RequestScope privacy notice

This notice describes what a trace sends, what RequestScope retains, and which optional services receive data. It applies to the open testing service at requestscope.illek.ie.

What is retained

A report is retained in Cloudflare D1 for up to 14 days. It contains a generated report ID, redacted requested and final URLs, hostnames, DNS observations, bounded HTTP status and selected redacted headers, redirect timing, static HTML reference metadata, derived findings, optional coverage, and release provenance.

Query values and URL fragments are removed before storage. High-entropy or token-like path segments (reset tokens, UUIDs, JWTs, and similar) are replaced with [redacted]. URL-bearing Location, Content-Security-Policy, NEL, Report-To, and derived JavaScript evidence are sanitized. Raw page bodies, cookies, caller headers, message context, and provider response bodies are not retained.

Observation identity

Each trace uses one of two fixed request identities. The default desktop profile identifies as RequestScope. The optional mobile profile identifies as mobile Safari (iPhone) so device-specific pages can be compared. Callers cannot supply a custom User-Agent. The chosen profile is stored as observation.deviceProfile on the report.

Recent-scan cache

A successful observation may be reused for five minutes for the same hashed client and the same options (URL, dependency map, reputation consent, device profile, and risk context). Different clients do not receive each other's report IDs. Create and stream responses advertise the reuse with the X-RequestScope-Recent-Observation header (reused or fresh) and a non-persisted reusedRecentObservation flag on the returned report. Quota is still charged on a cache hit. Reports remain capability URLs: anyone who learns the 16-character ID can retrieve the redacted report until it expires.

What the trace contacts

Optional reputation consent

Reputation is disabled unless the checkbox or request field is explicitly enabled. Google Web Risk and PhishTank receive the complete original and final URL, including query values, because those values can affect a match. PhishTank may record request parameters and the source IP used for the request. Cloudflare's malware-filtering DNS receives hostnames only. These services have their own terms and privacy notices. A provider not listing a URL is not proof of safety.

Access and abuse controls

Reports use opaque bearer-style IDs and are intended for limited sharing during open testing. Scan creation, provider quota accounting, MCP tool calls, and existing-report reads use bounded daily counters with hashed client keys. MCP handshake or discovery requests do not write rate-limit rows. A well-formed but unknown report ID is answered 404 without writing a rate-limit row.

The MCP endpoint and /api/v1/url-risk are intentionally open for testing and do not require an API key. They are protected by stricter daily limits than a wide-open agent API: MCP tool calls are capped near the anonymous UI scan limit (25 vs 15), and MCP traces default to no dependency map. Missing report probes do not consume retrieval quota. This is a rate-limited test surface, not a tenant boundary, and should not receive confidential customer URLs.

Your choices

Do not submit URLs containing credentials, private customer data, session tokens, or reset links. Leave optional reputation and dependency mapping disabled when their external processing is not appropriate. Contact Illek through the published site if you need a report removed before expiry or need to raise a security concern.

Last updated 11 September 2026. This notice describes the current open testing implementation. It does not create a promise of a particular provider's retention or availability.