Privacy
What we collect, why we collect it, how long we keep it, and how to take it back.
Last reviewed 2026-08-21
The short version
DomainOverseer stores the domains you add, the read-only connections you authorize, and normalized measurements from those connections. It does not store email bodies, attachments, raw visitor addresses, or a visitor identity that follows people between sites. You can export everything or delete the workspace at any time, on any plan.
What we collect
Account data
Your email address, display name, sessions, and, if you turn it on, an encrypted two-step verification secret and hashed recovery codes. Used to sign you in and to send essential account notices.
Workspace and membership data
The workspace name, timezone, member roles, invitations, and an audit history of the actions that change access, connections, billing, or data.
Domain inventory
The domains you add, their tags and notes, registrar and renewal information where a registry publishes it, and the results of the public checks we run.
Provider credentials
Access and refresh tokens for the connections you authorize, encrypted before storage and bound to the record they belong to. Deleted when you disconnect a provider.
Measurements
Normalized counts and states from the providers you connect, each stored with its source, the exact period it covers, and whether it was partial or sampled. Search Console query and page rows are stored where you have Search Console connected.
Mail information
DNS records that describe mail configuration for every domain. Where you connect Cloudflare Email Routing, routing counts and status. Where you map a Gmail label, the total and unread count of that label. No message content, in any mode.
Billing references
Identifiers for your customer and subscription with our payment processor, the plan you are on, and invoice status. Card details never reach our servers: payment is handled on the processor's own hosted pages.
Diagnostics
Structured operator logs recording what ran, how long it took, and a safe result code. These deliberately exclude tokens, cookies, addresses, search queries, email subjects, domain notes, and provider payloads.
How long we keep it
- Measurements: 30 days on Free, 13 months on Pro, 25 months on Studio.
- Provider credentials: while the connection is active, then deleted promptly after you disconnect.
- Diagnostics: 30 days, unless a specific security investigation requires a documented hold.
- Raw provider payloads: not retained.
- Sensitive mail metadata: off by default. If it is ever enabled, for the shortest declared period.
- Audit history: 12 months on paid plans, shorter on Free unless a legal or security need applies.
A provider's own retention can be shorter than ours. Where that leaves a gap, we show it as a gap rather than filling it in.
Product analytics
We use first-party analytics on domainoverseer.com to understand which parts of the product get used. Authenticated addresses are reduced to route templates before anything is sent, and the payload never contains a domain name, a workspace name, a search query, an email address, a provider identifier, a resource identifier, or a one-time token. There are no open-tracking pixels in our operational email, and provider open events are not used as a success measure.
Google user data
DomainOverseer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data received from Google APIs is used only to provide the features you switched on. It is never used for advertising, never sold, and never used to train a model, including any generalized or non-personalized model. It is not transferred to anyone except the infrastructure providers listed on our subprocessors page, and only as needed to run the service or as required by law. No human at DomainOverseer reads it, except where you have given explicit permission for a specific support request, where it is necessary for security purposes such as investigating abuse, or where the law requires it.
Specifically, DomainOverseer reads Google Search Console performance totals and Google Analytics reporting figures for the properties you map, and uses them only to display and compare your own portfolio inside your workspace. It never writes to a Google property, never changes a setting, verification, ownership, sitemap, or indexing request, and never requests a Gmail scope on this connection. You can revoke our access at any time from your Google account, and ourexport and deletion page explains how to remove what we already hold.
Your choices
- Export your workspace data at any time, on any plan.
- Disconnect any provider, which deletes its stored credentials.
- Choose whether normalized history is kept after a disconnection.
- Turn operational alert email and portfolio briefs on or off per person.
- Delete the workspace, which removes tenant data after any renewable subscription is confirmed cancelled.
Essential messages, such as sign-in links, invitations, security notices, deletion updates, and required billing notices, are not subject to those preferences. Turning off optional mail never turns those off.
Contact
Privacy questions go to support@domainoverseer.com. Security reports go to security@domainoverseer.com.