Privacy
Template policy. Have a lawyer review it before you take money, particularly for GDPR.
What we store
- Your email address, for sign-in and alerts.
- The domains you choose to monitor, and the DNS records we read for them.
- Your agency name, accent colour and logo, if you upload them.
- Billing identifiers from Stripe. We never see or store your card details.
What we deliberately do not store
We do not store IP addresses. Rate limiting works on a SHA-256 hash of the address combined with a server-side salt, which cannot be reversed to an address, and those hashes are deleted after two days.
We never ask for, hold or transmit credentials for your mail provider, your DNS host or any other third-party account. The only input the scanner needs is a domain name, and everything it reads is public DNS.
Scanned domains are public data
DNS records are public by design. Reports for anonymously scanned domains are reachable at a guessable URL under /s/ and may be indexed. Reports generated for your clients live under /r/ behind an unguessable token and are marked no-index.
Retention
Anonymous scan results are deleted after 30 days. Scan history for monitored domains is kept for the retention window of your plan. Deleting a domain removes its history and immediately revokes any client report links for it.
Processors
Supabase (database, authentication, file storage), Stripe (payments), Resend (transactional email), Vercel (hosting). DNS queries go to Cloudflare and Google public resolvers and contain only the domain being checked.
Your rights
Email us to request export or deletion of your account and all associated data.