or standard server logs can transiently record the raw IP and request metadata outside the application database.
We use this data to provide and publish requested security reports; detect phishing, malware, scams and abuse; maintain domain history and improve repeat-kit detection; authenticate existing users; secure, diagnose and defend the service; handle corrections and legal requests; and establish, exercise or defend legal claims.
4. Automated scoring and human labels
CheckURL automatically combines browser-observed behavior, page/content patterns, host and domain facts, and available third-party threat intelligence into a 0–100 score, confidence measure, verdict and reasons. Confirmed malicious evidence can cap the score; missing provider data generally lowers coverage rather than proving that a site is bad. Authorized administrators can apply or correct phishing, malware, scam, spam or clean labels, which can override the automated verdict and persist in domain history.
These outputs are security opinions about websites, not decisions producing legal or similarly significant effects about an individual. They can be incomplete, stale or wrong. Do not use a score as the sole basis for credit, insurance, employment, housing, legal, compliance or other high-impact decisions. A site owner or affected person can request human review or correction under §10.
5. Cookie and local storage
We set one strictly necessary private sid cookie when a page creates a session. It holds only an opaque session identifier; the CSRF token and login state stay server-side. The cookie is HttpOnly, SameSite=Lax, scoped to the site, expires after 30 days, and is marked Secure over HTTPS. It supports form security and, for existing accounts, authentication. We use no advertising, analytics or cross-site tracking cookies.
Your browser stores checkurl-theme (display preference) and checkurl-consent (whether you dismissed the legal notice) in localStorage. Despite the historical key name, dismissing the notice is an acknowledgment, not consent to optional processing. These values stay on your device unless your browser sends them through a feature outside CheckURL.
6. Legal grounds
Depending on the person, jurisdiction and purpose, we rely on:
- Contract or steps at your request — to validate, run and publish the scan you request, and to operate an allocated account.
- Legitimate interests — defensive threat research and public website-reputation reporting; preventing phishing, malware, fraud and misuse; keeping accurate domain history; protecting users, the public and the Service; and handling corrections. Safeguards include data minimization, hashed IPs, bounded raw retention, redacted permanent records, confidence reporting, human review and opt-out/removal channels.
- Legal obligation and legal claims — compliance, lawful requests, complaints, record preservation and establishing, exercising or defending rights.
- Consent only where we expressly request it and applicable law requires it. Reading or dismissing this Privacy Policy is not consent. Withdrawal applies prospectively and does not invalidate earlier lawful processing.
Under the UAE Personal Data Protection Law, we process on consent or another ground permitted by applicable law. Where GDPR/UK GDPR applies, the corresponding bases are generally Articles 6(1)(b), 6(1)(f), 6(1)(c), and, only when used, 6(1)(a).
7. Recipients, providers and transfers
The target site and its dependencies. The isolated scanner browser requests the submitted site and resources it chooses to load. Their operators see our infrastructure or proxy IP, browser user agent, requested URLs and ordinary browser metadata—not your IP or account. Target-controlled third-party scripts may process scanner-environment data as they would for a normal visit. If a scan proxy is configured, its operator can see destination and traffic metadata.
Reputation and registry providers, when enabled or applicable:
- Google Safe Browsing receives the final URL; Google Public DNS receives MX/TXT/DMARC queries for the registrable domain.
- VirusTotal receives the registrable domain; URLhaus (abuse.ch) receives the landing host.
- RDAP.org and relevant registries receive the registrable domain; Tranco receives the registrable domain; ipwho.is receives a resolved public server IP.
- GLEIF or the European Commission's VIES service receives a LEI or VAT number publicly claimed on the scanned page. Name comparison occurs in our worker.
- OpenPhish data is downloaded as a feed and matched locally; the submitted URL is not sent to OpenPhish by that check.
- IndexNow, if enabled, receives only already-public permanent domain-report URLs—not raw scan URLs. Telegram supplies signed login data only when a user invokes Telegram login for a linked account.
We do not sell personal data or disclose it for cross-context behavioral advertising. Providers and target sites can be in countries other than the UAE or yours. Where transfer law applies, PWN-ALL uses the applicable adequacy, contractual or statutory transfer mechanism described in the corporate Privacy Policy; contact us to request information about safeguards relevant to your data.
8. Retention
- Raw scans: the active scan row and screenshot are scheduled for deletion 40 days after creation. The purge runs about every six hours, so deletion normally follows within that sweep window; a transient failure or binding legal-preservation duty may delay it. Related proxy-usage rows cascade with the scan.
- Domain history: redacted snapshots and aggregate domain records are retained indefinitely to provide long-term security history. Public display can be opted out; underlying retention can continue unless deletion applies or the record is no longer needed.
- Threat fingerprints: fixed-size official/reviewed hashes and labels are retained indefinitely for repeat-threat detection. A direct administrative erasure of the source scan removes its learned observations; ordinary age-based raw-scan expiry does not.
- Accounts: existing account identifiers and password hashes are kept while the account is active or reasonably needed, then removed on a verified applicable request unless retention is legally required.
- Sessions and proof of work: session cookies and server-side sessions expire after 30 days; proof-of-work challenges expire after the configured short window (five minutes by default). Expired database rows are unusable but may remain until maintenance removes them.
- Abuse and audit records: scan-linked anonymous IP hashes follow raw-scan retention. Login attempts, first-use/quota records and administrative audit logs currently have no automatic fixed deletion schedule and are retained while reasonably needed for security, accountability or legal claims, subject to applicable deletion rights.
- Infrastructure logs: raw IPs and request metadata, if logged by hosting or a reverse proxy, are retained according to operational security and incident-diagnosis needs rather than as part of the public report.
9. Security and scanning safeguards
Controls include encrypted/private session cookies, Argon2 password hashes, keyed IP hashes, CSRF protection, proof of work, rate limits, authenticated administrative actions and audit logs. URL validation blocks loopback, private, link-local and metadata destinations. Browser captures and image processing are bounded. The scanner does not supply real credentials or intentionally complete target forms; staged phishing probes use synthetic events while blocking their resulting network requests.
No system is perfectly secure. Public report design means confidentiality must come from not submitting sensitive URLs. We investigate suspected breaches and notify regulators or affected people when required.
10. Rights, corrections and complaints
Depending on applicable law, you may request access, a copy, correction, deletion, restriction, portability, or object to processing; withdraw consent where consent is the basis; request information about sharing and safeguards; and request review of an automated or administrator-applied result. These rights are not absolute and can be limited to protect other people, security investigations, freedom of expression, legal duties or claims.
For a scan or domain-report request, email privacy@pwn-all.com or legal@pwn-all.com with the report URL/ID, the correction sought and your relationship to the affected data or site. We may verify identity or authority. A site owner can request correction, a fresh scan, or public domain-report opt-out; nobody can pay for a better score, review or removal. We ordinarily respond within 30 days or the applicable statutory period and will explain any permitted extension or refusal.
Removal from our active service cannot guarantee deletion of copies previously cached, archived or republished by independent third parties, though we take further reasonable steps when law requires. You may complain to the UAE Data Office, your EEA supervisory authority, the UK Information Commissioner's Office, or another regulator available where you live.
11. Children
CheckURL is not directed to people under 18, and the Terms do not permit them to use the Service. We do not knowingly create accounts for or collect data directly from children. Public target pages can nevertheless contain information about minors; contact legal@pwn-all.com if you believe such data appears in a report.
12. Changes
We may update this notice to reflect legal, provider or product changes. We will revise the date above and give a prominent notice for material changes when reasonably possible. A privacy notice describes processing; merely continuing to browse is not treated as consent where consent is legally required.
13. Contact
PWN-ALL Auditing, Reviewing & Testing Cyber Risks CO. L.L.C
145, Al Mustaqbal Street, Iris Bay Tower 2101-11, Business Bay, Dubai, United Arab Emirates
DET licence 1324553
Product privacy: privacy@pwn-all.com
Legal/data rights: legal@pwn-all.com
This product notice should be read with the CheckURL Terms of Service.