DeckproofBot visited your site. Here is what it did.
DeckproofBot is the scanner behind deckproof.dev. It only visits a site when a person starts a check of it, or a check they set up for their own site comes due. It does not crawl, it does not follow links across the web, and it never writes anything.
What it requests
The page you were asked about, the JavaScript that page loads, and a short list of well-known files: robots.txt, sitemap.xml, the favicon, the Impressum and privacy pages, and a handful of paths that should never be public, such as /.env and /.git/config, so the owner learns if they are. Each request is a plain read.
If the page talks to a Supabase or Firebase backend with a public key, the scanner asks that backend, with the same public key, how many rows an anonymous visitor could read. It asks for a count, never for a row, and it never inserts, changes or deletes anything.
A second pass opens the page once in a real browser with a fresh profile, to see which services are contacted and which cookies are written before anyone agrees to anything. It may click the reject button of a cookie banner and the site's own links to its Impressum and privacy page, and if there are none, open the usual addresses for them. It never fills in a form, never signs in and never buys anything. This pass identifies as an ordinary Chrome browser, because consent tools and tag managers often behave differently towards bots, and the point is to see what a visitor sees.
How often
Once per check. A check takes up to about 40 seconds and a few dozen requests. Each person can start at most five checks a minute, and monitoring re-checks a site about once a day, the free weekly check once a week.
Keep it out
Add this to your robots.txt and DeckproofBot will not scan your site, in either pass:User-agent: DeckproofBot
Disallow: /
The check is made before anything else is requested. A general "User-agent: * / Disallow: /" does not stop a check a person started, the same way it does not stop Lighthouse or a browser; it only tells search engines to stay away.
What happens to the result
Results are not published unless the person who ran the check chooses to list the grade, and a listed grade expires after 30 days. Page content is not stored; a finding keeps only the short technical evidence for it. Scans without an account are deleted after 90 days. Details are in the privacy notice.
Questions or a problem
Write to hallo@deckproof.dev. If our scanner caused a problem on your site, tell us the time and your domain and we will look into it and stop it.