Privacy
NetsCLI has no accounts, no advertising and no telemetry. Nothing you scan is sent to the developer or to anyone else.
What stays on your computer
NetsCLI reads information about your local network to do its job. That includes IP addresses, MAC addresses and the maker they belong to, hostnames, open ports, and the greetings services send back. It is shown to you and is not uploaded anywhere.
Some of it is kept on your computer.
- The desktop app can keep your 20 most recent runs, with their results, so you can reopen them. Clearing history removes them.
- From version 0.3.5 on, the command line and terminal UI keep a history of their results in
~/.netscli/netscli.dbonly if you setNETSCLI_HISTORY=1. Earlier versions kept every result there without asking. Deleting the file removes that history. - The desktop app and terminal UI remember their settings.
- Exports and packet captures are written only where you choose to save them.
What reaches the internet
- Scans go where you point them. A port scan, ping or trace contacts the hosts you ask it to. A DNS lookup, including the one a scan makes to turn a name into an address, goes only to the DNS servers your computer is set up to use.
- Version 0.3.4 and earlier also asked Cloudflare's public DNS. When your DNS servers could not answer a lookup, including when a name simply had no records of the type asked for, those versions asked Cloudflare's public resolver (1.1.1.1) the same question, unencrypted. Single-word names and names ending in .local, .lan, .home, .home.arpa, .internal or .test were never sent. Setting
NETSCLI_DNS_FALLBACK=0turns this off in those versions. From version 0.3.5 on, NetsCLI never does this. - The desktop app checks for new releases. Installs that can update themselves fetch one small file from GitHub's release downloads, and the rest ask GitHub's API for the latest release. Either way GitHub sees your IP address. You can turn the check off in Settings, under Release Notifications. If you choose to install an update, it is downloaded from GitHub Releases.
- The command line, terminal UI and MCP server make no connections of their own beyond the operations you run.
This website
This site is hosted on GitHub Pages behind Cloudflare, which handles every request to it and so sees your IP address. It uses Cloudflare Web Analytics, which counts page views without cookies and without identifying visitors. The landing page asks GitHub and crates.io for the star and download counts it shows, and the changelog page asks GitHub for the release notes. Your browser contacts those services directly.
Contact
Questions about privacy can go to the issue tracker.