Privacy Policy
Last updated: 7 August 2026
1. Overview
This Privacy Policy explains what information Domainity.App, LLC, a Georgia limited liability company ("Domainity," "the App," "we," "us"), collects, why we collect it, and how it is used. We collect the minimum information necessary to operate a subscription service and do not sell or share your personal information with third parties for their own marketing purposes.
2. Information We Collect
Account & subscription information:
- Email address (for account creation, login, and communication)
- Subscription status and tier (for billing and feature access)
- Payment is processed entirely by Apple App Store / Google Play billing (or RevenueCat, if used) — Domainity.App, LLC does not directly collect or store credit card numbers or other payment credentials.
Usage information:
- Domain search history, tied to your account, so that you can access your own past searches. This is kept in two parts: the full report for a limited period (7 days on the free tier, 30 days on a paid plan), and a short record of the domain, the outcome and the date, which is kept for as long as your account exists so the App can tell you when you last looked at a domain.
- A count of searches performed, used to enforce plan limits. On the free tier this is a lifetime total (five searches, not a recurring allowance). On paid plans we also keep daily and monthly counts to enforce fair-use limits that exist to prevent automated abuse.
- Basic technical information necessary for the App to function (e.g., device type, app version) may be collected automatically for troubleshooting, and is not linked to search content beyond what is needed to deliver the service.
We do not collect: contacts, precise location, photos, browsing history outside the App, or any data beyond what is listed above.
3. How We Use Information
- To create and maintain your account
- To process and verify your subscription, and to enforce free-tier limits
- To store and display your own search history back to you
- To provide customer support
- To maintain, secure, and improve the App (e.g., diagnosing bugs, understanding aggregate usage patterns)
We do not use your search history to build advertising profiles, and we do not sell or share personal information with third parties in exchange for money or other value.
4. Caching of Search Results
To reduce load on third-party data sources and to return results faster, the App caches responses from its data providers.
These caches are keyed by the domain name searched, not by user. They contain no account identifier, email address, or other personal information, and a cached result cannot be attributed to the user whose search produced it. Cached entries expire automatically, with retention periods ranging from approximately one hour to thirty days depending on how quickly the underlying data changes.
Certain results — specifically security and blacklist checks — are deliberately not cached, so that those checks always reflect current information.
5. Third-Party Service Providers
We rely on the following service providers ("sub-processors") to operate the App. Each processes data only as necessary to provide their service to us, under their own privacy terms:
Infrastructure
- Cloudflare (Workers, KV) — processes requests and caches results as described in Section 4
- Supabase — authentication, account records, and search history
Subscription and billing
- Apple App Store, Google Play, and/or RevenueCat — manage billing and subscription status
Data sources. These providers receive the domain name you search in order to return results. They do not receive your account identity, email address, or any other personal information:
- Domain registry RDAP services — current registration records. Queries go directly to the registry operating the domain's extension (for example Verisign for .com, Public Interest Registry for .org), identified via the IANA bootstrap registry
- Cloudflare DNS (1.1.1.1 resolver) — current DNS records
- WhoisFreaks — current WHOIS registration and DNS records
- BigDomainData — historical WHOIS records
- Google Web Risk — malicious-listing checks (malware, phishing)
- APIVoid — malicious-listing checks (scam and fraud blocklists)
- RapidAPI, serving United States federal trademark register data — trademark screening
- Internet Archive — presence of archived captures
- DataForSEO — backlink profile data
- Ahrefs — Domain Rating authority score
- OpenPageRank (Keywords Everywhere) — authority score, second opinion
- DomScan — supplementary domain data and market estimates
- Replicate, hosting a third-party machine-learning valuation model — market estimates
(Update this list whenever the vendor stack changes. Adding or removing a data source changes who receives searched domain names.)
6. Personal Data in Third-Party Historical Records
Some data the App retrieves is *about domains*, not about you — but historical WHOIS records published before 2018 frequently contain the personal contact details of whoever registered a domain at the time: full name, postal address, email address and telephone number. That information was lawfully published in a public register.
The App shows the registrant name, organisation and country where a record contains them. It does not read address, email, telephone or fax fields from the source data at all, so those values never enter a report, a log, or our cache. This is a property of the implementation rather than a handling policy.
We are a controller in respect of this data only to the extent we display it. Where an individual believes historical registration data about them should not be displayed, contact us at verify@domainity.app and we will remove it from display; we cannot amend the underlying public record, which is maintained by registries and third-party archives.
7. Data Retention
We retain your account information for as long as your account remains active.
Search history is retained in two parts, on different schedules:
- Full reports are deleted automatically after 7 days on the free tier and 30 days on a paid plan. This is deliberate: the underlying data goes stale, and a months-old security result is worse than no result at all.
- A short record — the domain searched, the outcome, and the date — is kept while your account exists, so the App can tell you whether you have looked at a domain before.
If you delete your account, your personal information and all associated search history are deleted within 30 days, except where retention is required for legal, tax, or fraud-prevention purposes. Deletion of your account removes the associated records automatically.
Cached provider responses (Section 4) expire on their own schedule and are not tied to your account, so they are unaffected by account deletion — they contain no personal information to delete.
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Object to or restrict certain processing
- Receive a copy of your data in a portable format
To exercise any of these rights, contact us at verify@domainity.app. We will respond within the timeframe required by applicable law.
9. Jurisdiction-Specific Disclosures
- European Union / UK (GDPR / UK GDPR): Our lawful basis for processing account and subscription data is performance of a contract (providing the service you subscribed to). Where technical/usage data is processed for app improvement, our lawful basis is legitimate interest. You have the rights listed in Section 8, plus the right to lodge a complaint with your local data protection authority.
- California (CCPA/CPRA): We do not sell or share personal information as defined under CCPA. California residents have the right to know, delete, and correct personal information, and to non-discrimination for exercising these rights. Since we do not sell/share data, no "Do Not Sell or Share My Info" opt-out is currently required — this section should be revisited if that changes.
- Other jurisdictions: Users outside the above regions are still entitled to the rights described in Section 8 as a matter of policy, regardless of whether local law mandates them.
10. Children's Privacy
The App is not directed to children under 13 (or 16 where applicable under GDPR), and we do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.
11. Security
We use reasonable administrative and technical safeguards to protect your information, including relying on reputable infrastructure providers (Supabase, Cloudflare) with their own security practices. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. International Data Transfers
Your information may be processed in the United States or other countries where our service providers operate. Where required (e.g., for EEA/UK users), we rely on appropriate safeguards such as Standard Contractual Clauses for any such transfer.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date, and, where required by law, we will provide additional notice.
14. Contact
Questions about this policy or requests regarding your data can be directed to: verify@domainity.app