Privacy follows the actual data path

Pasted evidence and local files stay in your browser. Public URL checks use a protected Crawl Foundry-operated gateway. Each data path is described separately here.

Controller

Matthias Ramahi
Kempener Straße 44
40699 Erkrath
Germany

Email: info@matthiasramahi.de
Telephone: +49 176 42 44 98 58

Hosting and delivery

AnalyseSpider is hosted and delivered through Vercel. When you request a page, your browser necessarily sends connection and request metadata to the hosting infrastructure. This can include the IP address, timestamp, requested URL, HTTP method and status, referrer, user agent, and security-related request information.

This processing is used to deliver the website, maintain availability, prevent abuse, and diagnose technical failures. Hosting-level processing and retention are governed by the applicable Vercel configuration and service terms. It is separate from the contents you paste into the current diagnostic tools.

Browser-local diagnostic tools

The Log File Inspector, IP Address Check and Bot Request Verifier run as browser-local JavaScript. Pasted response headers, redirect blocks and robots.txt rules are also evaluated locally. AnalyseSpider does not upload those selected files, pasted inputs, IP addresses, user-agent strings or generated local results to an application endpoint.

The input can still remain in your device memory, clipboard, browser history or extensions, screenshots, and any files you export or save. Redact confidential logs before using any diagnostic tool, including a local one.

Protected live URL check

The main crawler check and the public-URL modes in the Response Inspector, Redirect Chain tool and Robots Rule Tester send the public URL you enter to tools.contextter.com, a Hetzner-hosted gateway operated by Matthias Ramahi. The gateway fetches only public HTTP or HTTPS pages through an SSRF-protected transport. It blocks private and local addresses, pins DNS, checks every redirect, allows only ports 80 and 443, follows at most three redirects, stops after eight seconds, and limits the decoded response to 1.5 MB.

The Website Index Check sends the entered public site URL to a separate gateway operation. It requests that site's robots.txt and sitemap, or homepage links when no usable sitemap is found, and then checks at most 50 URLs on the same site. Each page fetch uses stricter response-size and timeout caps than the single-URL check. The operation does not follow arbitrary external links, scan ports, enter logged-in areas, or perform an unrestricted crawl.

The gateway uses a browser-computed proof-of-work challenge, an exact origin allowlist, a pseudonymous HMAC client key derived from the request IP address and a coarse device family, rate limits, one concurrent AnalyseSpider slot, a circuit breaker, and an immediate scope kill switch. The raw IP address is needed at the network and proxy layer but is not used as the application-level rate-limit key.

Successful AnalyseSpider URL reports, including the bounded website report and its checked URLs, can be cached in encrypted Redis storage for up to one hour; error reports for up to five minutes. Usage statistics keep the hostname, not the full submitted URL, for up to 90 days. Pseudonymous unique-client counters and aggregate run counters can remain for up to 400 days. This supports abuse prevention, capacity planning, cache efficiency, and service reliability. The check does not use DataForSEO, an LLM-mentions provider, an advertising service, or a customer account.

After a successful crawler check, up to five complete reports can be stored in this browser's local storage for no more than 24 hours. This local history includes the checked URL and exists only so you can compare a later check with an earlier result. It is not uploaded as a history record. You can remove it by clearing this site's browser storage. Choosing the crawler-token comparison sends one additional bounded request for the same public URL to the gateway; the selected token is included in the cache key and request user agent.

Do not submit private, signed, password-reset, preview, or secret-bearing URLs. A submitted path and query can be included in the generated report, the short-lived gateway cache, browser-local history, clipboard content, or an exported JSON file. Remove unnecessary query parameters before starting a live check.

Cookies, analytics, and accounts

AnalyseSpider uses the self-hosted open-source software Umami at analytics.crawlfoundry.com for cookie-free usage and technical quality measurement. The tracker is restricted to analysespider.com and www.analysespider.com, respects the browser's Do Not Track setting, excludes URL search parameters and hash fragments, and records web-performance measurements. It does not use advertising pixels, session replay, heatmaps, cross-site advertising profiles, or umami.identify(). No application or tracking cookie is set by the current site.

According to Umami's technical documentation, normal measurements can include page path without query or hash, referrer, browser, operating system, device category, screen information, approximate country, and Core Web Vitals. Umami creates a session hash from the request IP address, user agent and website ID; the raw IP address is not stored by Umami as an analytics field. Normal web-server and proxy request processing remains separate.

AnalyseSpider sends only allowlisted, low-cardinality product events: navigation category; tool start, success or error category; selected crawler profile; use of an example; report copy, download or comparison; Google spot-check click at domain-or-URL level without the value; a recorded result-seen or no-result-seen category without the URL; and marked hand-offs to another tool. It never sends the checked URL or hostname, IP address, log line, pasted headers or HTML, robots.txt content, user-agent text, report content, query string, exported data, clipboard content, or local history to Umami.

The legal basis is Article 6(1)(f) GDPR. The legitimate interests are understanding which public pages and tools are used, finding broken interactions and performance regressions, and operating the free service with proportionate data. Users can object for reasons arising from their particular situation by emailing the controller; browsers with Do Not Track enabled are not measured. Analytics records are kept only while needed for these purposes and are reviewed for deletion. The exact instance-level automatic deletion interval has not yet been independently verified and remains a production compliance gate.

There is no newsletter signup, payment flow, or user account.

Contact

No contact form is embedded on this website. Clicking an email link opens your chosen email service. If you contact the operator, the email address, message, headers, attachments, and follow-up correspondence are processed to answer the request, document rights or security concerns, and meet applicable legal obligations. Do not send passwords, raw customer data, private logs, or former software files.

External links and public repository

AnalyseSpider links to standards, search-platform documentation, source projects, Crawl Foundry, and the public GitHub repository. No external page is embedded automatically. When you follow a link, the destination receives the normal request information and applies its own privacy terms.

The Website Indexability Check offers optional Google site: search links for the checked domain and individual URLs. AnalyseSpider does not run or scrape these searches. After returning, you can record whether you saw a result. That observation and its timestamp stay in the current browser tab and are included only if you download the report as JSON; they are not uploaded or treated as Search Console evidence. Google receives the exact checked URL as a search query only after you click one of those links. Do not use this option for private, signed, or secret-bearing URLs.

The Google Search Console ownership TXT record is a DNS verification record. It does not add an analytics script or transmit visitor tool input.

Retention and recipients

The browser-local tools do not create an application record. The live URL check creates the bounded cache and usage records described above. The Umami service operated at analytics.crawlfoundry.com receives the limited usage events described above. Technical request information can also be processed by Vercel, Hetzner, the reverse proxy, and involved network providers; email correspondence by the involved email providers. Information is retained only as needed for delivery, security, rate limiting, cache operation, usage measurement, correspondence, evidence of handled requests, or legal obligations.

Legal bases and international processing

Where the GDPR applies, website delivery, the protected gateway, rate limiting, abuse prevention, availability monitoring, and technical fault diagnosis are processed on the basis of the operator's legitimate interests under Article 6(1)(f) GDPR in providing and protecting this free service. Email is processed under Article 6(1)(b) GDPR where it concerns a contract or steps requested before a contract, under Article 6(1)(f) for corrections, security reports, and general correspondence, and under Article 6(1)(c) where retention is required by law.

Recipient categories are the hosting and delivery provider, the Hetzner-hosted gateway and its technical operators, reverse-proxy and network providers, email providers, and authorities or advisers where legally required. Vercel is headquartered in the United States and publishes information about the EU-U.S. Data Privacy Framework and Standard Contractual Clauses in its privacy notice. The mechanism applicable to the operator's actual account and processing should be confirmed during a legal review.

This notice documents the current technical data paths. It is not an external legal certification; material provider, retention, analytics, or product changes require another technical and legal review.

Your data-subject rights

Where the GDPR applies, a data subject can request access, rectification, erasure, restriction, portability, or object to processing, subject to the statutory conditions. A complaint can also be made to a competent data-protection supervisory authority. Send privacy requests to info@matthiasramahi.de.

Changes

This notice describes the current static site, cookie-free Umami measurement, local bot verification, local 24-hour report history and protected crawler gateway as reviewed on 29 August 2026. A future upload, account, billing flow, paid data provider, identity feature, or additional processor requires an updated technical and privacy review before activation.