Privacy statement
We keep DNS records correct. That needs surprisingly little personal data, and this page says exactly which.
Last updated 2026-08-01
This page is incomplete.
Missing operator details: legal entity name, registered address and Chamber of Commerce number. Set the matching
LEGAL_* environment variables before going live.
What we store
When you check a domain
Anyone can check a domain without an account. For each check we store the domain name, its published SPF record, and the analysis we derived from it. That information is not personal data: it comes from public DNS and belongs to the domain, not to you.
We do not store the IP address of the person running the check. We store a keyed one-way hash of it, which we use only to spot abuse of the free checker and to enforce rate limits. It is never linked to an account, and it is deleted after 90 days while the report itself stays.
Reports are reachable at a public URL, listed at /reports and included in our sitemap, so search engines can find them. If you run a domain and would rather it were not listed, you can remove it yourself by publishing a TXT record we give you — or, if the domain is in your account, from the domain's own page.
When you have an account
- Your account: name, email address, password hash, and any passkeys or two-factor secrets you register.
- Your domains: the domains you added, their SPF records past and present, the flattened records we publish for them, and the change history.
- Your subscription: plan, billing status and invoice history. Card details never reach our servers; Stripe holds them.
- Operational logs: sign-ins, DNS changes we detected, and emails we sent you.
Why we are allowed to store it
Account and domain data is processed to perform the contract you entered into when you signed up. The hashed IP address and our server logs are processed on the basis of our legitimate interest in keeping the service available and free of abuse. Analytics cookies are set only after you consent, and you can withdraw that consent at any time.
How long we keep it
- Reports for domains checked without an account: kept, because the report is a URL people share and search engines index. Re-checked when someone visits an old one.
- The hashed visitor address on a report: 90 days, then removed from the report.
- Domains in an account: for as long as the domain is in the account, plus the change history we need to show you what we published and when.
- Account data: until you delete your account, after which it is removed within 30 days.
- Invoices: seven years, because tax law requires it.
Who processes data on our behalf
| Processor | What for | Where |
|---|---|---|
| Stripe | Payments and invoicing | EU / US |
| Resend | Transactional email | EU / US |
| TransIP | Publishing the DNS records we manage for you | Netherlands |
| Google Analytics | Website statistics, only with your consent | EU / US |
| CookieYes | Recording your cookie choice | EU |
| Anthropic | Naming the mail provider behind an SPF include | US |
Only the include hostname is sent for provider identification — for example
_spf.example-vendor.com. That is a public DNS name, never an
account, an email address or a customer domain.
Your rights
You can ask us for a copy of your data, correct it, delete it, or object to how we use it. Write to privacy@flat-spf.com and we will answer within a month. If you are not satisfied, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Cookies
Which cookies we set, and how to change your choice, is on the cookie page.