Privacy Policy
This notice covers the public checker and the optional panel. The public checker needs no account and sets no cookies; the panel does, as described below.
Who is responsible for this website
Cyber Deans Ltd, trading as Typosquatting.ai, is the data controller for the processing described in this notice. It is registered in England and Wales under company number 12784136, with its registered office at Flat 201, Jerome House, 14 Lisson Grove, London NW1 6TS, United Kingdom. Questions and rights requests go through the contact page.
Information used for a public check
When you enter a domain, the service processes the normalized domain and the variations it generates. Do not submit passwords, private URLs, or confidential information. The domain you check appears in the page address, so it may be present in your browser history and in hosting request logs.
Public data providers
To run a check, generated candidate names are resolved by our discovery engine through Cloudflare’s public DNS resolver, searched for in certificate-transparency logs at crt.sh, and, for the highest-priority findings, looked up in the relevant registry’s RDAP service identified through IANA’s bootstrap file and in urlscan.io’s public search API. Requests are made from our servers, so those providers see our address rather than yours, and they process the domain names under their own policies. The checker never submits new website scans to urlscan.io, and it does not load a suspect site to read what is on it. Names on public hosting platforms receive one request from our servers to confirm somebody claimed them, because those platforms answer DNS for every possible subdomain.
Where a candidate name resolves, the address alone is sent to a geolocation provider, ipwho.is, with ip-api.com used as a fallback when it does not answer, to record the country the address is announced from and the network that operates it. Only the IP address is sent, not the domain name and nothing about you, and it is a lookup on an address rather than a connection to the site. Treat the country as an estimate: providers disagree, and an address announced from many places at once has no single location.
Storage and retention for public checks
A public check runs as a background job. The job record (the domain, timestamps and progress) and the finished report are stored in our database for up to 24 hours so that the results page can show them and anyone checking the same domain in that time is served the same report; a scheduled sweep then deletes them. Neither record contains your address or any account information. Individual record lookups are cached in server memory for up to 15 minutes, and the rate limiter keeps a request count per client address for one minute.
The optional account panel
If you create a panel account we store your email address, your watchlist, the reports you run (the 40 most recent), a ledger of the lookalike findings under each domain with the review status you assign them and when each was first and last seen, a short log of your own actions in the panel (up to 60 entries, without IP addresses), and a hashed copy of any API key you create. These records are kept in a database on our hosting provider’s infrastructure until you delete the account from Settings, which removes them immediately. Sign-in links expire after 15 minutes and sessions after 30 days. We rely on performance of a contract, providing the panel you asked for, as the lawful basis for this processing.
A direct lookup from the panel also sends the domain name you looked up to urlscans.com, a threat-intelligence service that is separate from the urlscan.io search described above and operated by a different company, which returns a verdict with its own categories and reasons. The request is made from our servers, so that provider sees our address rather than yours, and it processes the domain name under its own policy. Public checks never use it, and neither service is ever asked to open or scan the site.
In the panel, the small icon beside each lookalike and the picture of its home page in the Screenshot column are fetched by our own screenshot service on Cloudflare’s network, never by your browser, and each is kept for a day. They help you recognise a page; they are not evidence and do not change a risk rating.
Takedown requests
On the Pro, Business and Enterprise plans you can ask our team to report a lookalike domain to its registrar or hosting network. When you do, we store the request: the lookalike name, the watched domain it resembles, the public records about the lookalike that your report already held, what you wrote about it, who on your account asked, each notice our team sent, and each step recorded after that. Our team reads it, and the report is sent to the registrar, the hosting network or another party that operates the name’s infrastructure, who process it under their own abuse policies. The reported site is never loaded to read what is on it.
When our team sends the report from the panel, the recipient’s replies to our takedown address are filed on the request for our team to read. You are told when the recipient’s first verified reply is recorded; the replies themselves stay with our team. If the recipient does not answer, or acknowledges the report and then goes quiet, the panel sends them up to three short reminders that quote the request’s reference and, from a fresh DNS lookup, whether the name still resolves.
Replies filed on a request are normally also read, within a daily allowance, by a language model on Cloudflare Workers AI, run by Cloudflare, Inc., our hosting provider, which sorts each one and drafts an answer for our team. The model is given the request, the replies filed on it and a fresh DNS answer for the name, and nothing else from your account. A person reads, edits and sends every answer; the model sends nothing.
Requests are kept with the account and deleted with it. A report already sent to a registrar or host cannot be recalled. We rely on performance of a contract as the lawful basis.
Cookies
The public site sets no cookies and loads no third-party scripts, fonts, or analytics. Signing in to the panel sets one strictly necessary cookie, ts_session, which identifies your session for up to 30 days and is not used for tracking or advertising. A content security policy restricts the browser to loading resources from this site only.
Email delivery
Sign-in links, alert emails on plans that include them, and emails about a takedown request are sent through Cloudflare Email Sending, run by Cloudflare, Inc., a United States company that also hosts this service. Cloudflare processes your email address on our behalf for that purpose only, and no other email provider is used. If you never create a panel account, no email is sent.
Billing
Paid plans are billed by Stripe, Inc. Stripe collects and stores your payment details under its own privacy policy; we never see your card number. We store the Stripe customer and subscription identifiers, the plan, its status and renewal date, so that your account is entitled to what you paid for. Invoices and payment methods are managed through Stripe’s billing portal from Settings.
Hosting and logs
Hosting infrastructure may keep access and security logs (client address, requested address, user agent, and timestamp) for operational and abuse-prevention purposes under the provider’s retention settings.
Your rights
Under UK data-protection law you can ask what personal data we hold about you and request its correction or deletion. Panel users can export everything or delete the account from Settings at any time. For anything else, use the contact page. You also have the right to complain to the Information Commissioner’s Office.
Changes to this notice
The last-updated date is shown at the top of this page. Adding alerts, contact forms, or analytics would require an update to this notice before those features go live.