Privacy Policy
Effective date: 9 August 2026 · Operated by Antibody Cyber / WinCyberScan
1. Overview
Cookie Finder Tool (CFT) at cft.wincyberscan.com is a free security scanner built for defenders. This policy explains what data is processed when you use the tool, and what is not collected, stored, or shared.
2. Data We Do Not Collect
CFT is designed with a privacy-first architecture. We do not:
- Set cookies or any persistent storage in your browser
- Collect names, email addresses, or any personally identifiable information
- Run analytics scripts, tracking pixels, or third-party SDKs
- Log, store, or retain the URLs you submit for scanning
- Log, store, or transmit cookie values — values are always redacted before any processing
- Share any data with third parties for advertising or profiling
3. Scan Processing
When you submit a URL for a Remote URL Scan, the following occurs server-side:
- CFT's server makes an HTTP GET request to the URL you provided
- The
Set-Cookieresponse headers are extracted and analysed - Cookie values are immediately redacted — they are never stored or returned to you
- The classified results are returned to your browser and discarded from the server
- No scan target URL, result, or IP address is written to persistent storage
Standard web server access logs (nginx) may record the source IP and request timestamp as part of normal server operation. These logs are retained for up to 14 days for security and abuse monitoring, then deleted.
4. Cookies and Local Storage
CFT sets zero cookies on your browser. No localStorage, sessionStorage, or IndexedDB data is written. You can verify this in your browser's developer tools at any time.
5. Third-Party Services
CFT does not load any third-party scripts, fonts, stylesheets, or resources. All assets are served directly from cft.wincyberscan.com. There are no calls to Google Analytics, Facebook Pixel, Cloudflare Insights, or similar services.
6. Infrastructure
CFT runs on a dedicated server hosted on Amazon Web Services (AWS) in the US-East-1 region. AWS acts as a data processor under a standard Data Processing Agreement. No scan data is forwarded to AWS services beyond the compute instance itself.
7. Children's Privacy
CFT is a professional security tool intended for adults. We do not knowingly process data from children under the age of 13.
8. Changes to This Policy
If this policy changes materially, the effective date above will be updated. Continued use of CFT after any update constitutes acceptance of the revised policy.
9. Contact
Questions about this privacy policy can be directed to Antibody Cyber via the contact details on that site.