Privacy · effective August 10, 2026
Public URLs, bounded evidence, no account.
WebVisible is designed to diagnose public web pages without creating a user profile or permanent scan archive.
What you submit
The checker accepts a public HTTP or HTTPS URL. Do not submit private, confidential, authenticated, internal, or token-bearing URLs. Query strings can contain sensitive values; remove them before scanning unless they are genuinely public and necessary to the page.
What the service retrieves
A Quick Scan may request the submitted page, validated redirects, the final origin's /robots.txt, /sitemap.xml, /llms.txt, and one same-origin sitemap declared by robots.txt when needed. A rendered comparison may open the public page in Cloudflare Browser Run.
WebVisible does not accept your cookies, credentials, authorization headers, uploaded files, proxy settings, or custom browser scripts.
Retention
- No account or database-backed scan history is created in the initial product.
- Quick Scan structured results can be held in Cloudflare's cache for approximately five minutes to reduce duplicate requests.
- Rendered HTML, Markdown, accessibility trees, and page bodies are processed during the request, reduced to bounded structured evidence, and are not stored as a persistent report.
- The interface does not write a “recent scans” list to local storage.
- A JSON export is created locally in your browser only when you choose Export JSON.
Operational logs
Cloudflare and WebVisible may process ordinary service metadata needed to operate and secure the site, including IP-derived rate-limit keys, request time, endpoint, status class, duration, cache state, response-size bucket, browser milliseconds used, and error category.
Application logs are designed not to include page bodies, robots contents, cookies, credentials, browser artifacts, or full query strings. Rate-limit subjects are hashed before use by the application.
Service providers
WebVisible runs on Cloudflare Workers, Static Assets, Cache, and Browser Run. Cloudflare processes requests under its own service terms and privacy commitments. The production interface does not load advertising, analytics, social, chat, or font scripts from third parties.
Security boundaries
The scanner rejects many unsafe target forms, validates every redirect, reads bounded response bodies, and rate-limits expensive actions. No public web scanner can guarantee that a submitted public page contains no personal information, so use the tool only for URLs you are authorized to test and comfortable sending to a diagnostic service.
Changes
Material policy changes will be reflected on this page with a new effective date. Future optional accounts, monitoring, or analytics would require an updated notice before launch.