startpage.com privacy policy — score 90/100 (low risk)

Último análisis

El contenido del informe (resumen, hallazgos, citas) se generó en inglés y no está localizado.

Ejecutar un nuevo análisis en otra política

Startpage (Surfboard Holding BV) · startpage.com

Detalles del informe

low riesgo

Startpage offers exceptional privacy by design, collecting virtually no personal data and explicitly rejecting tracking, profiling, and search logging, though minor data flows to third-party ad and analytics providers exist.

Startpage's privacy policy is remarkably user-centric and strongly aligned with GDPR principles, primarily because its business model does not rely on personal data collection. The policy explicitly states that IP addresses and search queries are not recorded, and tracking cookies are not used. The company operates under Dutch and EU jurisdiction, providing robust legal protections against surveillance. However, there are minor gaps regarding the specifics of data shared with Google AdSense for click fraud prevention and the lack of explicit mention of international data transfer mechanisms for their third-party tools (Amplitude, Sentry). Overall, the policy is highly transparent and sets a high standard for privacy-friendly search.

Último análisis
FuenteURL
Longitud10,925 caracteres

Evaluación por categoría

Desglose de la política en las principales áreas de cumplimiento. Bueno = sólido, regular = mixto, deficiente = preocupante.

Data Minimizationgood

The policy explicitly states no collection of IP addresses, search queries, or tracking cookies, limiting data to only what is strictly necessary for service functionality.

Transparencygood

The document is exceptionally clear and plain-spoken about what is and is not collected, avoiding legal jargon while clearly defining its privacy standards.

Third-party Sharingfair

While no personal data is shared, integration with Google AdSense, Sentry, and Amplitude means some system data flows to third parties, though it is claimed to be anonymized.

International Transfersfair

The company is based in the EU, but using US-based processors like Google AdSense and Amplitude likely involves data transfers, which are not explicitly addressed with legal transfer mechanisms.

AI/Model Traininggood

The policy makes no mention of AI training, and given the strict no-recording and no-profiling stance, user data is functionally excluded from being used for this purpose.

User Rightsgood

The policy explicitly mentions GDPR compliance, the right to be forgotten, and the right to lodge a complaint with the Dutch Data Protection Authority.

Hallazgos clave

Cláusulas destacadas, problemas o buenas prácticas detectadas (críticos primero)

Advertencia

Third-Party Data Sharing for Ad Fraud Prevention

While ads are strictly non-personalized, the policy admits that 'some non-identifying system information is shared' with platforms like Google AdSense to prevent click fraud. The exact nature of this data is undefined, creating a minor transparency gap regarding what Google receives.

Advertencia

Silence on International Data Transfer Mechanisms

The policy mentions using Google AdSense, Sentry, and Amplitude (all US-based entities), but fails to mention the legal mechanisms (such as Standard Contractual Clauses) used to lawfully transfer data to these third parties under GDPR Chapter V.

Info

Strong Data Minimization & Anonymization by Design

The policy explicitly states that IP addresses and search queries are not recorded, and tracking cookies are not used. This architectural decision limits the attack surface for data breaches and government requests, as they cannot hand over data they do not possess.

Info

App Analytics Mitigation via Proxying

The mobile browser app uses Amplitude for product analytics, but Startpage proxies the data through its own servers to strip personally identifying information before it reaches Amplitude. This is a strong privacy-preserving engineering practice.

Info

IP Address Exception for Abuse Prevention

The policy contains a notable exception where IP addresses are temporarily registered and blocked to mitigate automated robotic abuse. While necessary for security, this technically involves processing an IP address (which is personal data under GDPR), even if it is not stored long-term.

Resumen para el usuario

You can use Startpage with high confidence that your searches and browsing habits are not being tracked, profiled, or stored by the search engine itself.

Postura de cumplimiento

Strongly compliant. The policy explicitly embraces GDPR principles, operates from the EU, and designs its systems around data minimization and anonymity.

Transferencias en la UE

The company is based in the Netherlands, but uses US-based services like Google AdSense, Sentry, and Amplitude. The policy lacks explicit mention of Standard Contractual Clauses (SCCs) or other Chapter V GDPR transfer mechanisms for these third-party flows, though it claims data is anonymized or stripped of PII before transmission.

Señales detectadas

Datos y prácticas específicas identificadas en el texto

Datos recopilados
Search preferences (via cookie)Anonymized traffic statistics (OS, browser, language)Non-identifying system information (for ad click fraud prevention)Crash diagnostic reports (no IP address)Anonymized product analytics (installs, usage volumes, errors)
Finalidades del tratamiento
Providing search resultsServing non-personalized advertisementsPreventing click fraud and automated abuseAggregated anonymous traffic measurementApp crash reporting and product improvement
Cesión a terceros
Google AdSense (non-identifying system information for fraud prevention)Sentry (crash diagnostic reports)Amplitude (proxied, anonymized product analytics)
Transferencias internacionales
Data shared with Google AdSense (US)Data shared with Sentry (US)Data shared with Amplitude (US)

Fragmentos de evidencia

Citas directas de la política que respaldan estos hallazgos

We don’t record your IP address... The only exception is for automated search requests (robots) that rapidly submit more queries to our servers than any normal human would.

When you search, your query is automatically stripped of unnecessary metadata including your IP address and other identifying information. We send the anonymized search query to our search and content providers...

In order to enable the prevention of click fraud, some non-identifying system information is shared, but because we never share personal information... the ads we display are not connected to any individual user.

Product event analytics are powered by a service called Amplitude, and when this service is being used, data is proxied through servers managed by Startpage to ensure that personally identifying data is stripped before making its way to the service.

Ausente o poco claro

  • No explicit mention of legal bases for processing under GDPR Article 6
  • No mention of data retention periods for the IP blocklist or crash reports
  • No mention of international data transfer safeguards (SCCs, Data Privacy Framework) for US third parties
  • No specific details on what constitutes 'non-identifying system information' shared with Google AdSense

Preguntas que hacer

  • What specific 'non-identifying system information' is shared with Google AdSense for click fraud prevention, and is there any risk of re-identification by Google?
  • How long are IP addresses retained for the automated search request (robot) blocking exception before they are deleted?
  • Does the Sentry crash reporting service receive any device identifiers that could indirectly identify a user, despite the claim of no PII?
  • What legal mechanisms (e.g., Standard Contractual Clauses) are in place to ensure GDPR-compliant data transfers to US-based third parties like Amplitude and Sentry?
Este análisis lo genera la IA y no constituye asesoramiento legal. Consulta siempre a un profesional jurídico cualificado para decisiones de cumplimiento.

Compartir este análisis

Cualquiera con este enlace puede ver el resultado anterior.

Creado por DentroChat

Chat de IA 100 % europeo para todos

Chatea con la IA, trabaja con archivos, genera imágenes y busca en la web. Los datos permanecen en Europa.

Infraestructura alojada en la UETexto, archivos, imágenes y búsqueda webModos Rápido, Reflexión y CreativoPrivacidad por defectoNingún dato sale de Europa
Probar gratis →