BullSniffBack home

Privacy without the bull.

BullSniff researches the site you choose, when you choose it. The Chrome extension keeps page-content analysis on your device. The optional free web scanner processes a bounded set of public pages on BullSniff’s server.

Free web scanner

When you submit a URL on bullsniff.com, BullSniff receives that URL and requests up to eight useful public pages from the same website. It processes their public text, links, images, publication dates and basic form/security signals in memory to create your report. It does not use site accounts, bypass access controls or crawl private pages.

The submitted URL, fetched page content and generated report are not written to a BullSniff database. Hosting infrastructure may temporarily process ordinary request metadata, including IP address, timestamp and user agent, for security and reliability. The affected website will receive ordinary automated requests identifying BullSniff.

Data processed on your device

After you click Sniff this site, BullSniff reads the active page and follows same-site public links. It processes URLs, titles, page text, links, images, structured publication dates and basic form/security signals from up to 16 pages. Chrome treats website content and visited page URLs as user data, even when processing stays on your device.

The crawler ignores account, sign-in, sign-out, profile and administrative routes. It fetches public pages without your site credentials and prioritises company, contact, policy, review, product, pricing, testing, certification and payment-information pages.

Data sent for public-record checks

The extension sends BullSniff only the scanned site’s hostname and up to 11 domain names that the site presents as customers, portfolio work, testing, reviews, forums or verification evidence. It does not send page paths, page text, titles, images, form contents, passwords or your wider browsing history.

BullSniff uses those domain names to query the official registration-data service discovered through IANA’s RDAP registry, public DNS through Cloudflare DNS over HTTPS, and bounded public robots.txt, XML sitemap, home, about, company and case-study pages on the scanned or cited domains. Those providers receive the domain being queried. The affected sites receive ordinary requests for those public pages.

How it is used

The extension combines same-site evidence with public registration dates, nameservers, robots rules, sitemap dates and names explicitly published on company pages only to generate the warning-sign report you requested. It can flag chronology conflicts, large template-page footprints, internally sourced case studies, or named people recurring across supposedly separate portfolio and customer sites.

These signals do not prove fraud, ownership, a personal relationship or coordination. BullSniff does not use scan data for advertising, profiling, credit decisions or any purpose unrelated to this single function.

Reports and retention

The BullSniff application processes web-scan and domain-check requests in memory and does not write their payloads or results to a BullSniff database. The extension stores no scan history.

Reports are encoded in the URL fragment after the #. Browsers do not send that fragment to the website, and the report is decoded locally in your browser. Anyone you intentionally share that complete link with can read the embedded report.

Permissions

  • activeTab grants temporary access only to the site where you invoke BullSniff, including its same-origin public pages during that scan.
  • scripting lets BullSniff run its analyser and bounded crawler in that tab after your click.
  • https://bullsniff.com/* lets the extension call BullSniff’s domain-verification endpoint. It does not grant BullSniff access to every site you visit.

The extension does not request persistent access to all sites, background browsing, storage, identity, location or payment data.

Website analytics

bullsniff.com uses Plausible Analytics to measure aggregate visits, Chrome Web Store clicks and privacy-safe scan outcomes without cookies or cross-site tracking. Failed scans are grouped by broad reason—such as an invalid address, a blocked site, a timeout or a temporary service error. BullSniff does not send the submitted domain or page content to Plausible. This is separate from the extension’s local page analysis. See Plausible’s data policy.

Sharing

BullSniff does not sell user data. Domain names are transferred only to the public-record providers described above and requested directly from the affected public sites to perform the check. A report remains available only where you intentionally keep or share its link.

Chrome Web Store Limited Use

BullSniff’s use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Website data is used only to provide the user-requested warning-sign report and the necessary security and reliability of that feature.

Contact

Questions or deletion requests can be sent to hello@bullsniff.com. Because BullSniff does not maintain accounts or a scan database, there is normally no scan record for us to delete.

Effective 2 September 2026. Material changes will be posted here.