Privacy Exposure Score

⚠️ Affiliate Disclosure: This page contains affiliate links. If you purchase through them we may earn a commission at no extra cost to you. Read our full disclosure.

This page runs a set of checks against your own browser and shows exactly what a website learns about you the moment you arrive — your address, whether anything leaks around a VPN, and how identifiable your browser is without any cookies at all. Everything runs locally; nothing is stored.

…out of 100
Scanning
Checking what this page can see…

Six checks, all run in your browser.

Key takeaway: having a visible IP address is not a failure — every site you connect to needs one to send the page back. What matters is whether anything reveals more than you intended: an address leaking around a VPN, a timezone that contradicts your location, or a browser so distinctive it can be recognised without cookies.

How this score is calculated

Only things you can actually change cost points, and the score starts at 100. If nothing leaks and your browser resists fingerprinting, you score 100 — that outcome is reachable, which is the whole point of publishing the weights:

FindingCostWhy
WebRTC reveals a different public address−30A genuine leak: something is bypassing your VPN.
IPv6 reachable while on a VPN−25Traffic can escape an IPv4-only tunnel.
Timezone contradicts IP location−10A reliable tell that flags you as a VPN user.
Canvas fingerprint readable−10Identifies your device across sites without cookies.
GPU model readable−8Adds a distinctive, stable signal to that fingerprint.
Your IP is visible at all0Unavoidable. Scoring it would just make everyone fail.

That last row is deliberate. A score that nobody can achieve is a sales pitch wearing a lab coat, and the previous version of this page had exactly that problem — a normal home connection with nothing wrong scored 46 out of 100 and was told it was “leaking on multiple fronts”.

What a WebRTC leak actually is

WebRTC is the browser feature behind video calls. To connect two people directly it has to discover which addresses your machine can be reached on, and a web page can read that list.

The thing that matters is whether the address WebRTC reveals differs from the one the site already sees. If you are not using a VPN, WebRTC reporting your public IP is not a leak — the server you requested this page from already had that address. It is only a leak when a VPN is supposed to be hiding your real address and WebRTC hands over a different one anyway.

Most “leak test” pages get this wrong and mark every visitor as leaking, because a red result sells more subscriptions than a green one. This check compares the two addresses and only calls it a leak when they genuinely differ. Local addresses like 192.168.x.x are not leaks either — they describe your home network, mean nothing outside it, and modern browsers already mask them behind random .local names. For the deeper version of this test, including DNS, the full leak test goes further, and what a DNS leak is explains the part no browser can check on its own.

Fingerprinting, demonstrated rather than asserted

The fingerprint row above shows a short ID derived from your browser’s own characteristics: how it draws text, which GPU it reports, your screen dimensions, language list, processor count and timezone. Reload the page and the ID stays the same. Open a private window and it still stays the same — that is the point, and it is why private browsing does less than people assume.

No page can honestly tell you how unique you are, because that needs a database of everyone else to compare against, which we do not have and would not want. What this shows instead is which signals are readable and how stable the combination is. That is the honest version of the claim.

What actually reduces it

Browser choice does far more than any setting. Tor Browser makes every user look identical, which is the only real defence. Brave randomises canvas and audio signals per site. Firefox with resist-fingerprinting enabled reports standardised values. A VPN changes none of this — it moves your network address and leaves the browser signals untouched, which is the single most common misunderstanding about what VPNs do.

The timezone tell

Your browser reports its own timezone from your operating system, and your IP address implies a location. When the two disagree — a Romanian clock behind a Dutch exit node — that inconsistency is itself a signal. Fraud systems use it to flag VPN traffic, which is why some sites challenge you more aggressively while connected.

It is not a security hole and there is no reason to panic about it. If you want the two to agree, pick a VPN server in your own region, or change your system timezone to match the exit you use.

What a VPN fixes here, and what it does not

It replaces your IP address, so the location and ISP rows change and your provider stops seeing which sites you visit. It does not touch your browser fingerprint, it does not stop cookies, and a badly configured one can introduce the WebRTC and IPv6 leaks this page checks for. Worth having for the right reasons; not a privacy cure.

PureVPN IPVanish

Affiliate links. We do not rank by commission — compare providers yourself.

What this page cannot see

Who you are. None of this is tied to a name. It describes a connection and a browser configuration.

Your browsing history. That has not been readable by a web page for many years.

Whether you are being tracked right now. It shows which signals are available to a tracker, not who is collecting them.

Your DNS resolver. Checking that properly needs randomised hostnames resolved against controlled nameservers, which cannot be done from a page like this — the leak test explains why in more detail.

And nothing here is stored. The checks run in your browser, the results are never sent to us, and reloading the page starts from nothing.

Frequently asked questions

I scored below 100. Should I be worried?

Probably not. Points come off for readable fingerprinting surfaces that most browsers expose by default — that is a description of stock Chrome, not a fault. The rows worth acting on are a WebRTC leak or an IPv6 bypass while a VPN is connected, because those defeat a protection you thought you had.

Why does my score change between browsers?

Because the browser is most of what is being measured. The same connection through Chrome and through Tor Browser produces very different results, which is the clearest evidence that fingerprinting is a browser problem rather than a network one.

Does incognito mode change anything here?

Almost nothing. It clears cookies and history when you close the window; it does not change your IP address or your fingerprint. See what incognito actually does.

My IP shows the wrong city. Is that a problem?

It is normal. Geolocation maps addresses to the provider’s records, which are often a regional office rather than your street — how accurate IP geolocation really is covers the detail. Being visible at roughly the right region is the expected outcome, not a leak.

Can I get to 100?

Yes, and that is deliberate. A hardened browser with no leaks reaches it. If the maximum were unreachable the number would be advertising rather than measurement.

Related reading

Scroll to Top