Searches
The domain or IP address you enter is sent to netcheck's server only to run the selected check (DNS, SSL, HTTP headers, WHOIS, reputation, or ports) and is not logged, stored, or shared. Nothing about your search is written to a database or file. Once the response is sent, the target string is gone.
Third-party lookups
Running a check makes the server perform its own DNS/TLS/WHOIS/port queries against the target you entered — those queries reach the target's infrastructure, public DNSBL zones, or WHOIS registries directly, as any equivalent command-line tool would. The reputation check queries ten public spam-listing services; the WHOIS check queries the relevant domain or IP registry. None of them receive anything about you beyond the target you asked about.
Bot verification
Before your first search (and again roughly every three days), your browser runs a background check with InstantBlock to confirm you're not an automated script. This involves a browser fingerprint and a proof-of-work challenge, processed by InstantBlock's service. A timestamp marking when this last ran is stored in your browser's local storage so you aren't asked again for three days — that's the only thing netcheck stores locally, and it never leaves your browser.
Server logs
Like any web server, the underlying infrastructure may keep short-lived, routine access logs (IP address, timestamp, requested path) for abuse prevention and security — the same baseline logging any hosting provider keeps. These are not used to build profiles and are not shared with third parties.