legal / privacy
Privacy Policy
WhatPortIs is a public reference database. You can read every page on it without an account, and we would rather hold as little about you as the site can function on. This page says exactly what that is.
- last updated
- 6 October 2026
- accounts required
- none
- data sold
- none
00 / scope
What This Covers
This policy covers whatportis.com — the pages, the search, the contribute and suggest-an-edit forms, and the public JSON API. We are the controller of the personal data described here.
There are no public user accounts. Browsing and searching need no login, and the site does not ask you to identify yourself. The one login on the site is for the maintainers who review corrections; everything about it is described below in its own right rather than hidden in a general statement about "your account".
It does not cover the sites we link out to — RFCs, vendor documentation, and anything a reference points at. Their privacy practices are their own. Your use of the site is also subject to the terms of service.
01 / collection
What We Collect
given to us
Only if you fill in a form or write to us. Nothing here is collected from a visitor who just reads the site.
- port data
- the port number, service, transport, description, risk notes and references you propose on the contribute or suggest-an-edit form
- your name
- required on both forms, so a correction has an author behind it
- your email
- required on both forms, and only used to contact you about that submission or edit
- anything you email us
- the message and address you write from, kept while we deal with it
collected automatically
The by-products of serving a page and measuring whether it worked.
- request data
- ip address, user agent, url and timestamp — the ordinary server-side record of a page being served
- analytics events
- pageviews, time on page, and a handful of named actions such as a search or a submitted correction — counted without a cookie or an id
- cookies
- none for visitors; a login cookie only if you are a maintainer
We do not ask for and do not want anything else. No date of birth, no phone number, no payment details, no special-category data. Please don't put personal information into the free-text fields of a port submission — that text is written to a public database if the entry is accepted.
02 / legal basis
Why We Process It
Under the UK GDPR and the EU GDPR every use of personal data needs a lawful basis. Ours are these, and nothing here is used for profiling, scoring or automated decisions about you.
- serving the site
- legitimate interests — a web server cannot answer a request without processing the request
- handling submissions
- taking steps at your request, and our legitimate interest in a database that gets corrected
- analytics
- legitimate interests in knowing which ports people look up and what is broken — or your consent where local law requires it
- security and abuse
- legitimate interests in keeping the site up and rate-limiting the people attacking it
The name and email on a submission are used to contact you about that submission or edit — a question about a source, or a note that it went live. They are not added to a mailing list, and they are not published alongside the entry.
03 / analytics
Analytics, In Detail
The site uses Plausible, an open-source, cookieless analytics tool, running on a server we operate. A small script in your browser sends its requests to /api/pv on this domain, which forwards them to that server along with your IP address and user agent.
What it records:
- pageviews — the URL you loaded, the referrer, and when
- engagement — how long the page was in front of you and how far you scrolled
- named events — a search submitted, a search that found nothing (with the term you searched for), a correction or new entry submitted, a code sample copied, a sponsor or outbound link followed, a file downloaded, a page that wasn't found
- device context — browser, operating system, screen size category, and a country or region derived from your IP address, which is then discarded
Nothing is stored in your browser and no identifier is given to it. To count two pageviews as one visit, Plausible hashes your IP address and user agent with the site's domain and a salt that is replaced every 24 hours. Neither the address nor the user agent is stored, and once the salt is gone the hash can't be linked to you or to your visits on other days.
You can refuse it. Block requests to /api/pv with a content blocker and the site works exactly the same — you simply won't appear in the numbers. To be straight with you: the script does not act on Do Not Track or Global Privacy Control signals by itself, so a blocker is the reliable route. See the cookie policy for the specifics.
Analytics is how we know which ports get looked up and which pages fall over. It is not used to build advertising profiles, because there is no advertising.
04 / cookies
Cookies
One, at most, and not for you: an admin-auth cookie is set only when a maintainer logs in, and never for a normal visitor. The analytics are cookieless.
Your light/dark theme choice is not a cookie — it is kept in your browser's localStorage under whatportis-theme, is never sent to us, and disappears when you clear site data.
Names, lifetimes and how to refuse them are on the cookie policy.
05 / sharing
Who Else Sees It
- analytics
- nobody — plausible runs on a server we operate, so the events described above are not sent to an analytics company
- hosting provider
- runs the servers and the database on our instructions, and keeps short-lived request logs
- advertisers
- none. there are no ad networks, no trackers beyond analytics, and nothing is sold or rented
- everyone
- accepted port data becomes public in the database and the json api — your name and email do not
Our hosting provider acts as a processor: they handle the data to provide a service to us, under contract, and not for their own purposes. We would also disclose data if a law or a valid legal request required it, or to defend the site against abuse — and we would keep that to the minimum the request actually needs.
Separately, large language models are used inside the maintainers' admin tooling to help check and migrate the port database itself. They are pointed at port records, not at visitors, and no visitor personal data is sent to them.
06 / retention
How Long We Keep It
- analytics events
- kept on our plausible server as aggregate counts; no raw ip address or user agent is stored
- submissions and edits
- kept while under review, and afterwards as the record of where an entry came from
- submitter name and email
- kept with that submission; ask us and we will delete them
- server request logs
- short-lived, kept only for operations and abuse handling
- email to us
- kept as long as the conversation is useful, then deleted
Port data that has been accepted stays in the database — that is the point of the site, and it is not personal data. The contact details attached to the submission are a separate thing and can go independently of it.
07 / rights
Your Rights
If you are in the UK or the EEA, the GDPR gives you the rights below. Write to [email protected] and we will answer within a month. There is no charge, and we won't treat you differently for asking.
- access
- ask what we hold about you and get a copy
- rectification
- have anything wrong corrected
- erasure
- have it deleted, including a submitter name and email
- objection
- object to processing based on legitimate interests, analytics included
- restriction
- ask us to hold processing while a dispute is sorted out
- portability
- get what you gave us in a machine-readable form
- complain
- take it to your data protection authority — in the uk, the ico
One honest caveat: analytics keeps no id for anyone, so there is no analytics record we could find for the person asking — nothing to hand over, and nothing to delete. For a submission, tell us the email you used and we can find it immediately.
If you are a California resident, the CCPA/CPRA gives you comparable rights to know, delete, correct, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined, and we do not run cross-context behavioural advertising — so there is nothing to opt out of, but the other rights work the same way: use the same address.
08 / transfers
Leaving The Country
Hosting, the database and the analytics server may be operated from outside your country. We use providers who commit to equivalent safeguards. If you would like the current details of who processes what and where, ask and we will tell you.
09 / children
Children
This is a technical reference for network engineers and developers. It is not directed at children under 13, and we don't knowingly collect anything from them. If you believe a child has sent us a name and email through a submission form, write to [email protected] and we'll delete it.
10 / security
Security
The site is served over HTTPS. The database is not publicly reachable, and the admin area sits behind a login that only maintainers hold. Submitter contact details are visible to maintainers reviewing the queue and to nobody else.
No system is perfectly safe, and we won't claim otherwise — but the amount of personal data here is deliberately small, which is the most effective security measure available. If you find a vulnerability, tell us at [email protected] before you tell anyone else.
11 / changes
Changes
When this policy changes, the date at the top of the page changes with it — it currently reads 6 October 2026. If a change is material, such as a new processor or a new category of data, we will say so on the page rather than quietly editing a line. There are no accounts to email, so this page is the announcement.
12 / contact
Questions about any of this?
Privacy questions, access requests and deletion requests all go to the same place. A real person reads it.
last updated 6 October 2026