Your Privacy Matters

Privacy Policy

We believe in transparency. This policy explains exactly what data we collect (and don't collect), how we use it, and your rights as a user.

Last updated: 2026-09-18 Version: v2.1

Overview

Lutfifakee ("we", "our", "us") operates the website at https://lutfifakee.top/ and provides online security tools for penetration testing, text processing, and developer utilities.

This Privacy Policy explains how we collect, use, and protect your information when you use our services. By using our website, you agree to the practices described in this policy.

We DO Collect

  • Anonymized usage statistics
  • Technical logs (IP hash, timestamp)
  • Session cookies (essential only)

We DO NOT Collect

  • Personal information
  • Tool input/output data
  • Email addresses
  • Payment information

Data We Collect

We collect the minimum amount of data necessary to operate our services:

Anonymized Usage Statistics

Aggregated data on tool usage, page views, and general traffic patterns. This data cannot be traced back to individual users.

Technical Logs

Server logs include timestamp, HTTP status code, and a hashed version of your IP address (SHA-256). We never store raw IP addresses.

Session Cookies

We use essential session cookies for CSRF protection and rate limiting. These are deleted when you close your browser.

Data We Do NOT Collect

We want to be absolutely clear about what we don't collect:

No Personal Information

We don't collect names, email addresses, phone numbers, or any personally identifiable information (PII).

No Tool Input/Output Data

When you use our tools, your input and output data is processed in real-time and never stored on our servers.

No Payment Information

All tools are free. We don't process payments, so we never collect credit card or banking information.

No Precise Location

We don't collect GPS data or precise location information. Country-level data may be inferred from IP for statistics only.

No Device Fingerprinting

We don't use browser fingerprinting, canvas fingerprinting, or any tracking technique to identify you across sessions.

No Selling to Third Parties

We never sell, rent, or trade your data to advertisers, data brokers, or any third party. Ever.

How We Use Data

The limited data we collect is used exclusively for:

Service Operation

To keep our tools running, process requests, and respond to user actions.

Security & Abuse Prevention

To detect and prevent abuse, spam, and malicious attacks (rate limiting, CSRF protection).

Performance Monitoring

To identify issues, optimize performance, and improve user experience.

Bug Fixing

To diagnose errors and fix problems reported by users.

Cookies & Tracking

We use only essential cookies. Here's exactly what we use:

Cookie Purpose Duration Type
PHPSESSID Session management & CSRF protection Session Essential
csrf_token Security token for form submissions Session Essential
No Tracking Cookies:

We don't use Google Analytics, Facebook Pixel, or any third-party tracking cookies. Your browsing behavior on our site is not tracked.

Third-Party Services

We use a minimal set of third-party services to operate:

Cloudflare

Purpose: CDN & DDoS protection

Data shared: IP address (required for CDN routing)

Cloudflare Privacy Policy

Google Fonts

Purpose: Typography (Plus Jakarta Sans, JetBrains Mono)

Data shared: IP address (for font delivery)

Google Privacy Policy

jsDelivr / cdnjs

Purpose: Font Awesome icons

Data shared: IP address (for asset delivery)

jsDelivr Privacy Policy

Data Retention

We retain data only as long as necessary:

Session CSRF tokens, rate limit counters
7 days Server error logs (anonymized)
30 days Aggregated usage statistics
Never Tool input/output data (not stored)

Your Rights

Depending on your location, you may have the following rights:

Right to Access

Request a copy of the data we hold about you.

Right to Erasure

Request deletion of your personal data.

Right to Object

Object to processing of your data.

Right to Portability

Receive your data in a machine-readable format.

Note:

Since we don't collect personal information, most data rights are automatically satisfied. If you have specific concerns, contact us.

GDPR Compliant CCPA Compliant No Data Selling

Children's Privacy

Our services are not directed at children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.

Security

We take security seriously. Here's how we protect your data:

HTTPS Encryption

All traffic to and from our site is encrypted with TLS 1.3.

CSRF Protection

All forms are protected with CSRF tokens to prevent cross-site attacks.

Rate Limiting

Automatic rate limiting prevents abuse and DDoS attempts.

Hashed IPs

IP addresses are hashed (SHA-256) before being logged, protecting your identity.

Policy Changes

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the "Last updated" date at the top of this page
  • Increment the version number
  • Announce significant changes on our GitHub and X (Twitter)

We encourage you to review this page periodically. Continued use of our services after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or how we handle your data, you can reach us at:

Our promise: We will never sell your data, never track you across the web, and never compromise your privacy for profit. This is our commitment to you.