BITCOPS Security Tools

Privacy Policy

Last updated: 25 August 2026

This policy explains what BITCOPS Security Tools (tools.bitcops.net) does with information when you use the site. We have tried to write it in plain language rather than legal boilerplate, because a privacy policy nobody can read is not much use to anybody.

Who we are

This site is operated by BITCOPS, a cyber security training project based in Abbottabad, Khyber Pakhtunkhwa, Pakistan. For any privacy question, or to exercise any right described below, contact admin@bitcops.net.

Tools that run entirely in your browser

Most tools on this site never send your input anywhere. Hash generation, Base64 and URL encoding and decoding, JWT decoding, password generation and strength estimation, CVSS scoring, subnet calculation and email header analysis are all performed locally by your browser using standard web APIs. We do not receive, log or store the text you paste into those tools, because it never leaves your device.

Tools that require a server request

Some checks cannot be done from a browser. DNS lookups, SPF, DKIM and DMARC checks, TLS certificate inspection, HTTP security header checks, CORS checks and HTTP status checks all require a request to be made from our server to the address you supply. For those tools we receive the domain or URL you entered, and we make the corresponding public request.

We use that information only to produce your result and to apply rate limits that keep the service available. We do not sell it, and we do not use it to build a profile of you. Request records are retained for a short period for abuse prevention and then removed.

Information collected automatically

Like almost every website, our server records standard technical information when a page is requested: IP address, date and time, the page requested, the referring page, and browser and device type. This is used to keep the site running, diagnose faults, and detect abuse.

Cookies

We set a small number of cookies. Strictly necessary cookies keep a session working and protect forms against cross-site request forgery. A preference cookie remembers whether you chose the light or dark theme. Advertising and measurement cookies may be set by third parties as described below. Full detail is in the Cookie Policy.

Advertising

This site is supported by advertising, and we intend to serve ads through Google AdSense. The following disclosures apply to that arrangement:

  • Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites.
  • Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this and other sites on the internet.
  • You may opt out of personalised advertising by visiting Google Ads Settings.
  • You may opt out of third-party vendor use of cookies for personalised advertising at aboutads.info/choices or optout.networkadvertising.org.
  • Third-party advertising vendors operate under their own privacy policies, which we do not control. Google's is available at policies.google.com.

If you are in a region that requires consent before non-essential cookies are set, a consent notice will be presented and advertising cookies will not be set until you agree.

Accounts

This site does not offer public account registration. A small number of administrative accounts exist so that articles can be published and maintained. If you hold one, we store your username, email address and a hashed password. Passwords are hashed with bcrypt and are never stored or transmitted in readable form.

Newsletter and email updates

If you enter your address in the signup form at the foot of any page, we store that address, the page you signed up from, a one-way hash of your IP address, and the date. The IP hash exists only to rate-limit abuse of the form; it cannot be reversed into an address.

We use it for one thing: an occasional email when we publish a new tool or article. We do not send advertising on behalf of third parties, we do not sell or rent the list, and we do not share it with anyone outside BitCops.

Every email carries a one-click unsubscribe link. You can also unsubscribe at any time by writing to admin@bitcops.net, and we will remove you by hand. Unsubscribing removes you from the list and changes nothing else about your use of the tools.

Where consent is the lawful basis for this processing, subscribing is that consent and unsubscribing withdraws it. We keep unsubscribed addresses only so we do not re-add you by mistake; ask and we will delete the record entirely.

Comments

To leave a comment on an article you provide a name, an email address and the comment itself. We also store a one-way hash of your IP address and your browser user agent, both for spam prevention.

Your name and comment are published once approved. Your email address is never published or shared - it exists so we can reply to you if a reply is warranted. Comments are reviewed before they appear, so nothing you write goes live automatically.

To have a comment removed, or the email address behind it deleted, write to admin@bitcops.net.

Your rights

Depending on where you live, you may have the right to request a copy of the personal data we hold about you, to have it corrected or deleted, to object to or restrict certain processing, and to withdraw consent you previously gave. Residents of the European Economic Area and the United Kingdom have these rights under the GDPR. Residents of California have comparable rights under the CCPA, including the right to know what is collected and the right to request deletion. We do not sell personal information as that term is defined under the CCPA.

To exercise any of these rights, email admin@bitcops.net. We will respond within the period required by the applicable law.

Data retention

Server logs and rate-limiting records are kept only as long as they are useful for security and reliability, and are then deleted. Content you publish, if you hold an administrative account, is kept until you remove it.

Children

This site is intended for a general professional audience and is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

Third-party links

Some tools display, and some articles link to, third-party websites. We are not responsible for the privacy practices or content of those sites, and we encourage you to read their policies.

Security

The site is served exclusively over HTTPS, session cookies are marked Secure and HttpOnly, and forms are protected against cross-site request forgery. No system is perfectly secure, but we take reasonable technical measures to protect the limited data we hold.

Changes to this policy

We may update this policy as the site changes. The date at the top of this page reflects the most recent revision. Material changes will be made clear on this page rather than applied silently.