Privacy and data handling
This technical summary explains what the openByte application itself processes and what stays on your device.
Last updated: 17 July 2026
About this technical summary
openByte is self-hosted software, so this built-in page is not a complete operator-specific notice under Article 13 GDPR. The operator must publish its own notice and can configure /privacy to redirect to it.
Operator-specific privacy notice
A complete operator-specific privacy notice must identify the controller and contact details, any data protection officer, the purposes and legal bases, applicable legitimate interests, and the right to complain to a supervisory authority.
Requests, speed tests, and IP addresses
Every request necessarily exposes its source IP address to this server and any reverse proxy. openByte uses it to answer the request, display the public IPv4 and IPv6 addresses, enforce transfer and request limits, and protect service capacity. The download and upload tests exchange meaningless random bytes that are discarded. A completed measurement is not written to the results database unless you choose Share.
Sharing a result
Only activating Share sends a result to the server database. The record contains download, upload, latency, jitter, latency under load, bufferbloat grade, the displayed public IPv4 and IPv6 addresses, server name, and the time it was shared. The random result link has no access control: anyone who knows it can view the record.
Storage on your device
Language and theme are stored in local storage only after you select them. Recent-test history is off by default; enabling it stores the setting and up to 10 results (measurements, time, and grade) in this browser until you turn it off or clear site data. The local copy is not transmitted automatically. Failed optional address probes are remembered only in page memory and are not written to device storage.
Cookies and tracking
openByte sets no cookies, performs no analytics or advertising tracking, and embeds no third-party resources. Fonts and other application assets come from this server. Following an external link or an operator-configured redirect sends a request to that destination only after you navigate there.
Logs, recipients, and transfers
API logs may contain method, path, status, duration, and IP address. The operator and its configured reverse-proxy, hosting, logging, storage, or support providers may receive request data; anyone with a shared-result link receives that record. openByte itself sends no data to analytics or ad networks. Only the operator can name its actual processors, international transfers, and safeguards in its complete notice.
Retention
Transfer bytes are discarded with the request. IP rate-limit entries stay in volatile memory; inactive entries become eligible for cleanup after 10 minutes and disappear on later cleanup or a restart. An hourly job removes shared results once they are older than 90 days, and the configured count limit may remove them earlier. Operational failures can delay cleanup. The operator controls log and any backup retention and must disclose those periods in its notice.
Your choices and rights
Where GDPR applies, you may have rights to access, rectification, erasure, restriction, data portability, and objection, and to complain to a supervisory authority. Exercise those rights against the operator named in its notice; because openByte has no accounts, a result link or request details may be needed to find data. Turn off recent-test history or clear site data to remove browser-stored results.
Required data and automated decisions
An IP address is technically required for the server to answer; without a network request the page and speed test cannot be provided. Running a measurement and sharing it are optional, and openByte creates no statutory or contractual duty to provide data. It performs no profiling and makes no decision covered by Article 22 GDPR.