Legal
Privacy Policy
How NHM LLC and DomainGuard collect, use, protect, and retain data across the public website, dashboard, API, mobile app, and payments.
Effective Date: September 3, 2026
Effective Date: September 3, 2026
NHM LLC ("we," "us," or "our") operates the website at nhmohio.com, related APIs and backend services, and the DomainGuard mobile apps. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use these services.
1. Information we collect
Information You Provide Directly:
- Contact form, lead-report and newsletter submissions: Name, email address, phone number, company name, and message content when you submit a form, plus the page the form was on. We also record the IP address the submission came from, to stop automated abuse of the form; we remove it after 90 days. If you allowed Preferences cookies, the campaign tags, click identifiers, landing page and referrer from your visit are saved with the inquiry (see "Lead attribution data" below).
- Account Registration and Profile: Name, email address, mobile phone number, password, and your SMS consent choice when you create or update an account in the dashboard or DomainGuard app. Declining SMS does not prevent account creation or use of the service.
- Domain Monitoring: Domain names you add to your dashboard for security scanning and monitoring.
- Dark web monitoring addresses: Email addresses you add to your monitored list so we can check them against known data breaches. We store each address in two forms and never in plain text: a one-way SHA-256 hash, which is what identifies the address everywhere in our system, and an AES-256-GCM encrypted copy, which is what we decrypt when a check runs. Our internal audit records reference the hash, not the address. You can remove an address at any time, which deletes both forms. See section 6 for what we send to the breach index and section 8 for how account deletion applies.
- Scan and assessment results: Outputs from security scans, DNS and checkup results, uptime checks, SEO and accessibility audits, vulnerability findings, compliance checklists, and related alerts or reports generated for your account. We retain these results on our servers so we can show history, run notifications, and keep the dashboard and DomainGuard app working as designed—not for unrelated marketing.
- Security Assessments: Responses to our IT security survey and security assessment tools.
- Checkups and free tools: Domain checkups and scans run from an account, and the results are stored with that account as described above. When a checkup or scan is requested we also send ourselves an internal email noting the account, the domain, and the IP address, country, referrer and campaign of the request, so we can spot abuse and understand where requests come from. That email is a notification, not a database record, and it goes through our email provider (SMTP2GO, section 6). The public password checker and phishing quiz run entirely in your browser and send us nothing. The public lookalike-domain check stores nothing about you beyond a 48-hour rate-limit record keyed by IP address.
- DomainGuard (mobile): When you use our mobile app, we process account credentials, profile information, SMS consent, and tokens as described below. We may receive mobile push notification tokens and related identifiers so we can deliver alerts you opt into. The app caches domain and account data on your device for performance and offline access, and refreshes your domain list and alerts in the background when iOS allows it. Some settings and drafts (for example an onboarding draft, quick-check history and the email address you chose for SEO reports) live in standard app storage and are included in your device backups. When you run a site check from the app, your phone contacts your website directly, so your site sees a request from your device.
- In-app purchases: If you subscribe through the Apple App Store or Google Play, Apple or Google process payment information. We receive subscription identifiers and receipts or tokens needed to validate your plan on our servers—we do not receive your full payment card number from the stores.
- Website purchases: If you subscribe on nhmohio.com, the payment provider identified at checkout processes the payment. Paddle.com acts as Merchant of Record when Paddle is shown; Stripe processes the payment for NHM when Stripe is shown. You provide your name, email address, billing country and postal code, payment card details, and any VAT or tax identifier directly to that provider. NHM never receives or stores your full payment card number. We receive customer and subscription identifiers, the plan and billing period, subscription status and renewal date, and lifecycle events needed to keep your plan correct.
Information collected automatically:
- Analytics Data: Ahrefs Web Analytics runs on every page for aggregate website measurements; Ahrefs states that it uses no cookies and no persistent identifiers. Google Analytics 4 and Microsoft Clarity load only after you accept analytics in the cookie banner; before that, nothing is sent to either. If you later reject, we deny Google analytics storage, tell Clarity to stop, and remove the first-party cookies each set on our domain. Google advertising storage, advertising user data, advertising signals, and ad personalization remain disabled regardless of your choice.
- Log data and IP addresses: Our web server (Cloudflare Workers) logs a sample of requests, including IP address, browser type, path and timestamp, for security and performance purposes. Separately, we store the IP address (and in some cases the browser identifier) with a small number of records so we can rate-limit and investigate abuse. Each has a retention period we enforce automatically:
- Contact, lead-report and newsletter submissions, support requests and abuse reports: 90 days, then the address is erased from the record.
- SMS consent records: kept with the consent record for the life of the account.
- Security audit log (account actions, with your email, IP and browser): 12 months.
- Sign-in attempts: 24 hours. Registration attempts: 2 days. Forgot-password requests: 30 days.
- Public tool rate limits: 48 hours. Scan-abuse counters keyed by domain: 90 days.
- Authentication events in our operations log (sign-in, sign-out, failures): kept for security monitoring and reviewed only when investigating an incident.
- Mobile advertising data: The free tier of the DomainGuard mobile app shows banner ads served by Google AdMob. When the app requests an ad, Google's Mobile Ads SDK may process device and app identifiers, coarse location derived from your IP address, ad interactions such as impressions and taps, and performance and diagnostic information, to deliver, secure, and measure ads. Where the law requires consent, the app presents Google's consent form before requesting any ad, and you can change those choices later in Settings. We disable publisher ad personalization and publisher first-party identifiers; the app does not use IDFA or Apple App Tracking Transparency, and paid plans do not request ads.
- Scan usage and abuse-prevention records: We record the account, target, scan type, timestamps, blocked requests, and domain add/delete activity needed to enforce limits and investigate spammy, malicious, or unauthorized use. These counters are not erased merely by deleting and re-adding a domain.
- Lead attribution data: If you allow Preferences cookies, we keep the campaign tags, advertising click identifiers, landing page and referring page from your visit in your browser session. If you then submit a contact form, register, or run a checkup, that context is saved with the inquiry and passed to our CRM so we can tell which advertising or referral source produced it. If you do not allow Preferences cookies, nothing is recorded.
- Device / app data: For push notifications and app reliability, we may process device tokens, app version, and similar technical data as needed to deliver the service.
2. How we use your information
- To respond to your inquiries and provide requested services
- To provide dashboard functionality including domain monitoring, security scanning, and compliance tracking
- To store and display scan results, scores, logs, and related outputs so you can review past runs, compare changes over time, receive alerts, and use features that depend on prior data (for example trend lines, reports, and synced views between the web dashboard and DomainGuard mobile app)
- To send service-related notifications (e.g., scan results, security alerts), including push notifications when you enable them
- To improve our website and services
- To protect against unauthorized access and security threats
- To comply with legal obligations
3. Data storage and security
Your data is stored on Cloudflare's infrastructure: account and scan records in Cloudflare D1 databases, and generated scan and checkup reports in Cloudflare R2 object storage. Account passwords are hashed with PBKDF2-HMAC-SHA256 and a per-account salt and are never stored in plain text. We implement appropriate technical and organizational measures to protect your personal information, including encryption in transit (TLS/SSL) and access controls.
Retention of operational results: We keep scan results, monitoring outputs, and related records for as long as your account is active and they are needed to provide the service—for example to show recent and historical results, power notifications, and maintain app and API behavior you rely on. If you delete a domain or your account, associated results are removed in line with our technical processes and your deletion requests, subject to limited backup or legal retention where applicable.
Abuse-prevention retention: We may retain limited scan-usage, domain-lifecycle, network, and enforcement records after a target or account is deleted when needed to detect limit evasion, prevent repeat abuse, investigate a complaint, or meet legal and security obligations. We do not use these records to restore deleted scan results or for unrelated marketing.
4. Local storage on your devices
The DomainGuard app stores your session token in the iOS Keychain and caches data on your device so the app can load quickly and work offline in limited ways. On the website, signing in sets first-party cookies (auth_token, auth_present and refresh_token) that are described in the Cookie Policy; when the DomainGuard app opens a dashboard page it may also place its token in the page's local storage. The website keeps your cookie-consent choice and your California opt-out flag in local storage, the dashboard keeps UI state such as the console mode and your finding queue in local storage, and, only if you allowed Preferences cookies, campaign attribution stays in session storage until you close the tab. You can clear app data through device settings and website data through your browser.
5. Two-factor authentication
If you enable two-factor authentication (2FA) on your dashboard account, we store the encrypted TOTP secret associated with your account. This data is used solely for authentication purposes.
6. Information sharing
We do not sell, trade, or rent your personal information. We may share information in the following limited circumstances:
- Service providers that run DomainGuard: These receive data because the product cannot work without them.
- Cloudflare hosts the site, the API, and the database. Everything described in this policy is stored on or passes through Cloudflare infrastructure.
- SMTP2GO delivers our email. It receives the recipient address and the content of the message, which for a contact form includes the name, email, phone, and message you submitted, and for an alert includes the domain and the finding being reported.
- GoHighLevel / LeadConnector is our CRM. It receives contact form, lead-report and newsletter signups, including the name, email, phone, message, the page the form was on, and any campaign attribution you allowed, so we can follow up on an inquiry. It does not receive your IP address. The same company runs the live chat widget on our marketing pages, which loads only if you allow Preferences cookies and receives whatever you type into it.
- Cloudflare Workers AI generates the AI fix suggestions. The model runs inside Cloudflare's environment; the scan context we send it is the domain, the finding, and the surrounding scan output, never your name, email, or account identifier. No outside AI provider is involved.
- Analytics providers (Ahrefs, and Google Analytics and Microsoft Clarity once you accept analytics) receive website usage data as described in section 1 and in the Cookie Policy. None of them receives your account identity or your monitored domains.
- Expo receives device push tokens for notifications delivered to non-Apple builds. It does not receive your account email.
- Google (advertising) serves the banner ads shown to free-tier users of the DomainGuard mobile app through Google AdMob. When an ad is requested, Google's Mobile Ads SDK may process device and app identifiers, coarse location derived from IP address, ad interaction data such as impressions and taps, and performance and diagnostic information, to deliver, secure, and measure ads. Where the law requires it, the app asks for your consent through Google's consent form before requesting any ad, and you can change or withdraw those choices in the app under Settings. We disable publisher ad personalization and publisher first-party identifiers, and the app does not use the advertising ID (IDFA) or Apple App Tracking Transparency. Paid plans and the ad-free add-on do not request ads at all.
- DomainGuard third-party checks: When you run a DomainGuard SEO, accessibility, or performance check on a domain or page, the URL is sent to the appropriate provider so it can return a score:
- DNS resolvers and domain registries receive the domain name whenever we look it up. DNS queries go to Cloudflare's resolver (1.1.1.1). Registration data comes from the registry that runs the domain's top-level domain over RDAP (for example Verisign for .com and .net, Public Interest Registry for .org, Google Registry for .dev and .app). They receive the domain name and nothing about your account.
- crt.sh (Sectigo's public certificate log search) receives the brand name or domain we search for when looking for lookalike domains, including from the free public lookalike-domain check. No account identity is shared.
- Cloudflare API receives the DNS records we publish on your behalf when you use managed SPF or DMARC delegation. Cloudflare already hosts everything else in this policy.
- LocalSEOData receives the domain and the page URLs, plus the search terms and the city or area you are targeting, when you run a local SEO or geogrid scan. No account identity is shared.
- OSV.dev (operated by Google) receives the names and versions of software packages detected on a site so it can return known vulnerabilities. It receives no personal data and no domain.
- Certspotter (SSLMate) receives the domain when we watch Certificate Transparency logs for certificates issued against it. No account identity is shared.
- Public asset-discovery sources receive the verified domain when Subfinder looks for publicly recorded hostnames. The configured sources are crt.sh, Certspotter, Common Crawl, the Internet Archive, and Shodan's Certificate Transparency index. They receive no account identity. Active vulnerability checks run in our Cloudflare environment rather than being sent to a hosted scanning provider. Bounded manual checks are available on Free accounts; recurring checks are paid-only. Active checks require current DNS or file proof of control and can cover the main domain and public subdomains found within that verified domain.
- Webhooks you configure (for example a Discord or Slack channel) receive the alerts you choose to route there: the domain and the finding. You control that destination, not us.
- 330 Hosting portal — if you explicitly link a 330 Hosting account inside DomainGuard, we exchange the minimum fields needed to identify the linked customer (hosting email, NHM customer ID, link timestamp). The 330 Hosting portal opens inside Safari View Controller in the iOS app and uses its own cookies and account state.
- Dark web monitoring (XposedOrNot): If you add an email address to the Dark Web Monitoring list in the DomainGuard app, we send that address to XposedOrNot, a breach-index service, so it can tell us which known data breaches list it.
- What we send: one email address at a time, and only an address you have added yourself. We do not send your name, your phone number, your domains, or any other field from your account. There is no way to ask about an address that is not on your own list.
- What comes back: a description of each breach the address appears in. That is the breached company, its website, the date, the categories of data exposed, and how many records were involved. It does not return anyone else's email address, and we do not receive breached passwords.
- Caching: we keep the result for 24 hours so that repeated checks do not repeat the lookup. The cache is keyed by the hash of the address, so two accounts monitoring the same address share one cached result. Removing an address deletes your entry immediately, and the cached result once no other account is monitoring that address.
- International transfer: XposedOrNot is operated from India and runs on Google and Cloudflare infrastructure. Sending an address there is a transfer outside the United States and the EEA. Its published policy states that addresses submitted for checking are processed in memory and are not logged in identifiable form. If you would rather not have an address transferred, do not add it to the monitored list. The rest of DomainGuard works without this feature.
- We do not verify that you own an address you add. Adding an address tells us to check it against a public breach index and report back to you. Only add addresses that are yours or that you are authorised to check. Free accounts may monitor one address, paid accounts more; those limits are the main control on misuse. We may add ownership verification in a future release.
- Apple platform services:
- Sign in with Apple transmits the Apple-issued identity token to NHM and, on your first sign-in, the name and email address you choose to share. Your real email is shared with us only if you choose to share it; otherwise Apple provides a private relay address.
- Apple Maps supplies the map behind the local SEO geogrid view in the iOS app. Apple receives the map area for the business location you typed, under Apple's own privacy policy; NHM sends Apple nothing.
- Apple App Store (purchases) receives a purchase token derived from your NHM account number with each in-app purchase, so Apple can tell us which account a subscription belongs to. It is not your email or name.
- Apple Push Notification service (APNs) receives your device token when you opt in to notifications inside the app, plus the notification payload NHM needs to deliver the alert. APNs does not receive your account email or identity.
- Apple StoreKit / App Store processes payment information for in-app purchases. NHM receives only the subscription identifiers, signed transaction receipts, and lifecycle events needed to validate and manage your subscription.
- Paddle (payments on this website): Paddle.com Market Ltd is the Merchant of Record for subscriptions bought on nhmohio.com. Paddle is an independent controller of the payment and billing data you give it, not merely our processor: it issues your invoice, calculates and remits sales tax and VAT, runs fraud checks, and handles returns. Its handling of that data is governed by the Paddle Privacy Notice. We share your account email with Paddle so a purchase can be matched to your account, and Paddle shares the subscription state back with us so your plan stays correct.
- Stripe (payments on this website): When Stripe is identified at checkout, Stripe processes the payment for NHM, performs fraud prevention, and may calculate tax. We share your account email and an internal account identifier so the purchase can be matched to your account. Stripe returns customer, subscription, price, payment status, renewal, and lifecycle data needed to provide and manage your plan. Stripe's handling of payment data is described in the Stripe Privacy Policy.
- Legal requirements: We may disclose your information if required by law or in response to valid legal process.
Where this data goes. NHM Ohio operates from the United States and most of the providers above are US companies or run on US infrastructure. Two are not. XposedOrNot is operated from India, as described above. Cloudflare, which hosts everything, may process and cache data in the region closest to the person making the request. If you are in the EEA or the UK, using DomainGuard involves transferring your data to the United States and, if you use dark web monitoring, to India.
This list is the complete set of third parties that receive customer data from DomainGuard. If we add another, we will update this section before the feature ships rather than after.
7. Cookies and similar technologies
Our website and web dashboard pages opened inside DomainGuard may use first-party cookies and browser storage for functionality and analytics choices. Native app features use the iOS Keychain and local device storage as described above. Please see our Cookie Policy for details.
8. Your rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Opt out of non-essential communications
You can delete your DomainGuard account yourself, and you do not need to contact us to do it. In the iOS app, open the Account tab, then Settings, and tap "Delete account". You will be asked to type DELETE to confirm, and the deletion runs immediately. On the web dashboard, request deletion from nhmohio.com/account/delete and confirm using the single-use link we email you.
Either route removes the same things: your login and profile, your saved domains and groups, your scan, checkup, DMARC, and SEO history and the stored reports behind them, your dark web monitoring addresses, your API keys, and your push notification subscriptions. What remains afterwards is listed in section 1 under "Log data and IP addresses": security audit-log rows for up to 12 months, sign-in attempt records for 24 hours, and domain-keyed scan-abuse counters for 90 days, none of which we use for anything but security and fraud investigation. On your phone, the app clears its session and cache; a few local settings and drafts remain until you delete the app. If you would rather we handle it, you can still email support@nhmohio.com from the address registered to your account and we will confirm receipt within five business days.
For all other rights (access, correction, opt-out) please contact us at (330) 305-2750, by email to support@nhmohio.com, or through our contact page.
9. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to Know what personal information we collect, the categories of sources, the business or commercial purposes, and the categories of third parties with whom we share it.
- Right to Delete personal information we have collected from you, subject to legal exceptions.
- Right to Correct inaccurate personal information.
- Right to Opt Out of Sale or Sharing. We do not sell personal information. We do not share it for cross-context behavioral advertising. You can still record an opt-out preference through our Do Not Sell or Share My Personal Information page or by enabling Global Privacy Control (GPC) in your browser.
- Right to Limit Use of Sensitive Personal Information. The only sensitive personal information we hold is your account log-in credentials (your password, stored only as a salted hash, and your two-factor secret, stored encrypted). We use them solely to authenticate you, which is a purpose CPRA permits without a limit request, so there is nothing further to limit.
- Right to Non-Discrimination for exercising any of the above rights.
You may submit a California rights request through the contact information below. We will verify your identity as required by California regulations and respond within 45 days. Authorized agents may submit requests on your behalf with verifiable authorization.
California Shine the Light (Cal. Civ. Code § 1798.83): California residents may request a list of the categories of personal information disclosed to third parties for those third parties' direct marketing purposes in the preceding calendar year. We do not disclose personal information to third parties for their direct marketing purposes.
9a. Your privacy rights under GDPR (EEA/UK)
If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) gives you the following rights:
- Access the personal data we hold about you (Article 15 GDPR).
- Rectification of inaccurate or incomplete data (Article 16 GDPR).
- Erasure ("right to be forgotten") of your data, subject to legal exceptions (Article 17 GDPR).
- Restriction of processing while we verify a complaint or comply with a legal obligation (Article 18 GDPR).
- Data portability — receive your data in a structured, machine-readable format and transmit it to another controller (Article 20 GDPR).
- Object to processing based on our legitimate interest (Article 21 GDPR).
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3) GDPR).
- Lodge a complaint with your local data protection authority (see edpb.europa.eu for the EEA or the UK ICO).
- Automated decision-making: we do not subject you to decisions based solely on automated processing that produce legal or similarly significant effects (Article 22 GDPR).
The legal bases we rely on for processing are: (a) performance of a contract when you sign up for the dashboard or DomainGuard; (b) our legitimate interest in operating and securing the site; and (c) your consent for analytics, marketing, and any non-essential cookies (see our Cookie Policy). We respond to GDPR requests within 30 days.
International transfers: we use Cloudflare, Google, Apple, and other providers that may process your data in the United States and other countries outside the EEA/UK. Where required by GDPR, we rely on the European Commission's Standard Contractual Clauses and equivalent UK safeguards. A copy of the relevant safeguards is available on request.
10. Children's privacy
Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. We do not direct any advertising or marketing to children. The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal information from children under 13; we collect nothing of the sort. If you believe we have inadvertently collected information from a child under 13, please contact us immediately and we will delete it.
11. Third-party links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites. We encourage you to review the privacy policies of any third-party sites you visit.
12. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Your continued use of our website after changes are posted constitutes acceptance of the updated policy.
13. Contact us
If you have questions about this Privacy Policy or our data practices, please contact us:
- NHM LLC
- East Canton, OH 44730
- Email: support@nhmohio.com
- Phone: (330) 305-2750
- Web: nhmohio.com/contact
SMS and mobile messaging
If you actively opt in, NHM LLC / DomainGuard may send recurring account, support, service, security alert, and DomainGuard notification text messages to the mobile number you provide. Message frequency varies based on account activity, support interactions, and security or service events. Message and data rates may apply. Reply STOP to opt out at any time or HELP for help. SMS consent is not a condition of purchase.
When you opt in, we keep consent evidence such as the mobile number, opt-in method, timestamp, disclosure version, source, and the IP address and browser the opt-in came from, so we can document and honor your messaging choice. Consent records tied to an account are removed when that account is deleted.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile phone numbers and SMS consent information are not sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes. We may provide mobile numbers and messaging data to service providers solely as needed to deliver messages you requested and operate the messaging service.
