LEGAL

Privacy Policy

Last updated: September 11, 2026. This policy explains how ToolsNovaHub handles information when you use our website and tools. We are committed to protecting your privacy.

🔒 Short version: We don't store the actual search terms or values you enter into our tools (an IP, domain, email, etc.) on our own servers — most are sent directly from your browser to a third-party API. Like most websites, we do use Google Analytics and Google AdSense, which separately collect standard usage data and set cookies as described in Sections 2, 3 and 5 below. No account is required to use any tool.

1. Information We Do Not Collect

ToolsNovaHub is designed with privacy as a default. We do not collect:

  • IP addresses you look up or convert using IP Lookup, My IP, Bulk IP Lookup, IPv6 Lookup, IP Address Converter, IP Reputation Checker, IP Abuse Checker, IP Geolocation API Tester, Blacklist Checker, Ping Test, Traceroute, Port Scanner, Open Port Checker, or the CIDR / Subnet / IP Range / IPv6 Calculators
  • Domain names or hostnames you query via WHOIS, DNS Lookup and the individual A, AAAA, CNAME, TXT, NS, SOA, SRV, PTR, CAA and MX record lookups, DNS Propagation Checker, DNS Cache Checker, DNS Leak Test, DNSSEC Checker, Reverse DNS Lookup, ASN Lookup, BGP Lookup, or Malware Scanner
  • URLs you check via Security Headers Checker, HTTP Headers Checker, Website Security Scanner, Redirect Checker, or SSL Certificate Checker
  • Email addresses you verify using Email Checker, or the sending domains you check with SPF Lookup, DKIM Lookup, DMARC Lookup, DMARC Record Generator, BIMI Checker, SMTP Tester, SMTP Banner Checker, or TLSA Lookup
  • MAC addresses you look up or generate using MAC Address Lookup or MAC Address Generator
  • Wi-Fi passwords, UPI IDs or contact data entered in QR Generator
  • Passwords generated using Password Generator, or values entered into UUID Generator or Unix Timestamp Converter
  • Dates of birth entered in Age Calculator, or times/timezones entered in Timezone Converter

Most queries made through our tools are sent directly from your browser to third-party APIs (such as ipapi.co, dns.google, rdap.org, crt.sh). These requests do not pass through our own servers. The exceptions are Security Headers Checker, HTTP Headers Checker, Website Security Scanner and Redirect Checker, explained in Section 1a below.

1a. Security Headers Checker, HTTP Headers Checker, Website Security Scanner & Redirect Checker: How the Proxy Works

Browsers block JavaScript from reading another site's response headers unless that site explicitly opts in, which almost no site does. To make Security Headers Checker, HTTP Headers Checker and Redirect Checker actually work, the URL you enter is relayed through a minimal serverless proxy (a Cloudflare Worker) we operate, which fetches the target page and returns its response headers or redirect chain to your browser. Website Security Scanner uses the same proxy for its headers component, alongside separate client-side SSL and DNS checks. The proxy's own code contains no logic to log the URLs checked or store response data — it relays the single request and returns the result, without reading cookies, submitting forms, or otherwise interacting with the target site beyond one GET request. As with any hosted service, the underlying infrastructure provider (Cloudflare) may retain brief, standard operational logs for security and abuse-prevention purposes that are outside our application code's control; we do not have a separate database or log store for these requests. This is the same architecture used by essentially every public security-header-checking tool, since no browser-only alternative exists.

2. Information We May Collect Automatically

Like most websites, our hosting provider and analytics tools may collect standard server log information including:

  • Your IP address (used for basic server security and DDoS protection)
  • Browser type and operating system
  • Pages visited and time spent on pages
  • Referring website

This data is aggregated and anonymised. We use Google Analytics to understand site usage. Analytics data is subject to Google’s own privacy policy and is not shared with or sold to any third party.

3. Cookies & Consent

ToolsNovaHub does not set any first-party tracking cookies. Third-party services used on this site may set cookies:

  • Google Analytics — Sets cookies to track page visits and user sessions anonymously
  • Google AdSense — May set advertising cookies to show relevant ads. You can opt out via Google Ad Settings

If you're visiting from the European Economic Area, the UK, or Switzerland, a consent banner is shown before any analytics or advertising cookies are set, and no such cookie is placed until you make a choice. Google Consent Mode defaults every visitor from those regions to "denied" for ad and analytics storage until you respond to that banner; declining consent doesn't affect any tool's functionality, since the tools themselves don't depend on these cookies.

You can control cookies through your browser settings. Disabling cookies will not affect the functionality of our tools.

4. Third-Party APIs

Our tools use the following external APIs. When you use a tool, your query is sent directly to these services from your browser (except where Section 1a applies). Please review their respective privacy policies:

  • ipapi.co, geojs.io, freeipapi.com — IP geolocation data (compared side-by-side in IP Geolocation API Tester; used individually elsewhere)
  • ipinfo.io — IP metadata, hostname and organisation data
  • ipwho.is — IP security flags, VPN/proxy/Tor detection and country data
  • dns.google, cloudflare-dns.com, dns.quad9.net — DNS-over-HTTPS record queries (multiple resolvers are used for cross-resolver comparisons such as DNS Propagation Checker and DNS Leak Test)
  • rdap.org — Domain WHOIS/RDAP registration data
  • crt.sh — Public Certificate Transparency log search for SSL Certificate Checker and Malware Scanner
  • api.ipify.org, api64.ipify.org — Public IP auto-detection for the My IP feature
  • api.bgpview.io, bgp.he.net — BGP routing, ASN and prefix data for BGP Lookup and ASN-related links
  • DNSBL zones (Spamhaus, SpamCop, Barracuda, SORBS, UCEPROTECT, SpamRats, PSBL, JustSpam, GBUdb, Blocklist.de, Manitu, and abuseat.org) — queried by IP Blacklist Checker to check whether an IP is listed; Malware Scanner separately queries Spamhaus DBL and SURBL to check whether a domain is listed
  • tile.openstreetmap.org / openstreetmap.org — Map tile rendering; maps.google.com is linked as an optional external "view on map" link, not embedded
  • unpkg.com — Serves the Leaflet.js mapping library used to render location maps

Security Headers Checker, HTTP Headers Checker, Website Security Scanner and Redirect Checker additionally route through our own serverless proxy as described in Section 1a — our proxy code does not log or retain the URLs you check, though the underlying hosting infrastructure may keep brief standard operational logs outside our control.

5. Advertising

ToolsNovaHub displays advertisements served by Google AdSense. Google uses cookies to serve ads based on your browsing history. We do not have access to or control over the cookies used by advertisers. To learn more or opt out, visit Google’s Advertising Policies.

6. Data Security

The entire ToolsNovaHub website is served over HTTPS (TLS encryption). All data in transit between your browser and our site is encrypted. Since we do not store user query data on our servers, there is no user database that could be breached.

7. Children’s Privacy

ToolsNovaHub is not directed at children under the age of 13 and we do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us.

8. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. Continued use of the site after changes constitutes acceptance of the new policy.

9. Contact

For privacy-related questions or concerns, contact us at support@toolsnovahub.com.

Frequently Asked Questions

No. We do not sell, rent, or share personal data with third parties for marketing purposes. Advertising cookies are managed entirely by Google AdSense per its own policy.
No. It only relays the single URL you explicitly submit through a stateless proxy that fetches that one page's headers — it has no visibility into your browsing elsewhere. See Section 1a for details.
The lookup itself isn't logged by us, but remember the underlying data (Certificate Transparency logs, DNS TXT records) is inherently public — anyone else could look up the same domain and see the same results.
Since we don't store your tool queries in the first place, there's typically nothing to delete. For analytics or advertising cookie concerns, use the opt-out links in Sections 3 and 5.
Because we minimise data collection by design — no accounts, no stored query logs — most GDPR data-subject request categories (access, deletion, portability) are inherently satisfied by having nothing to provide.