WhatAmI ← Back to the check

Privacy Policy

Last updated: 14 September 2026

WhatAmI (“we”, “us”) builds connection- and device-integrity detection. This policy covers all of our products: the website at whatami.me, the embeddable detection tag, and the apps (mobile / desktop network-integrity monitors). Each product is described separately below, because what is processed — and who is responsible for it — differs.

On this page: Website · Detection tag · Apps · Enterprise · Retention, security & your rights

1. The website — whatami.me

Role: we are the controller for your direct use of the site.

When you run the check, your browser performs measurements and sends them to our server, which returns a result. Most items are measurements and hashes, not content.

Network & connection

Device & browser

Behaviour, context & result

2. The embeddable detection tag

Role: the website that embeds the tag is the controller; we act as its processor.

Other websites can run our detection on their own visitors to prevent fraud and abuse (VPN/proxy use, multi-accounting, bots, connection tampering). When you encounter our detection on another website, that website’s operator decides to run it and is responsible for informing you; we process the data on their behalf to return a risk verdict. The categories are the same as §1, and additionally:

The tag is used only for fraud and abuse prevention — never for advertising, marketing profiles, cross-site tracking, or resale of data.

3. The apps — network-integrity monitors

Role: you install it on your own device and choose to run a scan; we process the results to return a verdict.

Our mobile and desktop apps look at your own device’s network behaviour to detect proxyware / residential-proxy SDKs, VPN and relay apps, and malware-like beaconing — software that may be running on the device without your knowledge. With your explicit consent (on Android, the system VPN permission), the app observes the device’s outgoing connections locally.

What the app reads on the device

What the app does NOT read or keep

Identity & isolation

4. Enterprise / on-premises

Role: the deploying organisation is the controller; the data stays on their infrastructure.

For organisations that deploy WhatAmI on their own premises, collection and storage happen on the customer’s own infrastructure. WhatAmI does not receive that traffic data; the deploying organisation is the controller and governs it under its own policies.

5. What we never do · retention · security · your rights

What we never collect or do

Why we process it

To perform the detection you or the operator requested, to display and explain the result, and to maintain and improve the accuracy of the detection engine. Where the law requires a basis, we rely on legitimate interests in preventing fraud and abuse, or on your consent where you install and run an app.

Storage & retention

International transfers

If you are in the EU/EEA/UK, data may be processed on our server in Canada. Where an adequacy decision does not cover the transfer, appropriate safeguards (such as Standard Contractual Clauses) apply.

Your rights

Depending on where you live, you may have the right to access, correct, erase, or restrict your data, or object to its processing. For the website and apps, contact us directly; for the tag on a third-party site, contact that site’s operator, who can direct the request to us as their processor. Records are keyed by IP, device fingerprint / identifier, and session, so we can locate and act on them.

Contact

Email whatamicheck@gmail.com for any privacy request or question.

Changes

We may update this policy; the “last updated” date reflects the current version, and material changes will appear here.

This document describes how our products handle data in plain terms, for transparency. It is not legal advice.