Privacy policy.

Effective 5 September 2026. Applies to ctlogs.dev, api.ctlogs.dev and account.ctlogs.dev, operated by APPS34.

Who is responsible

The data controller is APPS34, SARL, 48 Rue Claude Balbastre, 34070 Montpellier, France (RCS Montpellier 944 081 553). Contact for anything in this policy: [email protected]. The full legal notice is on the about page.

What the service contains

ctlogs.dev indexes the public Certificate Transparency record: certificates that certificate authorities publish to public CT logs. That data (domain names, organization names and other certificate fields) is published by its issuers, is public by design, and is not information about you as a visitor. We do not alter the public logs and cannot remove a certificate from them; if a certificate concerns you, contact the certificate authority that issued it, or write to us and we will explain what we can and cannot do.

Searching the website and using the API

Request logs. Every search and API request is logged with the query, the time, the response status and a truncated hash of your IP address. We use this to operate and secure the service, to enforce rate limits and to understand demand. These logs are kept for 30 days. Your IP address itself is used only transiently, for per-client rate limiting: an anonymous daily request counter keyed by IP expires after 48 hours.

API keys. If you hold an API key, requests made with it are counted against its monthly quota and attributed to the key in the same 30-day request log. Keys are stored only as SHA-256 hashes.

Cookies. ctlogs.dev and api.ctlogs.dev set no cookies.

Visitor statistics. Page views are counted by a self-hosted Plausible Analytics instance (plausible.apps34.com) that APPS34 runs on its own infrastructure: no cookies, no cross-site tracking, aggregate counts only, nothing shared with third-party analytics providers.

The account cabinet (account.ctlogs.dev)

Sign-in. You sign in with GitHub or Google. We receive from the provider your account identifier and your verified e-mail address, and nothing else; we do not receive your password. We store the e-mail address and the provider identifiers to recognise you next time and to link both providers to one account.

Session. A session cookie (strictly necessary, first-party, valid for 30 days and renewed while you use the cabinet) keeps you signed in. Signing out deletes the session.

Keys and usage. The cabinet stores your API key hashes, when each was created, rotated or revoked, when it was last used, and its usage: the month-to-date quota counter and the per-request log described above (30 days).

Deleting your account. Write to [email protected] from the address you signed in with; your keys stop working at once and the account and its data are erased within 30 days.

Correspondence

If you write to [email protected] (for example to request an API key or a plan), we keep the correspondence for as long as needed to handle your request and the resulting relationship, and for the periods required by French commercial law for invoices.

Who else sees data

We use these providers, each of which sees only what its role requires:

  • Hetzner Online GmbH (Germany) hosts our servers; all stored data lives in the EU.
  • Cloudflare serves the sites and terminates TLS; it sees standard request metadata including your IP address.
  • Google Fonts serves the web fonts; your browser requests them directly from Google.
  • GitHub and Google act as sign-in providers for the account cabinet; their own policies apply to your account with them.

We do not sell data, do not run advertising, and do not share personal data with anyone else unless the law requires it.

Legal basis and your rights

We process request logs and rate-limiting data on the basis of our legitimate interest in operating, securing and improving the service; account and API-key data on the basis of the contract you enter by creating an account or requesting a key; and correspondence on the basis of our legitimate interest in answering you and of our legal obligations.

Under the GDPR you may ask for access to, rectification or erasure of your personal data, ask us to restrict or object to its processing, and receive a copy in a portable format. Write to [email protected]; we answer within one month. You may also lodge a complaint with the French supervisory authority, the CNIL (cnil.fr).

Changes

We will update this page when the service changes. The effective date at the top tells you which version you are reading.