Cookie Policy
The short version
- MyRecon’s own code sets no cookies. Every cookie you pick up here is placed by Google’s advertising script — a few of them stored under the myrecon.xyz name, but set and read by Google, not by us.
- The site keeps four things in your browser’s local storage — your theme, your recent lookups and your saved investigations. They never leave your device, and they are not cookies.
- The only cookies here come from Google advertising, which runs on the tool, the guides and the breach archive. These policy pages, the contact page and Deep Search carry none.
- In the EEA, the UK and Switzerland those cookies are set only after you agree, through Google’s certified consent message. You can reopen it at any time from the footer of any page.
1. What cookies and local storage are
A cookie is a small file a website asks your browser to keep and send back on later visits. A first-party cookie is set by the site you are on; a third-party cookie is set by another company whose content the page loads — an advertising network, for example.
Local storage is a different browser feature. It also keeps data on your device, but unlike a cookie it is never transmitted anywhere: only scripts on the same site, in the same browser, can read it. This policy covers it all the same, because the law governing what gets stored on your device — the EU ePrivacy Directive and its UK and Indian equivalents — covers both, and because you deserve to know what is on your machine either way.
2. What MyRecon stores (no cookies)
MyRecon has no accounts, no sessions and no server-side state tied to you, so there is nothing for a cookie of ours to do, and our own code sets none. (Google’s advertising script does set a few cookies under the myrecon.xyz name; those are Google’s and are listed in section 3.) What our code uses instead is local storage, for four things, all of which exist to make the tool behave the way you asked it to:
| Key | Type | Purpose | Lasts |
|---|---|---|---|
myrecon-theme | Local storage | Remembers whether you chose the light or dark theme, so the site does not flip back on every visit. | Until you clear it |
myrecon.theme | Local storage | The same preference for the Deep Search page, which keeps its own copy. | Until you clear it |
myrecon-history | Local storage | Your recent lookups, so the tool can show them again. Clearable from the tool with the “Clear history” button. | Until you clear it |
myrecon-saved | Local storage | Investigations you explicitly pressed “Save” on. Each one is individually removable. | Until you clear it |
These four are strictly necessary, or explicitly requested by you — a preference you set, a history the tool exists to show you, a save you pressed a button for. Under the ePrivacy rules that category does not require consent, which is why you are not asked about them. They hold no identifier we can read: everything stays in your browser. Clearing site data for myrecon.xyz removes all four at once.
3. Third-party cookies: Google advertising
Parts of this site carry advertising, which is what pays for the free tools and the written archive. Advertising is served by Google (Google AdSense). When an ad is served, Google and its partners may set and read cookies in your browser, and may use web beacons and your IP address to collect information.
These cookies are set by Google under Google’s own policies, not ours. We do not control them, cannot read them, and receive no personal data from them. Typical examples of what Google sets in this context:
| Cookie | Set by | Purpose | Typical duration |
|---|---|---|---|
__gads, __gpi, __eoi | myrecon.xyz, by Google’s script | Ad selection and delivery, frequency capping, and measuring how ads perform. | Up to about 13 months |
IDE, DSID | doubleclick.net | Ad measurement and, where you have consented, personalisation. | Two weeks to about 13 months |
NID | google.com | Google preferences, including ad settings. | About 6 months |
FCCDCF, FCNEC | myrecon.xyz, by Google’s consent message | Records the consent choice you made, so you are not asked again on every page. | Up to about 13 months |
Because Google sets and maintains these, the current list is Google’s — not a copy here that would quietly go stale. See how Google uses cookies in advertising and how Google uses information from sites that use its services.
Nothing you type into the tool is passed to any advertising system. The identifiers you search for — an email address, a username, a domain — reach the public data sources needed to answer the question, and nowhere else.
Ads are placed automatically by Google, which chooses the position on a page. The home page is where the lookup tool runs, so an ad can appear on the same page as your results; it is chosen from that page’s published content, never from what you typed. By contrast, these policy pages, the contact page and Deep Search carry no advertising at all.
4. Other third parties we load
Some parts of the site load files from other companies. These set no advertising cookies, but any request your browser makes to another company discloses your IP address to it, so they belong in an honest cookie policy:
- Google Fonts (
fonts.googleapis.com,fonts.gstatic.com) — the typeface. Google receives your IP address and browser details when the font loads. Google states that it sets no cookies for this. - Have I Been Pwned (
logos.haveibeenpwned.com) — the company logo shown on a breach article. This discloses your IP address to HIBP’s image host. We send these requests with no referrer, so HIBP is not told which breach page you were reading. - Pwned Passwords (
api.pwnedpasswords.com) — contacted only if you run the password checker, and only ever sent the first five characters of a SHA-1 hash, never the password. See the privacy policy for how that works. - Vercel and Render — hosting for the site and the API. They keep standard technical request logs. No cookies.
5. How consent works here
If you are in the European Economic Area, the United Kingdom or Switzerland, Google’s EU user consent policy applies. Advertising cookies are set only after you have made a choice through a Google-certified consent message, shown before personalised ads are served. Refusing locks you out of nothing: the site and every tool on it work exactly the same either way — you simply see non-personalised advertising, or none.
We use Google’s own certified message rather than a banner of our own design, and that is deliberate. Google requires a certified consent platform for ads served in those regions, so a home-made banner would not be a valid basis for the cookies Google sets. It would only be a second prompt standing in front of the real one.
Outside those regions no ad-consent prompt is shown, which is the standard behaviour of the advertising system. You can still refuse or delete these cookies at any time using the controls in the next section, and those controls work everywhere.
Withdrawing is as easy as consenting. Use the cookie control in the footer of every page to reopen the consent message and change your answer.
6. How to manage or refuse cookies
Reopen the consent message
Use the cookie control in the footer of any page. Where a consent message applies to you, this reopens it so you can change your choice. Where none applies, use the controls below — they work regardless of where you are.
Turn off personalised advertising
- Google My Ad Center — turn off personalised ads across Google, including here.
- aboutads.info/choices and youronlinechoices.com — opt out of vendors other than Google.
Block or delete cookies in your browser
Every major browser lets you block third-party cookies outright, delete what is already stored, or clear everything for a single site. Look under privacy settings for “Cookies and site data” in Chrome, Firefox, Safari or Edge. Blocking third-party cookies breaks nothing on this site.
Clear what MyRecon stores
Your recent-lookup history has a Clear history button in the tool, and each saved investigation has its own remove control. Clearing site data for myrecon.xyz in your browser removes all four local storage keys at once.
Global Privacy Control
We do not sell or share personal information, so there is nothing on our side for a Global Privacy Control signal to switch off — what the signal asks for is already how this site works. Your browser sends it to Google as well, independently of us, and Google treats it as an opt-out of sale and sharing under US state privacy laws. To be certain either way, use the advertising controls above as well.
7. Changes and contact
If the cookies used on this site change materially, this page changes with them and the date at the top is updated. Questions about anything here go to aryan@bugsnaps.in.
This policy sits alongside our privacy policy, which covers everything else we do with data, and our terms of use.