Privacy and scan data
Operational data-handling notice ยท Reviewed October 6, 2026
Creative Validator processes submitted files and tags on its server to build diagnostic reports. This page describes the current service behavior, including its limits.
Before submitting: remove passwords, access tokens, personal data and material you are not permitted to share. Runtime scans can contact external servers. Report links may give their holder access to submitted content and results.
What is stored
HTML5 scans can retain the original ZIP, extracted files, scan results and preview artifacts. Tag scans retain submitted code or URLs, reports, screenshots and diagnostic artifacts. These can include remote request URLs, redirects, console messages and content returned by creative vendors. A scan is not a process that stays entirely in your browser.
Retention and deletion
- HTML5 scan files: reports and persisted creative files expire after 30 days. Expired files are removed when accessed or by scheduled cleanup.
- Tag scan artifacts: the current service uses a 30-day retention window, with hourly cleanup based on the artifact directory's last modification time. Cleanup also removes associated scan index rows. This is not an exact deletion deadline measured from submission.
- Other records: saved tags, accounts, monitor history, operational logs, analytics and backups are separate from scan-artifact cleanup. There is no single 30-day deletion promise for all service data.
Signed-in owners can delete their HTML5 scans through the scan API. Tag scans do not currently offer a user-facing delete operation. Revoking a share token removes that token's access; it does not erase a report, backups or copies someone has already downloaded.
Who can view a report
Default tag-report links are unlisted access links: anyone with the scan link can read the report. Signing in alone does not make a tag report private. An owner can enable token-protected sharing, which requires the owner's session or a valid share token.
Anonymous HTML5 report and preview links also grant access to their holder. Owner-associated HTML5 previews and files require the owner's session. Search exclusion is not an access control; treat every report link as sensitive and review the sharing controls before distributing it.
What a scan sends to external servers
- General tag rendering and HTML5 runtime checks: a test browser may load vendor scripts, images and other resources. Some recognized tracking requests are blocked, but the service cannot promise that every impression or tracker is prevented. External servers can receive requests from the testing infrastructure.
- VAST analysis: fetching a VAST URL, following wrappers and downloading bounded media files contacts their hosts. Declared impression, error, click and event tracker URLs are checked as text, without firing those trackers to test reachability. Controlled media playback uses local sentinel events.
- Consent, MRAID and SafeFrame simulations: these isolated checks abort external requests and record attempted behavior. Remote vendor scripts blocked in those checks cannot execute. This restriction does not describe every other stage of a scan.
- Landing-page checks and manual preview: reaching a destination or interacting with a creative can generate real requests. Use test campaigns where traffic matters.
Site analytics, storage and accounts
First-party analytics records page views, tool events, performance and basic device information. Page paths remove report identifiers and query strings; submitted creative code is not part of the workflow event payload. The analytics service derives a daily visitor estimate from a salted hash of IP address and browser user agent. It does not store the raw IP in that analytics event. Server and security logs are separate and may record request information.
The analytics tracker does not set tracking cookies. The application does use browser storage for preferences and session workflow state, and account features use authentication cookies. Account records and saved tags are retained separately from temporary scan artifacts.
Read how validation works for the evidence and limitations behind a report, or consult the API documentation for available access controls.