// Policy

Privacy Policy

What we collect, what we don't, and exactly who else is involved. We're a security company — it would be a poor look to be careless with your data.

EFFECTIVE SEPTEMBER 7, 2026

The short version: we run no analytics, no tracking pixels, no advertising networks, and no cookies of our own. Our free tools run in your browser. We collect personal information only when you email us or buy something, and we don't sell or share it.

Who we are

ByTE X Bit Technologies LLC, a Maryland limited liability company, operating byte-x-bit.com. Questions about this policy go to [email protected].

Browsing the site

We don't run analytics software. There is no Google Analytics, no Plausible, no Facebook pixel, no advertising or retargeting network, and no tracking cookie on this site.

Our site is served through Cloudflare, which acts as a content delivery network and security layer. Cloudflare processes your IP address and basic request information to route traffic and block attacks. That's operational, not analytical — we don't build profiles from it. Cloudflare's own privacy practices are described at cloudflare.com/privacypolicy.

We load fonts from Google Fonts, which means your browser contacts Google's servers to fetch them. That's the only third-party asset on our pages.

Some pages store a single preference in your browser's local storage — whether you chose light or dark mode. It never leaves your device and we can't read it.

The free tools

Our tools are built to keep your data on your device. Here is exactly what each one does.

Phishing & Scam Spotter

Any message you paste is analyzed entirely in your browser. It is never uploaded, and we never see it.

If you drop in a file, the file stays on your device — we compute a fingerprint (a hash) locally. If you paste a link, the structural checks also run locally.

The optional threat scan is the one exception, and only if you click it. Clicking "Scan for threats" sends either the file's fingerprint or the link exactly as you typed it to a server we operate, which forwards it to VirusTotal to check against their threat database. A fingerprint reveals nothing about your file's contents. A link you submit becomes visible to other VirusTotal users — so if a link contains an email address, a token, or anything personal, don't run the threat scan on it. Nothing is sent unless you click that button, and we retain no record of what was checked.

DNS & Domain Health Checker

Your browser queries public DNS-over-HTTPS resolvers directly — Cloudflare first, then Google. The domain you enter and your IP address go to those resolvers, exactly as they would for any website lookup. No server of ours is involved and we never see your query.

Other tools

The email checker, posture scanner, posture check, and Sigma validator run entirely in your browser. Nothing you enter is transmitted to us or stored anywhere.

When you contact us

If you email us, we receive whatever you send — your email address, your name, and anything in the message, including scanner reports you choose to attach. Our business email runs on Zoho Mail. We keep correspondence as long as it's useful for the working relationship, and we don't add you to any mailing list. We don't run one.

When you buy a consultation

Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers — we never see or store a card number.

Through Stripe we receive:

We use that to deliver the service you paid for, send receipts, and keep the records a business is required to keep. Stripe's handling of your data is governed by stripe.com/privacy.

When we do work for you

Security work means seeing your systems. Depending on the engagement, that can include domain and DNS configuration, network layout, device details, account settings, and findings about vulnerabilities in your environment.

We treat that as confidential. We use it to do the work you hired us for and for nothing else. We don't share it, sell it, or use it as an example without your written permission. When an engagement ends, you can ask us to delete our working copies of your data and we will.

What we never do

Your choices

You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email [email protected] and we'll respond within 30 days. There's no charge and we won't treat you differently for asking.

Some records we have to keep — transaction records for tax and accounting purposes, for example. We'll tell you if that applies to your request.

If you're covered by a privacy law that grants additional rights, such as the California Consumer Privacy Act or the GDPR, contact us and we'll honor those rights.

Children

This site and our services are for adults and businesses. We don't knowingly collect personal information from anyone under 13. If you believe a child has sent us information, email us and we'll delete it.

Security

We keep client data on systems we control, with access limited to those who need it for the work. No system is perfectly secure, and anyone claiming otherwise is selling something. If we ever learn of a breach affecting your personal information, we'll notify you promptly and tell you what we know.

Changes to this policy

If we change what we collect or who we share it with, we'll update this page and change the effective date above. Material changes affecting existing clients get an email, not just a quiet edit.

Contact

ByTE X Bit Technologies LLC
[email protected]
+1 443-333-9512