Privacy Policy
A simple website should have a simple privacy posture.
Diagnostics usage monitoring
Barefoot Diagnostics may record aggregate tool usage and, for server-side tests, the tool name, tested public domain or IP address, timestamp and a result summary for operational monitoring and troubleshooting. A result summary may also be sent internally to alerts@barefootsoft.com. Visitor IP addresses are used transiently for rate limiting but are not included in diagnostic result emails.
The Email Header Analyzer and DMARC XML Report Analyzer are designed to process their sensitive input in the visitor's browser. Raw email headers and uploaded DMARC XML content are not sent to Barefoot by those tools.
If you request an emailed diagnostic report, the email address you provide, the diagnostic name, tested target (where relevant) and the result summary displayed in your browser are sent to Barefoot's report-delivery endpoint so the requested HTML email and PDF can be generated and delivered. For browser-only Header/DMARC tools, the raw pasted header or XML file is still not uploaded; only the displayed summary is used. Barefoot also receives a report-request notification containing the email address, test name and target so we can identify the request and, where appropriate, follow up about the findings. Report requests are not added to an advertising mailing list.
Website data
This website does not use advertising cookies or third-party advertising analytics. Barefoot Diagnostics uses limited operational telemetry as described above; there is no visitor account system or marketing-profile database.
96K private area
The password-protected 96K area records successful entry events including the email address supplied, timestamp, IP address and browser user-agent so the Keykeeper can see who entered and when. If an authorised visitor uploads emulator media, Barefoot stores the uploaded file privately outside the public web root together with limited upload audit information such as uploader email, IP address, filename, system and size. Uploaded media remains until the Keykeeper deletes it. Passwords are never logged.
Protected-area security logging
The 96K and Server Health gates record successful, failed and rate-limited authentication submissions for security purposes. Records may include the email address supplied, timestamp, client IP address, coarse IP-derived location, browser user-agent and outcome/reason. Password plaintext is never stored or included in alerts; failed attempts use only length and a keyed fingerprint for comparison. Security alerts are sent internally to alerts@barefootsoft.com.
The Server Health dashboard is read-only. If an authorised administrator requests an emailed PDF health report, it is generated only from the existing read-only telemetry snapshot and sent to the fixed internal address alerts@barefootsoft.com. The report excludes passwords, password hashes, authentication tokens, email content, message subjects and configuration secrets.
Local browser storage
The site may use short-lived browser session storage solely to avoid replaying the welcome animation repeatedly during the same browsing session. This is not used for advertising or profiling.
Email and WhatsApp
If you contact Barefoot by email or WhatsApp, your message and contact details are processed through those services for the purpose of responding to you and providing requested services.
External services
Links to partner services and free tools open external websites. Those services have their own privacy practices and are outside the operation of this static website.
Contact
Questions about privacy can be sent to Email Barefoot.
