Privacy policy
Last updated: September 2026
The short version
We do not have user accounts, we do not run analytics scripts, and we do not sell or share personal data. The network tools send only the URL or hostname you enter to our edge service so it can perform the request on your behalf; the result is returned to you and not stored.
Network tools and public endpoints
The URL status checker, redirect tracer, security headers scanner, CORS tester and DNS lookup call an edge function at mcp.httpstatus.com. That function receives the URL or hostname you entered, performs the lookup, and returns metadata. It does not persist URLs or results. To prevent abuse it keeps a short-lived counter of requests per IP address (100 per hour) that expires automatically. The public status responder and dummy JSON endpoints are stateless and log nothing beyond Cloudflare's standard, aggregated request metrics.
MCP server
Connecting an AI client to our MCP server creates an OAuth authorization. We store the token and grant record needed to keep that connection working (in Cloudflare Workers KV) and nothing else; there is no profile, and tool calls are not logged with their inputs. Tokens expire automatically and you can revoke a connection from your client at any time.
Advertising
We display advertisements served by Google AdSense. Google may use cookies or similar technologies to show ads based on your prior visits to this and other websites, and may collect data as described in Google's privacy policy. You can opt out of personalised advertising at Google's ad settings page. Ads load lazily and only when they scroll into view.
Hosting
The site is served by Cloudflare, which processes request metadata (IP address, user agent, requested URL) transiently to deliver content and protect against attacks, under Cloudflare's own privacy policy. We do not enrich or export this data.
Contact
Questions about this policy: privacy at this domain.