Privacy Policy
Last updated: 14 September 2026
WhatAmI (“we”, “us”) builds connection- and device-integrity detection. This policy
covers all of our products: the website at whatami.me, the embeddable
detection tag, and the apps (mobile / desktop network-integrity monitors).
Each product is described separately below, because what is processed — and who is responsible for it —
differs.
1. The website — whatami.me
Role: we are the controller for your direct use of the site.
When you run the check, your browser performs measurements and sends them to our server, which returns
a result. Most items are measurements and hashes, not content.
Network & connection
- Your IP address and values derived from it: country, city, ASN, network operator, and network type
(residential / datacenter / mobile / VPN).
- Transport measurements (round-trip and connection timings, TLS handshake timing) and derived proxy
indicators; a server-side TLS/TCP fingerprint.
- WebRTC candidates, which can reveal local network addresses and, if the connection leaks, a
different public IP.
Device & browser
- A device fingerprint derived from browser and hardware characteristics (canvas / WebGL / audio
hashes, screen, device memory, CPU cores, timezone, languages, voices, codecs, User-Agent and client
hints), plus automation / anti-fingerprint signals.
Behaviour, context & result
- Aggregate interaction counts and timing only — never keystroke content, a coordinate trail, or form
input.
- Page URL, referrer, load timings, a session identifier, and the computed verdict with the signals
behind it.
2. The embeddable detection tag
Role: the website that embeds the tag is the controller; we act as its processor.
Other websites can run our detection on their own visitors to prevent fraud and abuse (VPN/proxy use,
multi-accounting, bots, connection tampering). When you encounter our detection on another
website, that website’s operator decides to run it and is responsible for informing you; we process
the data on their behalf to return a risk verdict. The categories are the same as §1, and additionally:
- A persistent visitor identifier and a session identifier stored in the browser, used to recognise
the same browser across visits (multi-account linkage).
- An optional account identifier the operator may pass, to tie a visit to their own user account.
The tag is used only for fraud and abuse prevention — never for advertising,
marketing profiles, cross-site tracking, or resale of data.
3. The apps — network-integrity monitors
Role: you install it on your own device and choose to run a scan; we process the
results to return a verdict.
Our mobile and desktop apps look at your own device’s network behaviour to detect
proxyware / residential-proxy SDKs, VPN and relay apps, and malware-like beaconing — software that may be
running on the device without your knowledge. With your explicit consent (on Android, the system VPN
permission), the app observes the device’s outgoing connections locally.
What the app reads on the device
- Connection metadata: destination IP and port, bytes sent/received, and the owning app package.
- DNS lookups: the domain queried, the response code, and the app that asked.
- Per-app usage statistics: background vs foreground data volume and when each app was last opened.
- Whether installed apps declare a VPN service, and which app currently holds the system VPN.
What the app does NOT read or keep
- No packet payloads, message content, page content, or browsing history — only the metadata above.
- On the device, only the last verdict is cached (app names and labels); the traffic
log, destinations, and domains are never written to the device’s storage.
Identity & isolation
- The app uses a per-install identifier derived from a device value that is hashed and salted
on the device — the raw value never leaves it. It exists so a device keeps one history across
re-installs; it is not tied to your name or account.
- Each device’s data is analysed only against itself; one device’s data never enters
another device’s analysis or verdict. The only thing shared across devices is the reputation of a
public relay gateway (its address, port, and how many networks saw it) — never any device’s private
traffic.
4. Enterprise / on-premises
Role: the deploying organisation is the controller; the data stays on their
infrastructure.
For organisations that deploy WhatAmI on their own premises, collection and storage happen on
the customer’s own infrastructure. WhatAmI does not receive that traffic data; the
deploying organisation is the controller and governs it under its own policies.
5. What we never do · retention · security · your rights
What we never collect or do
- No form contents, passwords, or message text; no page or browsing content.
- No special-category data (health, biometric identification, political or religious data).
- No microphone or camera data; no precise location unless you explicitly grant a browser prompt.
- No advertising identifiers. We do not sell your data or share it for marketing.
Why we process it
To perform the detection you or the operator requested, to display and explain the result, and to
maintain and improve the accuracy of the detection engine. Where the law requires a basis, we rely on
legitimate interests in preventing fraud and abuse, or on your consent where you install and run an app.
Storage & retention
- For the website, tag and apps, records are stored on our server in Canada (OVH)
and transmitted over HTTPS. (Enterprise data stays on the customer’s own infrastructure.)
- Raw per-scan records are retained for up to 90 days; aggregated, non-identifying
statistics may be kept longer. Detection-verdict history for a device is kept while that device keeps
being scanned, so a result is not lost between scans.
- Access is restricted to the operator.
International transfers
If you are in the EU/EEA/UK, data may be processed on our server in Canada. Where an adequacy decision
does not cover the transfer, appropriate safeguards (such as Standard Contractual Clauses) apply.
Your rights
Depending on where you live, you may have the right to access, correct, erase, or restrict your data,
or object to its processing. For the website and apps, contact us directly; for the tag on a third-party
site, contact that site’s operator, who can direct the request to us as their processor. Records are
keyed by IP, device fingerprint / identifier, and session, so we can locate and act on them.
Contact
Email whatamicheck@gmail.com for any privacy request or
question.
Changes
We may update this policy; the “last updated” date reflects the current version, and material changes
will appear here.
This document describes how our products handle data in plain terms, for transparency.
It is not legal advice.