Privacy
What this service stores, what it never collects, and what the sites you open can see. Everything below describes how the software actually behaves.
The short version
There are no accounts, so we never ask for a name, an email address or a password. We do keep a record of each session, which includes the address you asked us to open. We run no analytics and load no third-party scripts.
What is stored
- A session cookie. When you first arrive we set
sb_guest_token, a random identifier that lets the service tell your sessions apart from someone else's. It is markedHttpOnlyandSameSite=Lax, it is not readable by scripts, and it carries no expiry date — so your browser discards it when you close it. It is not linked to any identity and is not used for tracking or advertising. - A session record. For each session we store the address you submitted, an internal container identifier, and timestamps for when the session started and ended.
- An activity log recording that a container was created, started and stopped, which also contains the address that was opened.
- Your IP address, briefly. It is held in memory to enforce rate limits and is not written to our database. D9 · to decide: whether the hosting provider keeps access logs, and for how long
How long it is kept
D4 · to decide: the retention period for session records and activity logs
The container itself keeps nothing. It is destroyed when the session ends, and cookies, cache, downloads and history inside it are destroyed with it — no storage from your machine is attached to it, so there is nowhere for any of that to survive.
What we do not do
- No accounts, and no personal details collected.
- No analytics, no tracking pixels, no advertising.
- No third-party scripts of any kind. Fonts are served from this site rather than fetched from Google, so loading a page here does not tell anyone else that you visited.
- We do not sell or share session records.
What the sites you open can see
The page loads inside a container on our infrastructure, not on your machine. The site therefore sees that container's network address rather than yours, and any cookies or storage it sets belong to the container and die with it.
Your keystrokes and clicks are sent to the container so you can use the page. What comes back to you is video of the screen. Anything you type into a site during a session — including a password — is sent to that site exactly as it would be in your own browser, so a session is not protection against a site that is itself untrustworthy.
Sessions are not private from us
We record the address you open, so the operator can see what was requested. We do not record the contents of a session or what you do inside it, but you should not treat a session as anonymous or confidential from the people who run this service.
Your rights
D5 · to decide: which access, correction and deletion rights are offered, and how a request can be authenticated when the only identifier is a cookie the visitor may no longer hold
Who operates this service
D1 · to decide: the operating person or company, and the country it operates from Privacy questions can be sent to D2 · to decide: a contact address for privacy requests
Changes
If this policy changes materially we will update this page and the date below. Last updated D8 · to decide: the effective date of this version