Skip to main content

Privacy

This page describes the browser-based buffer.lol toolbox. IP Lens has a separate, direct-provider architecture described in IP Lens privacy and data flow. buffer.lol includes two kinds of tools: browser-local utilities and server-side diagnostics. The privacy model depends on which kind of tool you open.

Browser-local tools

Developer utilities such as JSON Formatter, Base64, Hash Generator, UUID Generator, Timestamp Converter, URL Parser, JWT Decoder, Regex Tester, CIDR Calculator, and User Agent Parser run in your browser. Their input is processed by client-side JavaScript and is not sent to the diagnostics API. The tool launcher keeps up to five recently opened tool slugs in browser local storage to populate quick access. It does not store diagnostic targets or launcher search text there.

Server-side diagnostics

Network and IP checks use POST /api/tools/[slug] when they need the buffer.lol server to resolve DNS, make an HTTP request, open a TCP connection, read a TLS certificate, or query RDAP and ASN data. The API receives the target and supported options you submit, normal request metadata, and the headers required to serve the response. RDAP results are requested from rdap.org, and ASN results are requested from Team Cymru’s DNS ASN service. DNS Resolver Comparison sends the requested domain and record type to Cloudflare, Google, Quad9, and OpenDNS from the buffer.lol server. DNS, resolver comparison, RDAP, and ASN responses may be cached briefly to reduce repeated provider calls. Browser Latency Test and Connection Stability Test send repeated same-origin HTTPS requests to buffer.lol. Traceroute sends the submitted public destination to a restricted diagnostics worker.

Target validation

Server-side diagnostics reject private, local, reserved, and multicast addresses before making outbound requests. HTTP requests are pinned to the address that passed validation to prevent a later DNS resolution from switching to a blocked destination. URL checks only support HTTP and HTTPS, and URLs with embedded credentials are not allowed.

Result storage

The app displays results in the current browser session. API responses include a requestId for troubleshooting, but diagnostic payloads are not designed as file storage or a long-term result archive. Successful result panels do not display request IDs by default. Rate limiting uses a hashed client-and-target key. If Upstash Redis is configured, the limit is shared across app instances; otherwise, it is enforced in memory per instance. In production, proxy IP headers are ignored unless the deployment explicitly trusts its platform or reverse proxy; when enabled, cf-connecting-ip wins over x-real-ip, which wins over x-forwarded-for.

Analytics and hosting metadata

buffer.lol does not run product analytics or third-party tracking. The hosting platform may process basic request metadata such as request time, IP address, user agent, and abuse-prevention signals as needed to deliver and protect the service.

What not to infer

Server-side checks describe what buffer.lol can see from its runtime. Your local network, VPN, resolver, firewall, or regional routing can produce a different result from the same target.