Privacy Policy
Robots.txt Lab keeps a long-term first-party analytics history of page use, tool events, sources, devices, and separately classified crawler traffic. It does not store raw IP addresses, submitted domains, generated robots.txt text, or form secrets in the analytics tables.
Last updated: July 17, 2026
Scope of this policy
This Privacy Policy explains how Robots.txt Lab handles information when you browse the public site, use the robots.txt generator or checker, change privacy preferences, or contact us.
Information processed by the checker
When you submit a domain, Robots.txt Lab normalizes the host and requests its public /robots.txt file. The checker processes the returned status, rules, sitemaps, and analysis required to display the result.
A technical log may store the submitted domain, HTTP status code, a summary of the analysis, and a one-way hash derived from the requesting IP address and the application key. The hash supports diagnostics and abuse prevention without intentionally storing the raw IP address in the checker log. Domain names and summary results may still constitute operational or personal data in some circumstances.
Generator input
The generator processes the website URL, crawler choices, paths, sitemap setting, and other options you submit in order to produce robots.txt text. Do not enter passwords, API keys, private URLs, personal data, or confidential configuration into public tools.
Server logs and security data
The hosting platform and web server may process standard request information such as IP address, date and time, requested URL, referrer, browser or User-Agent string, response status, and security events. This information is used to deliver the site, troubleshoot failures, maintain availability, prevent abuse, and protect the service.
First-party site analytics
Robots.txt Lab operates a first-party analytics system to understand whether public pages and tools are being used. It can record the requested path, time, referrer domain, campaign parameters, device and browser category, crawler classification, and events such as generating, checking, copying, or downloading robots.txt content. Submitted domains, generated robots.txt text, form secrets, and raw IP addresses are not stored in this analytics system.
When analytics permission is available, a random first-party visitor identifier and a short-lived session identifier may be used to measure sessions, returning visits, and journeys between pages. Without analytics permission, the system can use short-lived one-way identifiers derived from request data to produce limited aggregate counts without storing the underlying IP address. Known crawlers and automated requests are reported separately from human traffic.
Analytics records are retained as a long-term historical record so the site operator can compare months and years. Access is restricted to the private administration area. You may reject optional analytics or withdraw permission through the privacy center; browser Do Not Track is honored by preventing persistent analytics identifiers.
Approximate location analytics
For human visits included in first-party analytics, Robots.txt Lab may derive an approximate country, region, and city from the visitor’s public IP address. The raw IP address is used only transiently for the lookup and is not written to the analytics tables or geolocation cache. Results are approximate and may be affected by mobile networks, corporate gateways, proxies, or VPN services.
The current lookup provider is FreeIPAPI. The server sends the public IP address to that provider over HTTPS, then stores only the returned approximate location together with a one-way IP hash used to avoid repeating the same lookup unnecessarily. Failed and successful lookups are cached for limited technical periods, while the resulting location attached to analytics sessions and events remains part of the long-term historical analytics record.
Cookies, analytics, and advertising
Robots.txt Lab uses essential storage for sessions, security, form protection, administrator authentication, and privacy preferences. Google Analytics and advertising technologies remain optional and are denied by default unless configured and permitted. The first-party analytics described above is operated directly by Robots.txt Lab and does not send its records to an advertising provider.
The Cookie Policy describes the active storage categories, typical purposes, and available privacy choices. You can reopen the privacy center from the footer at any time.
Contact messages
If you contact us, your message may include your email address, name, message content, attachments, and technical context you choose to provide. This information is used to review and respond to the request, maintain necessary records, prevent abuse, and protect legal rights.
Retention and deletion
Checker logs and related technical records are retained only for as long as reasonably necessary for diagnostics, security, abuse prevention, and service operation. Older records may be deleted through the administration tools. Contact records, security logs, and hosting backups may follow different retention periods based on operational need and applicable requirements.
Sharing and service providers
Information may be processed by hosting, infrastructure, security, email, analytics, advertising, or other providers used to operate Robots.txt Lab. Information may also be disclosed when reasonably necessary to comply with applicable law, protect rights or security, investigate misuse, or complete a legitimate transfer of the service.
Your choices and rights
You can avoid submitting a domain to the checker, reject optional cookies, withdraw a previous choice, or use Global Privacy Control where supported. Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, or a copy of certain personal data, and to complain to an appropriate supervisory authority.
Send privacy requests to contact@robotstxtlab.net. Include only the information reasonably necessary to identify the request and locate the relevant record.
Children and policy changes
Robots.txt Lab is a technical resource and is not directed specifically to children. This policy may be updated when the service, providers, privacy controls, or legal requirements change. The date at the top identifies the current published version.
Live privacy controls
A permanent privacy center is available in the footer. Optional analytics and advertising are denied by default, can be accepted or rejected separately, and can be withdrawn later without losing access to public content.
Robots.txt Lab also honors Global Privacy Control for advertising-related sale, sharing, and cross-context behavioral advertising. The first-party preference cookie stores the policy version, selected categories, and time of the choice; it does not contain your name, email address, or an advertising identifier.
Live privacy controls
The site provides a permanent privacy center in the footer. Optional analytics and advertising are denied by default, can be accepted or rejected separately, and can be withdrawn later without losing access to public content.
The site also honors Global Privacy Control for advertising-related sale, sharing, and cross-context behavioral advertising. The preference cookie stores the policy version, selected categories, and time of the choice; it does not contain a name, email address, or advertising identifier.
FAQ
What does the robots.txt checker store?
It may store the submitted domain, response status, a summary of the analysis, and a one-way hash derived from the requester’s IP address and the application key.
Does the checker publish the robots.txt content it fetches?
The fetched file is processed to display the requested analysis. The application’s checker log stores summary data rather than publishing the full third-party file as site content.
Are analytics and advertising always active?
The first-party Robots.txt Lab analytics system can collect privacy-preserving usage records when enabled, while persistent visitor identifiers require analytics permission. Google Analytics and advertising remain optional integrations and are not loaded unless configured and permitted.
How long are checker logs retained?
The current application allows the operator to purge older records manually but does not enforce a fixed automatic public retention period.
How can I make a privacy request?
Use the active contact method published by the site operator, identify the request, and provide only the information reasonably necessary to locate and verify the relevant record.