Skip to content

Privacy

Corelog is a fully client-side application. Here is exactly what happens with your data.

No part of your file — and nothing derived from it — is ever sent anywhere. There is no server, no API and no analytics platform to send it to. The only requests this tool makes are for its own static assets from this same domain: the analysis engine, the world map, and the offline IP-to-country database. They are downloads, never uploads. Verify it in browser DevTools → Network tab: every request is to this domain, and none carries a request body.

IP addresses are resolved to a country, a city and a network operator against databases bundled with the application and searched inside this tab. No address is ever sent to a geolocation service. The data is DB-IP IP to Country Lite, IP to City Lite and IP to ASN Lite, used under CC-BY-4.0 — IP Geolocation by DB-IP (db-ip.com).

The exported report can replace every identifier with a per-session alias — accounts, addresses in both the raw and normalised forms Purview writes, devices, filenames, sharing recipients, forwarding addresses, the tenant’s own domains and the labels you gave your declared networks. The substitution runs over the whole document, including inside the sentences detections write, because a detection bakes the account name into its own evidence text.

Two things it deliberately does not do, both stated on the report’s cover so a reader knows what the label covers. Declared network prefixes are omitted entirely rather than aliased, since a prefix is not the address of any event and has no alias to take. And city, region, country and network operator stay real, because a report whose locations read city_4f2a answers nothing.

Your CSV data is never written to localStorage, sessionStorage, IndexedDB, or any browser storage mechanism. When you close the tab, the data is gone.

There is no analytics, error tracking, session recording, or fingerprinting. This tool has no interest in how you use it.