Skip to content

Privacy Policy

Last updated: 2026-06-15

TechStack Analyzer (https://stack.leunos.com) is a non-commercial hobby project. This page explains what data is processed when you use it, on what legal basis, and what rights you have under the EU General Data Protection Regulation (GDPR).

Data processing is kept to the minimum needed to run the service securely. There are no user accounts, no advertising, and no tracking.

Who is responsible (controller)

Loading operator contact details…

Applicable jurisdiction / data protection law: Germany / EU.

What data is processed

  • Server access data. Like any website, the hosting and CDN provider records technical request data such as your IP address, the date and time, the requested URL/path, the HTTP status, your browser user agent and — where the browser sends it — the referrer. Error logs and security logs may also be generated.
  • Data you submit to the tool. When you analyze a website, the URL or hostname you enter is sent to the server so it can perform the requested analysis. To do this safely the server fetches that target site and looks up its hostname through a public DNS resolver. Only enter targets you are allowed to analyze (see the terms).
  • Cookies / local storage. This project does not set any cookies and does not store data in your browser's local or session storage. There is no login, no session state, and no theme/language preference stored on your device.
  • Third-party calls. To carry out an analysis the server contacts the third-party website you specified, a public DNS-over-HTTPS resolver, and — within strict limits — a small number of external resources (scripts, stylesheets and web app manifests) that the target page references. See “Who receives data” below.

Legal basis

  • Art. 6(1)(f) GDPR (legitimate interest) — in operating the service securely and reliably, including server, error and security logs needed to prevent abuse and keep the service available.
  • Art. 6(1)(b)/(f) GDPR (requested function) — when you intentionally submit a URL, processing that input is necessary to perform the analysis you asked for.
  • Art. 6(1)(a) GDPR (consent) — would only apply to optional analytics, tracking, marketing cookies or non-essential third-party embeds. This project uses none of these, so no consent is requested.

How long data is kept

The analyzer does not use a database or store scan history. Successful reports and their target URLs may be cached at the Cloudflare edge for up to 60 seconds to serve repeated requests. Cached reports retain the original analysis timestamp.

Technical server, error and security logs generated by the hosting/CDN provider are kept only as long as needed for operation, security and debugging, after which they are deleted or anonymized according to the provider's defaults, unless a specific retention period has been configured for this deployment.

Who receives data (providers & transfers)

The following categories of processors may be involved, depending on deployment configuration:

  • Hosting, CDN & edge functions. The site is built for Cloudflare Pages and its serverless functions, so Cloudflare processes request and log data on the operator's behalf.
  • Public DNS resolver. To validate and classify a target, the hostname you submit is sent to a public DNS-over-HTTPS resolver (currently Google Public DNS, dns.google), depending on deployment configuration.
  • The website you analyze. The server sends an HTTP request to the third-party target you specify; that site receives the request the same way it would receive any visitor.
  • Resources referenced by that website. To confirm some detections, the server may fetch a small, capped number of resources the target page links to — such as scripts, stylesheets or a web app manifest. These can be served by third parties (for example CDNs or package/script hosts), which therefore receive the request needed to retrieve the resource.

Some providers may process data outside the EU/EEA. Where that happens, transfers rely on the safeguards offered by the respective provider (such as EU Standard Contractual Clauses), depending on deployment configuration.

Cookies, storage & consent

This project uses no cookies and no browser storage, and it runs no analytics, advertising or tracking. Because there is nothing that requires consent, there is intentionally no cookie consent banner.

Your rights

Under the GDPR you have the right to:

  • access the personal data processed about you;
  • have inaccurate data rectified;
  • have your data erased;
  • restrict processing;
  • object to processing based on legitimate interest;
  • data portability; and
  • lodge a complaint with a data protection supervisory authority.

To exercise these rights, contact the controller listed above. As this is a hobby project with minimal data, most requests can be handled quickly.

Analyzing third-party websites

The analyzer fetches and inspects the public website you point it at. Only submit targets you own or are explicitly authorized to test. Misuse is your responsibility — please read the acceptable-use terms.