Privacy statement

lolwuz.nl is a collection of domain tools. This statement describes what the service processes, why, how long it is kept, and what rights you have.

Who is responsible

lolwuz.nl is operated by Marten Hoekstra in the Netherlands. For questions about this statement or about your data, write to privacy@lolwuz.nl.

Using the service without an account

Most checks work without an account and without leaving anything behind. A check you run while signed out is not linked to you.

The result of such a public lookup is cached briefly against the domain name so the next visitor gets the same answer faster. That cache holds publicly available information about the domain, not about you.

What we process

  • Account: your email address, and optionally a display name. Signing in uses a one-time link by email; there is no password.
  • Sessions: a session cookie and its matching session record, for as long as you stay signed in.
  • Organisation: which organisation you belong to, your role in it, and the email address of anyone you invite.
  • Followed domains: the domain names you follow, your own notes on them, the check interval you chose and your notification settings.
  • Check history: DNS lookups and snapshots of earlier checks per domain, plus the alerts they produce.
  • Slack: if you connect Slack we store the workspace id and name, your Slack user id, the granted scopes, and the bot token. That token is encrypted at rest (AES-256-GCM) and never leaves the server.
  • Mail tester: messages you send to a generated test address are stored in full — sender, recipient, subject, headers and raw content — so they can be analysed.
  • Secret links: only the encrypted content and a hash of the link. Without the link the content cannot be read, including by us.
  • Workspace: snippets and support documents you or your organisation create.
  • Abuse prevention: to enforce limits we keep a counter per user or, when you are signed out, per IP address.

Why we do it

We process this data to provide the service you asked for: running checks, following domains and alerting you when something changes. That is performance of the agreement between you and us.

A limited amount is processed on the basis of legitimate interest: enforcing usage limits, preventing abuse and keeping the service secure.

Connecting Slack and sending alerts there happens only if you make that connection yourself. You can disconnect it at any time.

How long we keep it

  • Account data: for as long as your account exists. Deleting your account also removes your domains, history, alerts and Slack connection.
  • DNS history: 365 days.
  • Check snapshots: 90 days. The alerts themselves stay with the domain.
  • Mail tests: until one day after the test expires. The message and its analysis are then deleted in full.
  • Secret links: until opened or expired, whichever comes first.
  • Pending invitations: until accepted or expired.
  • Rate-limit counters and the lookup cache: briefly, until the window or validity elapses.

Parties that process data for us

  • Vercel — application hosting.
  • Neon — the database, hosted inside the EU.
  • Cloudflare — receiving test messages for the mail tester.
  • Our email provider — for sign-in links, invitations and email notifications.
  • Vercel Analytics and Speed Insights — aggregate visit and performance statistics, without cookies and without profiling.

What we send outward

A domain check is by definition a question put to the internet. To produce a result the service queries public DNS resolvers, WHOIS and RDAP servers, the domain's web server and its certificate. The domain name you enter is shared with those parties.

If you check an IP address against blacklists, that address is submitted to AbuseIPDB.

If you request an AI diagnosis, the collected information about that domain and your own notes are sent to Google Gemini. This is done with storage disabled, so the content is not retained by Google. Do not put confidential information into it.

If you connect Slack, alerts go to the workspace you chose. If you also pick a public channel, the alert is visible to everyone in that channel.

Cookies

The service uses no tracking cookies and therefore shows no cookie banner.

It does use a session cookie when you sign in, a short-lived cookie while connecting Slack, and a stored preference for theme and language. These are needed for the service to work.

Security

Traffic runs over HTTPS. Slack tokens and the contents of secret links are encrypted at rest. Access to data is limited to your own account and, where applicable, your organisation.

No service is completely secure. Do not send anything to the mail tester that you would not want stored.

Your rights

You have the right to access, correct and erase your data, to restrict and object to processing, and to data portability.

You can delete your account yourself under Account → Profile. For other requests, write to privacy@lolwuz.nl.

If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Changes

As the service changes, this statement may change with it. The date above shows when the text was last reviewed.