Privacy Policy
Last updated: September 2026
The short version
436.io is an independent personal project, not a company. There are no accounts, no login and no database. Nothing about a scan you run is stored on our server once your browser has the result. The only things that touch our server at all are: the pages/sitemap you ask us to look up, your IP address (briefly, to enforce fair-use limits), and, if you use the contact form, whatever you type into it.
Running a scan
When you scan a website, your browser sends us the website address (or an uploaded sitemap file) and the list of check categories and device types you picked. Our server uses that to look up the site’s sitemap, then calls Google’s PageSpeed Insights API once per page/category combination, using a single API key we hold - you never need one of your own. The results are sent straight back to your browser and are not written to a database or log file. If you close the tab, the report is gone; running the same scan again calls PageSpeed Insights fresh.
The pages you ask us to check are, by definition, sent to Google as part of that API call - see Google APIs Terms of Service for how Google handles that. 436.io itself does not use scan data for anything beyond generating the report shown to you.
Your IP address and rate limiting
Because the PageSpeed Insights key is shared across every visitor, we keep a short-lived counter per IP address (via a managed Redis-backed store) to stop any one visitor from using more than a fair share of it. These counters exist only to enforce that fair-use limit, expire automatically within hours, are never linked to any other data and are never used to identify you.
What’s stored in your browser
The only thing 436.io saves client-side is a light/dark theme preference, in your browser’s localStorage. It never leaves your browser and we have no way of reading it. 436.io doesn’t set cookies and doesn’t run any analytics, advertising or tracking scripts of any kind.
The contact form
If you send a message through the contact page, the name (optional), email address and message you provide are sent, using Resend (an email-delivery service), to the inbox we use to answer messages. That message is kept only for as long as it takes to read and respond to it, in that ordinary email inbox - it doesn’t get written into any 436.io database, because there isn’t one. You can ask us to delete a message you sent at any time using the same contact form.
Hosting
436.io runs on Vercel, which, like essentially any web host, keeps its own standard infrastructure-level request logs (for reliability and abuse prevention) independent of anything described above. 436.io doesn’t control or access those logs beyond what Vercel’s own tools surface.
Fonts
436.io’s typefaces are bundled with the site at build time (via Next.js’s font optimization) rather than loaded from Google Fonts’ servers each time you visit, so no font-related request is made to Google as you browse.
Children
436.io isn’t directed at children and we don’t knowingly collect information from anyone under 13.
Changes to this policy
If what 436.io collects or how it’s handled changes, this page will be updated and the date at the top will change. There’s no mailing list to notify, since we don’t collect emails except when you send us one.
Questions
For anything about this policy, including asking what (little) data we might have and requesting it be deleted, use the contact page.

