Privacy policy
Applies to the ClickScout website (clickscout.zephyrcreativetechnologies.com) and the ClickScout Chrome extension, both made by Zephyr Creative Technologies. Last updated 24 September 2026.
The short version
ClickScout has no accounts, no analytics, no ads and no servers of its own. Every check runs in your browser. We never see what you paste or hover, and we never sell or share data, because we don't collect any.
What leaves your browser
- Domain names only. To show who owns a domain and how old it is, ClickScout sends the domain name (for example
example.com, never the full link, email address or page content) to the public RDAP servicerdap.org, which may forward it to the registry and registrar responsible for that domain. - DNS lookups. The domain name is looked up via public DNS-over-HTTPS resolvers (Google
dns.google, falling back to Cloudflarecloudflare-dns.com) to find mail servers, SPF/DMARC records and where a link points. - Threat lists. ClickScout downloads open-source blocklists (Phishing.Database and disposable-email-domains) from GitHub and checks against them locally. Nothing about what you check is sent to GitHub.
These services receive the request like any website visit (including your IP address) and are governed by their own privacy policies. The extension's toolbar badge does not contact any of them. It checks pages offline against the locally cached lists.
What the extension reads
To show hover cards, the extension reads the link address, link text or email address under your mouse pointer, only when you hover or right-click. It does not read, store or transmit page content, form data, passwords or browsing history.
What is stored, and where
- Your settings (hover cards, Alt-only mode, badge) in Chrome's extension storage, synced by Chrome if you use Chrome sync.
- A cached copy of the threat lists and recent results, kept locally so checks are fast.
- Your last 12 checks ("Recent scouts") and theme choice in your browser's local storage. Clear them anytime with the Clear button or by removing the extension.
Links you choose to open
Buttons such as VirusTotal, urlscan, URLhaus, MXToolbox, AbuseIPDB and crt.sh open those third-party sites in a new tab with the domain or link filled in. That only happens when you click them.
Contact
Questions or concerns: email benett@zephyrwebservices.com.