Last updated 2026-08-16

Privacy Policy

Draft — not yet in force.

This page is awaiting legal review and is excluded from search engines. It describes what Roftrlabs actually does today, but it is not yet a binding statement by Roftr Clouds LLP. Do not rely on it.

The short version

Roftrlabs has no accounts and runs no advertising. We use Google Analytics and our own cookie-free page counter to count visits and see which tools get used — nothing more. Most of our tools never send your data anywhere — they run entirely inside your browser. When a tool does need our servers, it is because it has to fetch a web address on your behalf, and what we keep from that is deleted within 24 hours.

Tools that run in your browser

Tools marked as running in your browser — the JSON formatter, for example — process what you paste entirely on your own device. The content never reaches Roftr Clouds LLP, is never transmitted over the network, and cannot be seen by us. You can confirm this: disconnect from the internet after the page loads and the tool still works.

Tools that check a web address

Some tools need to request a page from the internet to tell you anything about it. When you submit an address to one of these:

  • We store the address you submitted, in normalised form, along with the result of the check.
  • Both the address and the result are erased 24 hours later. After that the result link still resolves, but it tells you the result has expired — the data behind it is gone, not hidden.
  • Results are shared. If someone else asks about the same address within 15 minutes, they are served the result of the earlier check rather than the site being fetched again. Do not submit an address you consider confidential — a private staging URL, or a link containing a token — as the result becomes visible to anyone who submits the same address.

We do not store the content of the pages we fetch. We keep the structured findings — status codes, headers, measurements — not a copy of the page.

The public listing, if you ask for it

The complete SEO audit offers one optional box: “List my site on the public recently-audited page.” It is off by default, and nothing appears anywhere public unless you tick it. If you do, we keep three things past the usual 24-hour window and show them on one public page: your site's domain (never the full address you submitted), the audited page's title, and the audit score.

  • The listing stores nothing about you — no identifier of who submitted, and no link to the audit result, which still expires 24 hours after the run exactly as above.
  • To remove a listing: run a new audit of the same site with the box unticked — the listing is deleted the moment that audit completes. Or email us and we will remove it.
  • A listing that is not renewed by a fresh opt-in audit is deleted automatically after 180 days.

Your IP address

We need to recognise a repeat caller in order to enforce rate limits and stop the service being used to attack other people's websites. Your IP address is never written to our database. It is converted to an irreversible keyed hash the moment a request arrives, and only that hash is stored. Two requests from the same address produce the same hash; the hash cannot be turned back into an address, including by us.

At that same moment we derive the country the request came from — a two-letter code such as IN or US — and keep that code with the run's operational record. The lookup happens against a geolocation database held on our own server, so your address is never sent to a third party to be located, and a country code is the full precision of what we keep: nothing about your city, network or identity.

Our web server keeps ordinary access logs, which do contain IP addresses, for a short period for security and abuse investigation.

What you search for

When you use the search box we keep the phrase you searched for and how many results it produced. We do this for one reason: a search that comes back empty is a tool somebody wanted and we do not have, and it is how we decide what to build next.

The phrase is stored on its own. It is not attached to a name, an account, a cookie or a session, and nothing in that record can be used to connect two searches to the same person — the only identifier stored alongside it is the same irreversible hash described above, used to stop one source flooding the record. Phrases are deleted after 180 days.

We refuse to store some things outright, because search boxes are where people paste text meant for somewhere else. Anything containing an email address, anything containing a long run of digits such as a card or phone number, and anything long enough to be a paste rather than a search is discarded and never written down. A pasted web address is reduced to its domain before it is stored, so the path and any token in it are dropped.

Counting page views

We count how often each page is read with a counter of our own, so that we know which guides and tools are useful even for visitors whose browser blocks Google Analytics. When a page is shown, your browser sends us the page's address (never anything after a ?), and on the first page of a visit, the domain of the website that linked you here. Alongside that we derive, at that moment, the same two-letter country code described above and whether you are on a phone, tablet or computer.

None of that is stored as a visit. We keep daily totals — this page was viewed so many times today, by so many people, so many from India — and nothing that records who viewed it. To count a person once a day rather than once per page, we compute an irreversible keyed hash of your IP address, your browser's identification string and the date, and hold it only in temporary server memory for 48 hours. It is never written to our database, and because the date is part of it, tomorrow's hash has nothing in common with today's.

Automated browsers and known bots are not counted, and choosing “No analytics” in the site's notice stops this counter as well as Google's.

Cookies and tracking

The public site uses Google Analytics, which sets two cookies holding a random identifier so that two page views can be counted as one visitor. That measurement and the cookie-free counter described above are the only tracking on the site: we embed no advertising, no social widgets and no session recording, and blocking analytics in your browser changes nothing about how the site works. Our cookie policy names each cookie, its purpose and its lifetime.

What we never do

  • Sell, rent or share your data with advertisers or data brokers.
  • Build an advertising profile of you, or follow you across other sites.
  • Retain the content of pages we fetch on your behalf.

Your rights

Under India's Digital Personal Data Protection Act 2023 you may ask what personal data we hold about you, ask for it to be corrected or erased, and complain about how we have handled it. In practice we hold very little: with no accounts, an anonymous visitor's data is a hashed identifier and a submitted address that deletes itself within 24 hours.

Because the identifier is a one-way hash, we usually cannot connect a request to you even if you ask us to — which is the point of hashing it, but does mean we may be unable to locate records on request.

Contacting us about privacy

Entity
Roftr Clouds LLP
LLPIN
Not yet published — see the draft notice above.
Registered office
Not yet published — see the draft notice above.
Email
Not yet published — see the draft notice above.
Grievance officer
Not yet published — see the draft notice above.

Changes to this policy

If we change what we collect or how long we keep it, we will update this page and the date at the top of it. Material changes to how we handle data will be reflected here before the change takes effect, not after.