1. Zero-Log Diagnostic Guarantee for Interactive Tools

HTTPLens hosts interactive developer tools including the HTTP Response Explainer, CORS Preflight Simulator, Status Code Decision Picker, HTTP Header Security Analyzer, cURL to Code Converter, Cache-Control Validator, Retry-After Calculator, and API Error Inspector.

Strict Client-Side Isolation: All data, HTTP headers, authentication tokens, API URLs, cURL commands, and JSON payloads that you paste or generate within HTTPLens tools are executed 100% locally in your browser runtime. No payload contents are ever stored, cached, logged, or transmitted across network connections.

2. Data Collection and Processing

We do not require user accounts, passwords, or personal registration to access HTTPLens. The categories of data processed are strictly limited to:

  • Technical Web Server Logs: Standard HTTP request logs (IP address, User-Agent, requested URI, timestamp) generated by our hosting infrastructure (e.g. Vercel, Cloudflare) for operational security, DDoS mitigation, and server integrity. Server logs are automatically rotated and purged after 30 days.
  • Client-Side Local Storage: A single non-tracking key (httplens-theme) stored in your browser's localStorage to remember your selected theme preference (Light or Dark mode). This contains no personal identifiers.
  • Audience Measurement (Google Analytics 4): Aggregated, non-identifying telemetry used exclusively to assess page popularity and identify broken links. IP anonymization is permanently enabled, and Google Signals / advertising features are disabled.

3. Legal Basis for Processing (GDPR Article 6)

Our processing of server logs and privacy-preserving analytics is grounded on:

  • Legitimate Interest (Art. 6(1)(f) GDPR): Ensuring website security, network availability, and maintaining reference documentation relevance for the global software engineering community.
  • Consent (Art. 6(1)(a) GDPR): Where required for non-essential cookies, managed according to our Cookie Policy.

4. Data Retention and Third-Party Subprocessors

HTTPLens engages only established, compliant cloud infrastructure providers adhering to standard contractual clauses (SCCs):

SubprocessorPurposeLocationData Policy
Hosting Provider (Vercel / Cloudflare)Edge static delivery & DDoS protectionGlobal Edge NetworkTemporary server logs (30d max)
Google Analytics (GA4)Anonymized traffic metricsEU / US (SCCs compliant)14-month data retention

5. Your Rights Under the GDPR

Under European data protection laws, you retain the following rights regarding any personal data:

  • Right to access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure / "Right to be forgotten" (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to object to processing (Art. 21 GDPR)

Since HTTPLens does not store user profiles or maintain identifiable databases, exercising these rights generally applies to server logs and can be requested by emailing contact@httplens.net.

6. Contact Data Controller

For any privacy questions or data protection requests: