Last updated 2 September 2026
Privacy Policy
We collect as little as we can and never sell your data. This notice explains what we hold and why. We're the data controller for dnsdoctor.dev; contact us at [email protected].
What we collect
For the free scanner, no account is needed. We store scan results (the DNS records we read for the domains you check — public data) and privacy-respecting usage analytics, with IP addresses truncated so they can't identify you. For Monitor, we store your email address, the domains you choose to monitor, and the DMARC aggregate (RUA) XML reports your mail receivers send about your domains.
If you sign in with Google or GitHub, we take one thing from it: your verified email address. We never receive your password, and we don't ask for your profile, contacts, or repositories. If the provider can't give us a verified address, we refuse the sign-in rather than fall back to an unverified one.
Cookies
First-party cookies only — no third-party ones and no advertising or tracking networks. Sign-in cookies, set only when you sign in, which keep you signed in. And dd_ref, set on your first visit and kept for 30 days, which records only how you arrived — the site that linked you and the page you landed on — so we can tell which channels bring people here. It holds nothing about you, is never read by anyone else, and is not set at all if your browser sends a Do Not Track signal.
How we use it
To run the diagnosis, send you magic-link sign-in emails and the alerts you ask for, and to understand which pages are useful. You sign in with Google, GitHub, or a magic-link email — never a password, because we don't store one. We don't use your data to train third-party models, and we don't send you marketing you didn't request.
Who we share it with
A short list of processors that make the service work: Paddle (our merchant of record — it handles payments and tax; we never see your card), Postmark (sends our sign-in and alert emails), and our hosting and error-monitoring providers. Each processes data only to provide their part of the service.
We also use Cloudflare Turnstile for invisible bot protection on our scan, sign-in, and email forms. It runs without a visible challenge and processes limited device and network signals to tell humans from automated traffic, as described in Cloudflare's Turnstile Privacy Addendum.
Signing in with a provider is a two-way street worth naming: choosing that route tells Google or GitHub that you signed in to DNS Doctor, and what they do with that is governed by their own privacy policies, not this one. The magic-link option involves neither of them.
Retention
Monitor keeps your reports for 12 months. Sign-in tokens expire within minutes and are single-use. If you close your account we delete your personal data, keeping only what law or tax rules require.
Your rights
Under the GDPR and similar laws you can access, correct, export, or delete your personal data, and object to processing. Email [email protected] and we'll act on it. You may also complain to your local data-protection authority.
Changes
We may update this notice; the “last updated” date above tracks changes.