Privacy — short and honest
Responsible: see legal notice. Linkwache is a private, free service for friends and acquaintances — no business, no advertising, no sharing of data.
Where Linkwache runs
On a private server in Germany (Radeberg, Sachsen), operated by the responsible person. There is no hosting provider, no cloud, no content delivery network. The connection is encrypted (HTTPS, Let’s Encrypt certificate). The name linkwache.maro-datacenter01.synology.me is resolved to the server’s address by Synology Inc.’s DDNS service; Synology only sees the name lookup, not what you enter.
What is stored
- The checked link and the result — under a random ID so you can forward the result link. It is deleted automatically after 90 days. No names, phone numbers, e-mail addresses or IP addresses are stored — only the link, the technical facts about it and the assessment.
- The rest of a pasted message is not stored. From pasted text we only extract the links; the text itself is discarded.
- Telegram (if offered): the chat ID is only used to reply and is not stored.
Logs and abuse protection
The server keeps no access log with IP addresses. To keep anyone from flooding Linkwache with thousands of requests, we count requests per sender for one minute; for that, a daily changing hash of the IP address is kept in memory only and vanishes on restart. On technical errors the server’s error message may contain the IP address; those logs are overwritten regularly.
Where the link goes
To assess a link we query lookup services on the internet — the link (or only its domain name) is transmitted, nothing else about you:
- Name resolution (domain name only): Cloudflare (1.1.1.1) and Google Public DNS, encrypted via DNS-over-HTTPS.
- Domain age and registrar (domain name only): RDAP lookup at the responsible registry via rdap.org.
- Certificates (domain name only): crt.sh (Sectigo).
- Fraud databases (the link): Google Safe Browsing (Google LLC, USA — Advisory provided by Google), URLhaus (abuse.ch, Switzerland), PhishTank (Cisco, USA) and the urlscan.io search — each as far as the service is set up.
- Sandbox screenshot (the link, if set up): urlscan.io opens the page in a sandbox and takes a screenshot. The scan is “unlisted” (not searchable, but reachable with the link). The image is loaded into your result directly from urlscan.io — so urlscan.io sees your device’s IP address as with any image request.
The legal basis is our legitimate interest in giving you an assessment of a suspicious link (Art. 6(1)(f) GDPR). The link itself is usually not personal data; if it is (say, a link containing your name), the same applies: 90 days, then gone — or immediately on request.
Donation button
The “Buy me a coffee” button leads to PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg). Only there, with your click, does PayPal process data under its own rules. Linkwache only learns that a payment arrived.
Cookies, tracking, advertising
None of it. No cookies, no analytics scripts, no fonts or scripts from third-party servers, no advertising. Only your day/night choice is remembered by your browser itself (local storage, never leaves the device).
Your rights
Access, rectification, erasure, restriction, objection, complaint to a supervisory authority (for us: the Saxon Data Protection and Transparency Officer) — write to the address in the legal notice. As we store no personal data there is usually nothing to delete; a result link is deleted on request.
Last updated: 18 September 2026. This translation is for understanding; the German version is authoritative.