TL;DR
Fingerprint collection and valuation run in your browser first. Scan data reaches Panopticlick servers only when you opt in, and the completed case can export or delete that server session. AI chat is a separate, user-triggered feature described below.
1. Overview
Panopticlick ("we", "us", "our") is committed to protecting your privacy. This privacy policy explains how we collect, use, and protect information when you use our browser fingerprinting test and privacy tools.
Last updated: July 28, 2026
2. Information We Collect
2.1 Information Collected Automatically
By default, fingerprint collection and valuation run in your browser. The local report may be saved in this browser's local storage so it can be reopened on a later visit. It is not uploaded to Panopticlick servers unless you explicitly opt in to server storage.
2.2 Information You Choose to Share
If you opt in to data sharing, we may collect:
- Your browser fingerprint (technical configuration data)
- A randomly generated session ID
- Timestamp of your scan
- A salted hash derived from the request IP address (never the raw IP)
- Derived country, ASN, proxy, and VPN network signals
- Pseudonymous aggregate statistics
We do not collect:
- Your raw IP address in D1 scan records
- Your name or email address
- Cookies or tracking identifiers
- Browsing history
- Precise GPS location
3. How We Use Information
If you choose to store your fingerprint data, we use it for:
- Research: Understanding browser fingerprinting techniques and their prevalence
- Statistics: Calculating uniqueness metrics and entropy distributions
- Education: Providing comparative data to help users understand their privacy
- Case delivery: Returning network context and an authenticated export for the opted-in session
We never:
- Sell or rent your data to third parties
- Use your data for advertising or marketing
- Share individual fingerprints with anyone
- Track you across websites
4. Data Storage and Security
When you opt in to data sharing:
- Data is stored on Cloudflare's infrastructure with encryption at rest
- Opted-in scan sessions are retained for a maximum of 30 days
- De-identified fingerprint aggregates are retained for a maximum of 90 days
5. Your Rights
Under GDPR, CCPA, and other privacy laws, you have the right to:
5.1 Access
Export the data associated with an opted-in session from the completed case summary. The ownership token issued with that session is required.
5.2 Deletion
Request deletion through the authenticated privacy endpoint or contact us for assistance. A session ID alone is not enough; deletion requires the ownership token issued with that session.
5.3 Portability
Export your data in a machine-readable format (JSON) using the "Export" feature.
5.4 Objection
You can opt out of data sharing at any time by simply not selecting the "Share anonymized data" option during scans.
6. Cookies and Tracking
We do not use:
- Cookies (tracking or otherwise)
- Local storage for tracking purposes
- Third-party analytics (no Google Analytics, etc.)
- Advertising networks
- Social media trackers
We use local storage for the consent preference, the most recent local report and dossier, and—when a scan is stored—the session ownership token needed for export or deletion. These values support site functionality and are not used for cross-site tracking. Choosing “Scan again” clears the saved case and token from this browser.
7. Third-Party Services
Our website is hosted on Cloudflare Pages. Cloudflare may collect operational request data under its own service terms. Panopticlick minimizes application logs and does not run third-party advertising or audience analytics scripts.
If you choose to send a question to the analysis agent, the current chat transcript and a compact case context (such as entropy, modeled CPM, defense score, personas, and uniqueness) are sent through our Worker to OpenRouter so it can produce the answer. This happens only after you submit a chat question, but it is separate from the scan storage choice. Do not include names, contact details, or other sensitive information in chat. Upstream processing and retention are governed by OpenRouter and the model provider it selects.
We do not embed third-party content, widgets, or scripts that track browsing across sites.
8. Children's Privacy
Our service is not directed to children under 13. We do not knowingly collect information from children. If you believe a child has provided us with data, please contact us for deletion.
9. International Users
Our service is available worldwide. By using our service, you consent to the processing of any data you choose to share in accordance with this policy.
Optional server storage is based on your explicit choice and can be withdrawn by deleting the authenticated server copy from the completed case summary.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes by updating the "Last updated" date and, for major changes, posting a notice on our homepage.
11. Contact Us
If you have questions about this privacy policy or want to exercise your rights, contact us at:
12. Privacy Controls and Limitations
The site provides local-first processing, optional server storage, authenticated export, and deletion controls intended to support privacy rights requests. This policy describes the implemented behavior; it is not a certification or a substitute for legal advice.