BUILT FOR DEFENDERS

Cookie Finder Tool - CFT

Privacy Policy

Privacy Policy

Effective date: 11 September 2026  ·  Operated by Antibody Cyber / WinCyberScan

1. Overview

Cookie Finder Tool (CFT) at cookieft.com is a cookie security scanning service built for defenders. This policy explains what data is processed when you scan, create an account, or purchase a subscription.

2. Account and Billing Data

When you create an account, CFT stores your email address, a one-way password hash, subscription status, and monthly scan-usage totals. Passwords are not stored in plaintext. Stripe processes payments and stores payment-method details; CFT stores only Stripe customer and subscription identifiers and does not receive complete card numbers.

CFT does not:

  • Run analytics scripts, tracking pixels, or third-party SDKs
  • Log, store, or retain the URLs you submit for scanning
  • Log, store, or transmit cookie values — values are always redacted before any processing
  • Share any data with third parties for advertising or profiling

3. Scan Processing

When you submit a URL for a Remote URL Scan, the following occurs server-side:

  • CFT's server makes an HTTP GET request to the URL you provided
  • The Set-Cookie response headers are extracted and analysed
  • Cookie values are immediately redacted — they are never stored or returned to you
  • The classified results are returned to your browser and discarded from the server
  • No scan target URL, result, or IP address is written to persistent storage

Standard web server access logs (nginx) may record the source IP and request timestamp as part of normal server operation. These logs are retained for up to 14 days for security and abuse monitoring, then deleted.

4. Cookies and Local Storage

When you sign in, CFT sets one strictly necessary cft_session cookie. It is Secure, HttpOnly, SameSite=Strict, and expires after 30 days or when you sign out. It authenticates your account and is not used for advertising or analytics. CFT does not write account data to localStorage, sessionStorage, or IndexedDB.

5. Third-Party Services

CFT uses Google reCAPTCHA to protect scan endpoints from abuse and Stripe to provide hosted Checkout and subscription management. Their processing is governed by their respective privacy policies. CFT does not use Google Analytics, Facebook Pixel, or similar advertising and profiling services.

6. Infrastructure

CFT runs on a dedicated server hosted on Amazon Web Services (AWS) in the US-East-1 region. AWS acts as a data processor under a standard Data Processing Agreement. No scan data is forwarded to AWS services beyond the compute instance itself.

7. Children's Privacy

CFT is a professional security tool intended for adults. We do not knowingly process data from children under the age of 13.

8. Changes to This Policy

If this policy changes materially, the effective date above will be updated. Continued use of CFT after any update constitutes acceptance of the revised policy.

9. Contact and Deletion

Questions, access requests, and account-deletion requests can be directed to Antibody Cyber via the contact details on that site. Billing records may be retained where required for tax, fraud-prevention, or other legal obligations.