Scan yourself. We won’t see the results.
Every site you open reads a surprising amount about your device before you click anything. This hybrid scan combines the three checks that usually live on separate pages — DNS leak, WebRTC leak and browser fingerprint — and shows you exactly what a tracking company would get, including the things our own product cannot fix.
Nothing you see below is uploaded, stored or logged. The fingerprint and signal probes make no network requests at all; the two leak probes (DNS and WebRTC) are the only ones that touch the network, and they carry nothing but random tokens — never your results. Open your browser’s developer tools and watch the Network tab; that’s rather the point of this page.
—
—
The exposure score is an indicative summary of the signals found on this page, not a scientific measurement of how identifiable you are. Real uniqueness depends on how rare your particular combination is across the whole population of browsers, which no single site can determine on its own.
Fingerprinting is the tracking that survives everything
Most people picture tracking as cookies, and picture the solution as deleting them. That model is about a decade out of date. The dominant technique now identifies you by how your device is configured rather than by anything stored on it, which means there is nothing to delete.
The scan above shows the raw material: your timezone, language, screen geometry, graphics hardware, available fonts, processor count and a dozen smaller details. Individually none of them identifies anybody — plenty of people have a 1920×1080 screen. Combined, they form a pattern that is frequently unique, and crucially it is stable. Clearing cookies does not change it. Private browsing does not change it. Connecting through a VPN does not change it, because none of it travels over the network in a way a tunnel could hide; it is read directly by the page you are visiting.
Canvas and WebGL: the sharpest signals
Two of the checks deserve special mention because they are unusually revealing. A canvas fingerprint asks your browser to draw an invisible image and then hashes the result. Because rendering depends on your graphics driver, fonts and operating system, the same instruction produces subtly different pixels on different machines, and that difference is remarkably consistent on yours. WebGL goes further and can often report your actual graphics card model, which narrows the field considerably.
Neither exists to track you — they are legitimate graphics features that tracking simply repurposed. That is the awkward pattern across this whole area: the most effective identifiers are side effects of useful things.
Why we are showing you what we cannot fix
We sell a VPN, and a VPN does nothing about most of what the scan finds. We could have built a tool that only tested the things our product solves, presented you with an alarming red result, and sold you the fix. Plenty of sites do exactly that.
It seemed more useful to show the whole picture, including the large part of it where the answer is “change your browser, not your VPN”. A tool that exaggerates the problem it happens to solve is advertising wearing a lab coat, and you can generally tell.
What actually fixes what
Privacy is layered, and each layer has one job. Here is which tool addresses which exposure — including the rows where the answer is not us.
| Exposure | Fixed by | How |
|---|---|---|
| Your IP address | A VPN | Hidden by connecting through a VPN server — the site sees the server, not you. |
| Your ISP seeing your browsing | A VPN | Encrypted between you and the VPN server, so the network sees a tunnel rather than destinations. |
| Browser fingerprint | Your browser | A VPN cannot help. Use a browser that resists fingerprinting, and avoid exotic configurations. |
| Canvas & WebGL signatures | Your browser | Blocked or randomised by fingerprint-resistant browsers and some extensions. |
| Cookies & cross-site tracking | Your browser | Third-party cookie blocking and separate profiles or containers do the work here. |
| Accounts you log into | Nothing, technically | If you sign in, you are identified. Compartmentalise instead: separate accounts, separate profiles. |
| Timezone & language mismatch | Your browser | A VPN changes your apparent country but not your clock, which is why the two can disagree. |
| Payment identity | Private payment | Cards identify the buyer regardless of connection privacy. Monero does not. |
Three of these eight rows are solved by a VPN, and we would rather tell you that than imply otherwise. If you want to work out which layers matter for your situation specifically, the threat model assessment is a better starting point than any product page.
Privacy check questions
Does this privacy check send my data anywhere?
What does the hybrid scan combine?
What is browser fingerprinting?
Does a VPN stop fingerprinting?
What is a WebRTC leak?
Why does my timezone matter?
What is Do Not Track, and why is it usually useless?
My score is bad. What should I fix first?
Is a perfect score even possible?
We can fix the network half. Honestly, that’s the half we do.
No email at signup, no logs to search, and an independently audited claim behind it.