Privacy Policy
Effective 24 July 2026
Glyphwatch has no accounts, sets no cookies, and runs no analytics. It keeps exactly two things: ordinary server logs, and — only if you type it in — your email address for the monitoring waitlist. Scan results are never stored.
Controller (GDPR)
The controller responsible for this service is the operator listed in the imprint: Mediaforge Patrick Hasse.
Website hosting & server logs
This service is hosted on our own server infrastructure in the EU. When you visit, the web server processes the technical data your browser transmits (IP address, time of request, requested page, user agent) in standard server logs, used solely to operate and secure the service (legal basis: Art. 6 (1) f GDPR) and deleted on a short rotation. Fonts are self-hosted, so no requests are made to third-party CDNs.
The URL you scan
This is the part worth reading, because it is the one thing Glyphwatch does that an ordinary website does not.
- The scan runs on our server, not in your browser. When you submit a URL, our server requests that page, reads its stylesheets, and downloads the font files it references, in order to read the licence metadata inside them.
-
The site you scan sees us, not you. Those requests come from our
server's IP address and identify themselves as
Glyphwatch/0.1. Your own IP address is never passed on to the site being scanned. - The URL and the report are not stored. The submitted address is held in memory only for as long as the scan takes, the report is returned to your browser, and neither is written to a database or a file. We do not keep a history of what has been scanned.
- Please do not submit URLs that contain secrets. Addresses with session tokens, password-reset links or API keys in them should not be pasted into any scanner, including this one — they would appear in our server logs like any other requested path.
Legal basis: performing the scan you asked for (Art. 6 (1) b GDPR) and our legitimate interest in operating the service (Art. 6 (1) f GDPR).
Abuse limits
Because each scan makes outbound requests, the number of scans per IP address per minute is capped. To do that, your IP address is held in memory only, for at most a minute, and is never written to disk. It is discarded automatically (Art. 6 (1) f GDPR — preventing misuse of the service).
Monitoring waitlist
If you enter an email address to hear when Glyphwatch Monitoring opens, that address and the time you submitted it are stored on our server. It is used for one purpose: to email you when the product is available. There is no newsletter and no drip sequence, and the address is not shared with anyone.
Legal basis: your consent (Art. 6 (1) a GDPR), which you can withdraw at any time. Email kontakt@patrickhasse.de and the entry is deleted.
Your rights (GDPR)
Where personal data is processed (essentially: server logs, the abuse limit, the waitlist, and any email you send us), you have the right to access, rectification, erasure, restriction of processing, data portability, and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
Changes & contact
If this policy changes materially, this page will say so plainly. Questions: kontakt@patrickhasse.de.