Proof, not a promise
Web proxy leak test
Most privacy tools ask you to trust a badge. This one asks you to check. When you open a site through TrickyBird, its address is encoded rather than spelled out wherever TrickyBird has to carry it. You do not have to take our word for it. Run the 3 checks below in your own tab.
One of our addresses, with the site’s encoded into it
Run the leak test in 3 steps
- Look at the address bar. It does not start with the site’s address but with the one TrickyBird served the page from, and that address will not always look the same, since sometimes it is only numbers. The site’s address is encoded into the part that follows rather than spelled out. If the link you opened carried a second address inside it, the way a sign-in or consent link often does, TrickyBird passes that part through as the site wrote it, so you will see it there.
- Right-click the page and choose View Source, then press Ctrl+F (Cmd+F on a Mac) and search for the site’s name. TrickyBird writes it in one place, the data-tb-host value that the toolbar reads to show you which site you are on. Every other match is the site’s own writing, such as its name in a heading, in the folder names it uses for its own images, or inside a link it built itself.
- Open DevTools (F12), switch to the Network tab, click any request, and read its Referer and Origin headers. The Referer is the same address you saw in the address bar, carrying the site’s address encoded in the same way. The Origin, where the browser sends one at all, is that address without the path. Where the site puts its own address into a query it builds, for its analytics or one of its banners, you will see its name spelled out in the request list, because TrickyBird passes that through as the site wrote it.
One honest note
Running a check here opens a real, short-lived TrickyBird session, and it is logged like any other: a shortened IP address, kept for at most 48 hours. The claim on this page is deliberately narrow. Wherever TrickyBird has to carry the site’s address, in the address bar and in the headers your browser sends, it carries it encoded rather than spelled out. The toolbar shows you the site’s address on purpose, so you always know where you are. What TrickyBird does not edit is what the site wrote about itself, in its own page and in its own links, so that passes through as written. This is about hiding which site you visit.
Questions
- What does TrickyBird hide?
- TrickyBird encodes the site’s address rather than spelling it out in your URL bar and in the headers your browser sends, and it hides your IP from the site you open. Our own gateway handles the connection, and we keep a shortened IP for at most 48 hours.
- So do you keep logs?
- We keep minimal, short-lived logs, and we do not claim to keep none. The edge log records a shortened form of your IP address, the hostname of the site you connected to, and basic response details, kept for at most 48 hours. The Security page lists exactly what is stored and for how long, so you can check the numbers against what runs.
- Will these checks work on my school or work laptop?
- Yes. Everything here runs in the browser you already have. There is nothing to install and no account to create, so the same checks work on a managed Chromebook or a locked-down work laptop, where downloading an app is not an option.