Enter a URL below to audit the current privacy.txt and generate a suggested privacy.txt.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Invalid URL. Expecting https://host
We're fixing a few things with the audit tool. It will be online shortly.
Looking up the current https://foo.com
privacy.txt
Current https://foo.com
privacy.txt
This site does not have a privacy.txt. If you are the site owner, you can get started by reviewing and copying the suggested text on the right to https://foo.com/.well-known/privacy.txt
This site has a privacy.txt but it is not valid. See errors below. https://foo.com/.well-known/privacy.txt
Error message
This site has a valid privacy.txt 🙌 https://foo.com/.well-known/privacy.txt
Privacy-policy:
https://foo.com/privacy
Privacy-policy-text: | https://foo.com/privacy-policy.txt |
Action-delete-account-and-data:
mailto:privacy@foo.com
Action-delete-personal-data:
mailto:privacy@foo.com
Action-opt-out-sharing:
mailto:privacy@foo.com
Action-shared-list:
mailto:privacy@foo.com
Action-opt-out-marketing:
mailto:privacy@foo.com
Banner:
true,non-specific-custom
Cookie:
test,foo.com,300,false,true,false,true
Gray rows are actions implied by the spec.
Analyzing for privacy.txt suggestions
Privacy-policy:
https://foo.com/privacy
Banner:
true,non-specific-custom
Cookie:
test,foo.com,300,false,true,false,true
Cookie:
test2,foo.com,300,false,true,false,true
Cookie:
test3,foo.com,300,false,true,false,true
Red items missing in or different than the current privacy.txt
Make sure to 301
redirect all API, CDN, and ancillary host https://<host>/privacy.txt
to https://foo.com/.well-known/privacy.txt
. This establishes privacy settings on all connections from the user to your servers. At some point a privacy-aware client may block connections to hosts that do not have a valid https://<host>/privacy.txt
or https://<host>/.well-known/privacy.txt
.