Last updated: September 11, 2026
This policy explains what Digital Checkmark LLC collects when you use this website and our free security tools, why we collect it, how long we keep it, and who else sees it. We have written it in plain language rather than legal boilerplate, because a privacy policy you cannot read protects nobody.
The short version. If you run one of our free tools and ask for the report, we store your email address, your IP address, and a summary of what the tool found. We keep it for 90 days (180 days for the email analyzer) and then it is deleted automatically. We do not sell your data, we do not run advertising, and we do not add you to a marketing list. You can ask us to delete your record at any time and we will do it.
Who we are
Digital Checkmark LLC is an IT and cybersecurity services company based in Tampa, Florida, United States. We are the controller of the personal data described in this policy.
For any privacy question or request, write to [email protected]. A person reads that inbox between 8am and 8pm Eastern Time.
What we collect, and why
1. When you use a free tool
Our free tools can be used without giving us anything. You only give us an email address if you ask for the full report to be sent to you. When you do, we verify the address and then store a record that contains:
- The email address you submitted
- Your IP address
- The date and time, and which tool you used
- A summary of the result, which differs by tool (see the table below)
We collect the email address to deliver the report you asked for and so we can recognize you if you come back. We collect the IP address for one reason only: abuse prevention. These tools make outbound queries to third party services on your behalf, and without an IP we cannot stop somebody from using them as a free scanning engine.
| Tool | What the result summary contains | Kept for |
|---|---|---|
| Breach Checker | Number of breaches and pastes found, the names of the breaches, a risk level | 90 days |
| Email Health Check | The domain you analyzed, and how many findings fell into each severity level | 90 days |
| Email Analyzer | The subject line and sender address of the message you analyzed, its spam and threat scores, and how many indicators and attachments it contained | 180 days |
| Ransomware Tracker | The term you searched for, and how many results and groups matched | 90 days |
| Cyber Toolkit | Which utility you used and its category | 90 days |
| Voice Forge | Which voice and output format you used | 90 days |
The email analyzer deserves a specific note. To analyze a message you upload or paste it, and the analysis itself is performed and then discarded. What we keep afterwards is only the summary above, which does include the subject line and the sender address of the analyzed message. If the message you are analyzing is sensitive, please keep that in mind. The body of the message and its attachments are not stored.
2. When you contact us
The contact form on this site is served from our own customer system at crm.digitalchk.com and submits directly to it. It collects what you type into it, which normally means your name, your email address, and your message. We keep that for as long as we are in contact with you or have a business relationship, and we delete it on request.
3. When you simply browse
Our web server writes standard access logs containing IP address, timestamp, the page requested, and the browser user agent. This is ordinary server operation and is used for security and troubleshooting. Logs rotate and age out.
We also use Google Analytics 4 to understand which pages are read and how people arrive. This tells us that a page was viewed, roughly from where, and on what kind of device. We do not use it to build advertising profiles, we do not run ads on this site, and we have no advertising network connected.
Who else sees your data
We use a small number of outside services to make the tools work. Each one receives only what it needs to do its job. We do not sell personal data to anyone, and we never have.
| Service | What it receives | Why |
|---|---|---|
| Cloudflare | Your IP address and request metadata | Serves and protects the site, and runs the anti-bot challenge on the tools |
| Reoon | The email address you submit | Confirms the address is real and deliverable before we send a report to it |
| OpenAI | The technical findings of your analysis | Writes the plain language explanation and action plan in your report |
| Google (Gemini) | The technical findings from the email analyzer | Same purpose, used by that tool |
| Emailit | Your email address and the report | Delivers the email |
| Have I Been Pwned | Your email address, in the form their API requires | Performs the breach lookup you requested |
| ransomware.live | Your search term | Provides the ransomware group and victim data |
| Google Analytics | Page view data from your browser | Site statistics |
Some things that might look like third parties are not. Our PDF report generator runs on our own server and your report never leaves it during conversion. Our customer system and the email analyzer backend are likewise our own infrastructure.
Beyond the above, we disclose personal data only when the law requires it, or to protect our rights or the safety of others.
What we do not do
- We do not sell or rent your personal data.
- We do not add you to a mailing list because you used a free tool. The email you give us is used to send the report you asked for, and nothing else. If we ever offer a newsletter it will be a separate, explicit opt in.
- We do not run advertising or advertising trackers on this site.
- We do not store the body or attachments of messages submitted to the email analyzer.
How long we keep things
Tool records are deleted automatically once they pass the retention period shown in the table above: 90 days for most tools, 180 days for the email analyzer. This runs on a schedule, it is not something we have to remember to do. Contact enquiries and client records are kept for as long as the relationship or our legal obligations require, and deleted on request.
Cookies
This site uses a small number of cookies:
- Google Analytics sets two cookies,
_gaand_ga_W5YRYJGN9V, to distinguish one visit from another for statistics. pll_language, to remember whether you are reading the English or the Spanish version.- WordPress sets session cookies only if you log in, which applies to our staff, not to visitors.
- The anti-bot check on our tools runs from
challenges.cloudflare.comand keeps its state there, not on this domain.
You can block or delete cookies in your browser settings. The tools rely on the anti-bot challenge, so blocking those particular cookies may prevent them from running.
Your rights
Wherever you are, you can ask us to:
- Tell you what we hold about you
- Send you a copy of it
- Correct it if it is wrong
- Delete it
Write to [email protected] from the address concerned, or tell us which address to look up. We will confirm within 30 days, and normally much sooner. We do not charge for this and we will not ask you why.
If you are in the European Economic Area or the United Kingdom, the GDPR applies to you. Our lawful basis is your consent when you submit an email address to receive a report, and our legitimate interest in preventing abuse of the tools when we log an IP address. You also have the right to object to processing, to request portability, and to complain to your national supervisory authority.
If you are a California resident, the CCPA and CPRA apply to you. You have the right to know what is collected, to delete it, to correct it, and to opt out of sale or sharing. As stated above, we do not sell or share personal data, so there is nothing to opt out of, but the right to know and to delete applies and we honor it.
Where your data goes
We are based in the United States and our infrastructure is hosted in Europe. The services listed above operate internationally. If you are writing to us from outside the United States, your data will be processed in the United States and in the European Union.
Security
The site runs over HTTPS with modern transport security. Administrative access requires two factor authentication. Tool submissions pass an anti-bot challenge and an email verification step before any report is generated. Access to stored records is limited to the people who need it.
No system is perfect. If we ever discover a breach affecting your personal data, we will tell the people affected and the relevant authorities as the law requires, and we will tell you what actually happened rather than a sanitized version of it.
Children
This site and these tools are intended for business use by adults. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to us and we will remove it.
Changes to this policy
If we change how we handle personal data, we will update this page and change the date at the top. For a change that materially affects people whose data we already hold, we will say so clearly rather than quietly editing the text.
Contact
Digital Checkmark LLC
Tampa, Florida, United States
[email protected]
