Account and security

Privacy and data retention

What DomainGuard stores, what it hashes or encrypts, how long operational records are kept, what it never reads or changes, and the ads on Free.

Updated · 2 min read

DomainGuard reads public records and what your site already serves. The privacy policy at nhmohio.com/privacy-policy is the legal document; this article is the plain version of what the code does.

What is stored

Your account details; the domains you add and every scan result about them; change events; lookalike results; DMARC aggregate reports (counts and sending sources, never message content); compliance records and notes you write; conversations; API key hashes and usage; device tokens for push; the credit ledger; and an audit log of security-relevant actions.

What is hashed or encrypted

  • Monitored email addresses are stored as a SHA-256 hash plus an encrypted copy; audit entries and push payloads carry the hash or a masked form.
  • API keys are stored hashed; only the prefix is kept in the clear.
  • Two-factor secrets are encrypted at rest.
  • Passwords are PBKDF2 hashes.

What is pruned, and when

Record Kept for
IP addresses on contact and form submissions 90 days
Password reset requests 30 days
Audit log 365 days
Operational error events 90 days
API key usage 30 days (the current hour for limiting, 24 hours in the usage view)
Cached breach lookups Refreshed after 24 hours

Scan history is kept for the life of the domain on the account and deleted with it.

What DomainGuard never does

  • Read your mailboxes, filter inbound mail, or hold DNS or registrar credentials.
  • Change DNS, renew domains, or edit websites.
  • Send traffic to a domain the account has not proven it controls (beyond reading what it serves publicly).
  • Send your domain list to a third party for icons or enrichment; the favicon fetch that did so was removed from the app in 1.6.0.

Third parties in the path

Cloudflare (hosting, DNS for the DMARC report domain, browser rendering for audits), XposedOrNot (breach index, queried by address hash), localseodata.com (ranking and listing data for Local SEO), CISA and NVD (vulnerability feeds), Apple (purchases and push), and Google AdMob (non-personalised ads on Free only, no advertising identifier).

Ads on Free

Non-personalised banners in the iOS app, no App Tracking Transparency prompt, no IDFA. Ad privacy options are under Account. Paying anything removes them.

Your rights

Export what you need (PDF report, audit JSON, evidence pack) and delete the account at any time. Data requests can be sent through Ask for help.

Still stuck?

Ask the people who run the scanner.

Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.