Data we collect
- Account and workspace details you provide, such as email address and workspace name.
- Domains, public DNS evidence, scan history, incidents, settings, and reports created through the service.
- If you separately opt in to product updates, your email address and a record of the consent wording, source, and time.
- If you request pilot access, your contact email, organization, domain-count range, optional description, and permission to contact you about the pilot. This is separate from marketing consent.
- Technical security and product-usage events needed to operate, protect, and improve the service.
How we use data
We use this information to provide scans and monitoring, secure accounts, deliver requested alerts, enforce plan limits, troubleshoot failures, and understand whether product journeys work.
Public diagnostics
Domain scans inspect information already exposed through public DNS, HTTPS, certificates, mail infrastructure, and reputation services. A result is a point-in-time observation, not a guarantee or compliance certification.
Sharing and providers
We do not sell personal information. When provider integrations are enabled, the minimum necessary information may be sent to hosting, email, billing, security-intelligence, and AI providers to perform the requested service.
Retention and deletion
Scan retention follows the workspace plan. You can remove monitored domains or permanently delete your account from Settings. Legal, fraud-prevention, or backup obligations may require limited retention after deletion.
Your choices
Public diagnostic tools can be used without creating an account. Marketing updates are optional, are never required to receive a free email domain health check, and can be unsubscribed from at any time. If you use a workspace, you can remove monitored domains and request account deletion from Settings. We will publish additional jurisdiction-specific notices before collecting information that requires them.