Privacy Policy
Last Updated: August 3, 2026
This Privacy Policy explains how domaindetails.com ("we," "us," or "our") collects, uses, and protects your information when you use our service.
🔒 Privacy First Commitment
What We Don't Do:
- ✗Sell personal data or use it for targeted advertising
- ✗Collect your complete browsing history through the browser extension
- ✗Run an always-on browser-extension content script
What We Do:
- ✓Process the domain queries you explicitly request
- ✓Store limited local history and service records as described below
- ✓Use contracted service providers with appropriate safeguards
1. Information Collection
1.1 Free Visitors and Account Users
For users of our free service:
- Ordinary domain lookup history is stored locally in your browser
- If you create an account, we store the account identifiers needed to provide it
- If you use your free watched domain, we store that domain, its monitoring history, and your alert preferences on our servers
- Anonymous analytics data is collected via PostHog
- Technical error data may be collected via Sentry for service improvement
- Marketplace searches and result summaries may be stored for service analytics, reliability, and abuse prevention as described in Section 8
1.2 Domain Details Alerts Subscribers
For users with a paid subscription, we may collect:
- Email address for account management and communications only when you choose to create or use an account
- Subscription and transaction identifiers supplied by Stripe, Apple, or Google; we do not receive your full payment-card details
- Domain monitoring preferences and settings
- Usage data for service optimization
- Cross-device synchronization data when you choose to link an account
App Store and Google Play customers can purchase and use Alerts through a pseudonymous guest session without providing a name, email address, password, or social-login profile. Creating or linking an account is optional and enables cross-device access.
2. Use of Information
We use collected information for the following purposes:
- Providing and maintaining our service
- Processing payments and managing subscriptions
- Sending essential service notifications
- Improving and optimizing our service
- Responding to your requests and support inquiries
- Preventing fraud and abuse
3. Third-Party Service Providers
We use the following third-party services to operate our platform:
3.1 Essential Services
- Stripe: Payment processing and subscription management
- Apple App Store and Google Play: In-app payment processing and subscription management
- PostHog: Privacy-focused product analytics, error tracking, and user experience optimization (see Section 3.2)
- Cloudflare: Content delivery, request routing, security, rate limiting, and the browser extension registration-lookup Worker
- Sentry: Technical error diagnosis for supported product surfaces
- MailLayer: Transactional and optional lifecycle email delivery for account, product, Academy, newsletter, and Domain Details Alerts messages
All third-party services are GDPR-compliant and operate under strict data processing agreements to ensure the security and confidentiality of your data.
3.2 Analytics and Privacy
PostHog Analytics
We use PostHog to understand how users interact with our service and to improve user experience. Our PostHog implementation:
- ✗Does NOT track: The actual domain names you search for
- ✓Does track: Anonymous usage patterns, feature usage, page views, and performance metrics
- â—†Purpose: To improve our service, fix bugs, and understand which features are most valuable
- â—†Data sharing: Analytics are disclosed to PostHog as our contracted processor; they are not sold or shared for advertising
- â—†Data location: Analytics data is processed in the EU
PostHog product-analytics events do not include searched domains. A domain may appear in a technical error report or in the marketplace service records described in Section 8.
3.3 MCP Server Privacy
Our free Model Context Protocol (MCP) server at mcp.domaindetails.com:
- Does NOT store domain queries beyond temporary caching for performance
- Does NOT collect or store personal information about API users
- May log IP addresses temporarily for abuse prevention and rate limiting
- Operates with the same privacy-first principles as our main service
4. Data Protection
4.1 Security Measures
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Secure data backup procedures
4.2 Data Retention
We retain your data only for as long as necessary to:
- Provide our services to you
- Comply with legal obligations
- Resolve disputes
- Enforce our agreements
5. Your Privacy Rights
Under applicable data protection laws, you have the following rights:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
6. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer data:
- We use appropriate safeguards such as Standard Contractual Clauses
- We ensure adequate levels of protection for your personal data
- We comply with applicable data transfer regulations
7. Cookies and Tracking
Our approach to cookies and tracking is minimal:
- We do not use tracking cookies
- Essential cookies are used only for pro account functionality
- Analytics are collected anonymously without personal identification
- You can control cookie settings through your browser
8. Browser Extension: Collection, Handling, Storage, and Sharing
This section applies to Domain Details - RDAP, WHOIS & Marketplace Search for Chrome (item ID ceoknmdcolcpjnadklohkhjgoghnafmm) and the equivalent Domain Details extensions for Edge, Firefox, Safari, and other supported browsers.
8.1 Activation and Permissions
The extension activates only after you open its toolbar popup or choose its context-menu command. It does not run an always-on content script. Its permissions are used as follows:
- activeTab: read the active tab URL after you open the extension so it can identify a domain candidate
- scripting: read limited page metadata such as a canonical URL, Open Graph URL, heading, or title only when a marketplace URL does not identify the offered domain
- contextMenus: provide an explicit right-click domain lookup command
- storage: save preferences, identifiers, a short-lived access token, and observed lookup summaries in browser-managed extension storage
8.2 Data Collection
Depending on the feature you choose, the extension collects or processes:
- Requested domain or search term: the registrable domain detected from the active tab, selected through the context menu, or entered manually, but only when you request a registration or marketplace lookup
- Limited page metadata: canonical URL, Open Graph URL, heading, and title may be read locally to identify a domain on a marketplace page; the raw metadata is not sent to Domain Details or analytics
- Lookup results: public RDAP/WHOIS registration data and marketplace result data needed to display the requested response
- Local history: the domain, lookup time, lookup method, availability, and changed summary fields such as registrar, dates, status, nameservers, and DNSSEC
- Pseudonymous technical identifiers: a random installation analytics ID when analytics are enabled, a separate random request/rate-limit ID, and a short-lived signed gateway token
- Optional usage analytics: browser and extension version, feature used, general detection method, success or failure, coarse result counts, duration, and analytics preference changes
- Network and security metadata: service infrastructure and processors may temporarily process IP address, user agent, request time, and Cloudflare request identifiers for delivery, security, rate limiting, and troubleshooting
8.3 How We Handle and Use Extension Data
- A registration lookup sends the requested domain over HTTPS in a POST body to
ext.domaindetails.com. The Worker sends that domain to the relevant public RDAP service or WHOIS server and returns the response to the extension. - A marketplace search sends the requested domain over HTTPS to
api.domaindetails.com. Our service queries supported marketplace providers and returns the result summary. - The random request ID and signed gateway token are used to assign request capacity, prevent abuse, and keep extension traffic separate from general public traffic. They are not linked to a Domain Details account.
- If analytics are enabled, allowlisted events are sent to PostHog EU through our first-party proxy at
f.domaindetails.comto measure feature reliability and improve the extension.
8.4 Storage and Retention
- On your device: browser-managed extension storage keeps up to 20 changed summary snapshots per domain, analytics preference and onboarding state, the pseudonymous identifiers, and any unexpired gateway token. Domain history remains until you clear it for that domain or remove the extension; removing the extension deletes its browser-managed storage.
- Registration lookups: the
ext.domaindetails.comWorker has no KV, D1, analytics dataset, or application database and does not store lookup results. Its rate-limit state is ephemeral. Infrastructure security logs may be retained temporarily by Cloudflare under its operational retention practices. - Marketplace searches: Domain Details stores the requested domain, TLD, result summary, timestamp, traffic classification, and a pseudonymous hashed client classification in its application database for service analytics, reliability, and abuse prevention. These records are not linked to a Domain Details account and are retained only while needed for those purposes, after which they are deleted or aggregated.
- Usage analytics: PostHog stores the allowlisted event data under our configured analytics retention controls. Turning analytics off stops future extension events; it does not automatically delete events already received.
8.5 Data Sharing
We disclose extension data only as needed to provide, secure, and improve the requested features:
- Cloudflare processes requests, security metadata, and rate-limit state for our first-party endpoints.
- Public RDAP operators and WHOIS servers receive the requested domain to provide registration data.
- Supported marketplace providers receive the requested domain as necessary to search their listings.
- PostHog receives the allowlisted pseudonymous usage events only when analytics are enabled.
We do not sell extension data, use it for targeted advertising, or disclose it to data brokers. Service providers process data on our behalf or as necessary to answer the lookup you requested.
8.6 Data We Do Not Collect or Share
The extension does not collect your complete browsing history, run on every page in the background, or transmit complete source-page URLs, page titles, page contents, raw locally observed history, authentication information, financial information, personal communications, or precise location. Extension analytics never include searched domains, marketplace provider names, raw WHOIS/RDAP data, registration contact data, or Domain Details account identifiers. PostHog person profiles are disabled for extension events.
8.7 Your Controls
Before any optional analytics event is sent, the first-run screen presents the analytics choice. It is enabled by default on supported stores, but you can turn it off before continuing or later in the popup's Privacy control. You can clear locally observed history for each domain in the popup. To request access to or deletion of server-held data where applicable, email privacy@domaindetails.com; include the relevant domain, approximate request date, and browser extension so we can locate the record without asking for unrelated information.
9. Children's Privacy
Our service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
10. Changes to Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on our website
- Sending an email to pro subscription users
- Displaying a notice in our service
11. Contact Information
For privacy-related inquiries or to exercise your rights, please contact us at:
- Email:privacy@domaindetails.com
- Response time:Within 72 hours