Match each signal to its source
Open the exposure inventory to inspect this browser. Use the distinctions below: information available to JavaScript is not automatically sent to a server, and an API being present does not mean permission was granted.
- Public IP, network owner and approximate city
- Source: the request to our network endpoint and Cloudflare metadata. Sending that request necessarily exposes its public route to our infrastructure. It does not disclose GPS or your street address.
- Language, timezone, viewport and screen dimensions
- Source: browser APIs available to page scripts. They describe settings and the current environment; timezone mismatch is not proof of a VPN or deception.
- Cookies and storage availability
- Source: browser capability checks. A supported API is different from accessible contents or a record of another website’s activity. This inventory does not read other sites’ storage.
- Camera, microphone and device location
- Source: separate permission-controlled APIs. This inventory does not ask to activate them. A permission already granted, browser policy or an unavailable API can affect whether another site shows a new prompt.
- Local files, passwords and browsing history
- Not enumerated by this tool. Selecting a file gives the receiving page access to that file; ordinary page scripts do not gain access to an arbitrary folder, saved passwords or your complete history.
No persistent fingerprint or population-based uniqueness score is computed here. Similar settings can be shared by many people; this inventory cannot identify a person.
Primary references: Cloudflare request fields, browser Navigator properties and geolocation permission boundaries.
The server sees the connection
A site generally receives the public IP, request headers, protocol details, and metadata added by its infrastructure provider.
That information can reveal approximate network context, not a precise identity or physical address by itself.
Scripts see the page environment
JavaScript can read viewport, language, timezone, feature support, storage availability, and many device-adjacent attributes.
Technical availability is different from a site actually storing or sharing the information.
Permissions create boundaries
Precise location, camera, microphone, notifications, and some other capabilities require permission or a deliberate action.
Review prompts carefully and revoke permissions you no longer need.
Files are not openly browsable
An ordinary page cannot enumerate arbitrary local files. It can read a file you explicitly select or drop into an allowed control.
Local tools can process selected data without uploading it.
Inspect behavior, not slogans
Read the privacy notice, inspect network requests when needed, and prefer tools that explain what is local, transmitted, stored, and retained.
Absolute promises such as complete anonymity or universal no-logging claims deserve skepticism.