legal & privacy.
Everything we're obliged to tell you — written in plain language. We're three devs, not a law firm. If anything is unclear, email us.
tl;dr.
zero cookies. no personal data sold, shared, or profiled. analytics are self-hosted, cookieless and anonymous. server logs exist for abuse prevention. we're three devs building tools.
The rest of this page is legally required. The summary above accurately describes what we actually do.
mentions légales.
Per French law (LCEN art. 6-III-1), the following identifies the editor and host of this site.
publisher.
- entity
- CorpLoc — informal collective
- form
- no legal entity · unregistered · non-commercial
- location
- France
- contact
- contact@corploc.net
- publication dir.
- the three members of the collective
host.
- primary host
- Contabo GmbH · Munich, Germany
- cdn / edge
- none — served from origin
- dns
- Cloudflare, Inc.
- infrastructure
- self-managed · see colophon
terms & cgu.
scope.
These terms govern your use of corploc.net and any tool published by the CorpLoc collective. They do not govern the source code, which is licensed separately.
open-source licenses.
- Applications: AGPLv3 — share-alike, copyleft, no proprietary forks.
- Libraries and utilities: MIT — permissive, attribution required.
- License files are in each repository. If in doubt, check the repo.
no warranty.
- These tools are provided as-is, without warranty of any kind.
- We are not a registered company — there is no commercial SLA, no uptime guarantee, no dedicated support.
- We fix things when we can, because we care about the work — not because of a contract.
no accounts, no payment.
- No accounts on this site. No registration. No login.
- No payment processing of any kind. Everything we publish is free.
- If a tool we build eventually requires an account, it will have its own dedicated terms.
privacy policy.
two things exist: reverse-proxy access logs (security) and self-hosted anonymous analytics (umami — cookieless, no stored IP). no third-party trackers. no profiling. no data leaves our servers.
The long version is below because we are legally required to write it.
data controller.
CorpLoc collective, identified in section 01, acts as the data controller for all personal data described in this policy. Contact: contact@corploc.net.
legal basis · article 6 RGPD.
- legitimate interest (art. 6.1.f) — reverse-proxy access logs, including IP addresses, for abuse prevention and automated intrusion detection. Retained only as long as necessary for security operations.
- legitimate interest (art. 6.1.f) — audience measurement via self-hosted Umami: cookieless, no IP stored, aggregated stats only. Exempt from consent under CNIL audience-measurement guidelines.
- no consent-based tracking — we do not rely on consent for anything, because nothing we run requires it. No profiling, no A/B testing, no ads.
- No contractual basis, no billing, no accounts — so art. 6.1.b and 6.1.c do not apply here.
what we collect.
Complete inventory. If it's not on this list, we are not collecting it.
we do store (minimal).
we do not store.
third-party requests your browser makes.
Full transparency: these requests leave our infrastructure. Your IP is visible to the destination, like any web request.
api.github.com— tool pages fetch stars and versions client-side. Cached 1h in your browser. GitHub's privacy policy applies to that request.- Fonts are self-hosted — no Google Fonts, no font CDN, no third-party request for typography.
- The analytics script loads from our own server — not a third party.
your rights.
Under the RGPD / GDPR you have the following rights at any time. We reply to all requests within 7 days. Contact: contact@corploc.net — no account required.
Since we collect almost nothing, most of these rights are vacuous in practice. But they apply and we will honor them. If we fail to reply within 30 days, file directly with the CNIL.
cookies & tracking.
zero cookies. not one. preferences live in localStorage and never leave your browser. nothing to accept or refuse.
cookies set by this site.
what we don't set.
- No third-party cookies. Ever.
- No analytics cookies — our self-hosted Umami is cookieless by design. No
_ga, no_fbp, nothing. - No A/B testing or preference cookies of any kind.
localStoragedata is never transmitted, never read server-side, and cleared with your browser data.
No cookie banner is displayed because there is nothing that requires consent under RGPD or the ePrivacy directive.
security.
We build and maintain our own infrastructure. If you find a vulnerability, we want to know.
responsible disclosure.
No bug bounty — we can't afford to pay competitively. But we run a responsible-disclosure program and take reports seriously.
- Email:
contact@corploc.netwith subject[security] - We acknowledge receipt within 24h.
- We triage within 7 days.
- We fix reported issues within 72h for critical issues, 30 days for others.
- Public credit in changelog, unless you prefer to remain anonymous.
Please give us reasonable time to patch before disclosing publicly. We'll do the same — no gagging, no legal threats.
contact.
One address handles everything. We're a small collective — no ticket system, no support tiers, no bot.
Response time: 7 days for legal requests · 72h for security reports · best-effort for everything else.