Privacy policy

Last updated 2026-09-21

AstraVerify checks public DNS records and public web pages. Most of what it handles is public data about domains, not about people. This page lists the personal data it does collect, why, where it goes and for how long. Last updated 21 September 2026.

Who is responsible

AstraVerify (astraverify.com) is the controller of the data described here. Contact: [email protected]. There is no account system and no password; the site works without signing in.

What we collect and why

  • The domain you enter, and the public facts found for it (DNS records, status codes, headers, tag values, robots.txt rules). Purpose: producing the scores and recommendations, and caching them so a repeat visit does not scan the domain again. Scan results for a domain are visible to anyone who opens that domain’s result link; they contain public data only.
  • Your IP address and browser user-agent string with each request, including with each scan you run. Purpose: rate limiting, abuse prevention and diagnosing faults. They are never shown on result pages.
  • Your email address, when you ask for an emailed report, request a link to your page, send a fix request, or pay for a service. Purpose: delivering what you asked for and, for customers, giving you access to your history and orders. If you tick the marketing box on the report form we may email you about AstraVerify; every such email has an unsubscribe link and we do not sell or share the list.
  • The headers of a test email you choose to send us for the live DKIM check. Purpose: identifying the selector and signing configuration in use. We keep the parsed findings, not the message body.
  • Payment details are entered on Stripe’s checkout page and go to Stripe, not to us. We receive your email address, the amount, the package and Stripe’s customer and subscription identifiers. We never see card numbers.
  • If you create an API key on your page, we store a hash of it (not the key), the label you gave it and when it was used. Requests made with a key are attributed to your email address.
  • If you use AstraVerify through an AI assistant (MCP or the JSON API), we receive the domain the assistant asked about and the assistant’s IP address and user-agent string. We do not receive your conversation.

What we do not collect

No cookies are set for visitors and no advertising or fingerprinting scripts run on the site. Cloudflare Web Analytics gives us page-level visit counts without cookies or personal identifiers. The optional PageSpeed panel calls Google’s PageSpeed Insights API directly from your browser with the domain being checked; its result is cached in your browser’s session storage only. The staff area at /admin uses one session cookie for staff sign-in and is not part of the public site.

Where data is stored and who else processes it

  • Google Cloud (Firestore and Cloud Run, region us-central1, United States): all stored data and the servers that run scans.
  • Firebase Hosting and Cloudflare: serve the website and protect it from abuse; Cloudflare sees the IP addresses of visitors as any CDN does.
  • Stripe: payments, receipts, invoices, subscription management and the customer portal, under Stripe’s own privacy policy.
  • Google (Gmail SMTP): sends our transactional email, including reports, links to your page, order confirmations and monitoring alerts.
  • Google PageSpeed Insights: called from your browser, not our servers, when you open the PageSpeed panel.
  • We do not sell personal data and do not share it with anyone else. We disclose data only when the law requires it.

How long we keep it

  • Scan history (domain, scores, facts, requesting IP and user agent): 12 months, deleted automatically.
  • Request logs (IP, path, user agent): 30 days, deleted automatically.
  • Live email check findings: 30 days, deleted automatically.
  • Cached results per domain: replaced by the next scan of that domain; a domain can be excluded on request.
  • Emailed-report requests, fix requests, orders and monitoring history: for as long as the service relationship lasts, plus what tax and accounting law requires for payment records. Monitoring keeps the last 12 runs per domain.
  • API keys: until you revoke them on your page.

Your rights

You can ask us to show you, correct or delete the personal data we hold about you, to stop marketing email, or to exclude a domain from scanning altogether. Write to [email protected] from the address concerned; we answer within 30 days and usually much sooner. If you are in the EU, UK or a similar jurisdiction you also have the right to complain to your data-protection authority. We rely on your request as the basis for processing when you ask for a report, link or service, on the contract when you buy something, and on our legitimate interest in running a reliable, abuse-free service for the request logs and rate limiting.

Children

The service is for people who run domains and websites and is not directed at children under 16. We do not knowingly collect their data.

Changes

When this policy changes, the date at the top changes with it. Material changes that affect customers are also announced by email.

Contact

[email protected]