WEBDEFENSELAB
WEBDEFENSELAB

Privacy Policy

How we use website data

This page describes the data behaviour built into WebDefenseLab. Last prepared: September 25, 2026. You can send questions and corrections through the contact page.

Reading and searching

You can read articles without creating an account. Search is handled by this site and the query appears in the URL. Do not include passwords or other sensitive information in a search. Hosting and network providers may process routine request information, such as IP address, requested URL, time, and user agent, in operational logs.

Crawler activity logs

Requests whose User-Agent identifies a crawler may be recorded in a private operational log. Records include UTC time, the requested path without its query string, HTTP method and response status, IP address, User-Agent, and PHP processing time. Ordinary browser requests without a crawler identifier are not included in this dedicated log. Crawler identity is inferred from the header and is not independently verified.

The log does not store form contents, cookies, authorization headers or referrers. The default storage limit is one 5 MiB active file and five rotated files; older files are replaced as this limit is reached. The publisher can adjust these settings. Access to the browser viewer requires a private key.

Microsoft Clarity analytics

When the publisher configures a Microsoft Clarity project ID, the tracking script loads automatically on page visits. We use Clarity to understand traffic, page usage, clicks, scrolling, and browsing behaviour through analytics, heatmaps, and session recordings. No Clarity script loads while the project ID is empty.

Clarity may process usage information, device and browser details, and interaction data according to the project settings and Microsoft’s data handling. The publisher controls masking and analytics settings in Clarity. This website does not display an analytics consent banner or store a local consent preference.

Local media

Article images, diagrams, and the explainer video are hosted with the site. Playing the local video does not require loading a third-party video player.

Outbound and social links

Provider and social links take you to other services with their own policies. A referral URL may contain an affiliate identifier. The built-in link handler does not create a separate visitor tracking database, although ordinary server logs may record a request. Social share links do not load a social tracking widget on this page.

Contact messages

When you submit the contact form, we store your name, email address, selected topic, message, submission time, and a reference number to handle your enquiry. Messages are stored privately on the hosting server and are not published on this website. Please do not include passwords, recovery codes, or payment details.

The form uses a temporary session cookie to protect submissions and show their status. An automatically expiring, keyed hash of your network address limits repeated submissions; the message file does not include your IP address. Contact fields are marked for masking in Microsoft Clarity. The publisher manages access to messages and removes them when they are no longer needed.

Data requests and operational retention

The site has no reader accounts or subscription form in this edition. Operational log retention and any additional processing are controlled by the publisher and hosting configuration. Use the contact form for questions about those records. Do not send passwords, account recovery codes, or identity documents with an initial request.

Read Microsoft’s privacy statement for its processing information.