Privacy
This site is a fingerprinting tool. It would be absurd to be vague about what it reads.
When you run a scan on this site
The scan on the home page reads a large set of properties from your browser: your User-Agent and Client Hints, screen and window geometry, CPU cores and memory class, installed fonts, GPU driver strings, audio and canvas rendering output, installed speech voices, supported codecs, permission states, timezone and locale, and the ICE candidates WebRTC produces. It also watches pointer, keyboard and scroll activity on the page while you are on it.
That data is sent to our server, scored, and stored so the demonstration can show you velocity and clustering analysis. It is kept for thirty days and then deleted.
Your IP address is recorded alongside a salted hash of it. We resolve it to a country, network operator and timezone through a third-party lookup service, and cache that answer for seven days.
If you want to see the results without anything leaving your browser, open the
console and run BrowserScan.inspect(). That performs the same analysis
locally and sends nothing.
Third parties
- STUN servers. Discovering your public address requires a STUN request, which by default goes to Google's public STUN servers. They see your IP address, as they would for any WebRTC call.
- IP intelligence. Address lookups are sent to ip-api.com and, as a fallback, ipwho.is. They receive the address being looked up.
There is no advertising, no analytics and no third-party tracking on this site.
Cookies
None. Your theme preference is stored in localStorage and a random
session identifier in sessionStorage, both of which stay in your browser
and are cleared when you close the tab.
If you have installed the tag on your own site
Then you are the data controller for your visitors, not us. The tag collects the same signals described above from the people who visit your pages, and stores them against your property in your dashboard.
Fraud prevention is a recognised legitimate interest under the GDPR and comparable regimes, but it is not an exemption from telling people. If you operate in the EU, the UK, or a jurisdiction with similar rules, you should:
- name device fingerprinting for fraud prevention in your privacy notice;
- record your lawful basis, and your legitimate interests assessment if you are relying on that;
- set
BS_STORE_RAW_IPto false if you do not need raw addresses, which disables some proxy-rotation analysis; - shorten
BS_RETENTION_DAYSto the minimum that is useful to you; - be able to answer a subject access request, since a device fingerprint tied to an IP address is personal data.
This is a description of how the software behaves, not legal advice. If the answer matters commercially, ask a lawyer in your jurisdiction.
Who publishes this site
browserscan.in is published by Vikram Singh, who is the data controller for the processing described on this page. Postal address:
Vikram Singh
45, Civil Lines
Jaipur, Rajasthan 302006
India
Telephone: +91 98995 59698
Getting your data removed
Scan data on this site is keyed to a session identifier shown on the results page. Send it to us and we will delete the associated records, or wait thirty days and they will expire on their own.