Privacy Policy

Last updated: September 9, 2026

DNS Kit ("we", "our", or "us") is operated by Becoming Ventures LLC. This Privacy Policy explains how we handle information when you use the DNS Kit mobile app and website (collectively, the "Service"). We are committed to protecting your privacy and being transparent about our practices.

Accounts and Monitoring

Manual diagnostic tools do not require a permanent account. Mobile monitoring uses a Firebase account identifier, which may initially be anonymous. If you sign in, we store your account email and name when supplied by your sign-in provider. We store monitored domains, check configurations, saved monitoring results, notification preferences and registered push tokens to run background checks and deliver alerts.

How the Service Works

DNS Kit performs DNS lookups, email health checks, propagation monitoring, and related diagnostic queries in real time. When you submit a query, the domain or hostname you enter is sent to our API servers and to third-party DNS resolvers to generate results. Results are returned to you in real time. For aggregate usage statistics we store a one-way hash of the domain, a one-way hash of your device's attestation identifier, the tool used, the record type, your platform and country. Raw domains and IP addresses are not stored in these usage statistics. Domains you choose to monitor are stored separately for background checks. Analytics events sent to Firebase and PostHog carry the same hashed domain reference rather than the domain. Session replays (see below) show the screen as you saw it, so they can include the domain you entered and the results returned for it.

Usage Analytics and Diagnostics

We collect usage events and diagnostics to understand tool usage, investigate errors and improve the Service. These may include your device or installation identifier, session identifier, device and app version, approximate country, interactions, crash reports and performance information. Analytics services can associate events with the same device or session. These records are pseudonymous, not necessarily anonymous; aggregate reports are derived from them. We do not use this information for targeted advertising or sell it to data brokers.

To diagnose usability problems we record session replays of app and website interactions, including taps, scrolls and navigation. Domains, lookup results and other visible diagnostic content may appear in replays. We mask account details in the mobile account screen and password, email and contact form inputs on the website. Replays may be associated with a pseudonymous device or session identifier.

Local Storage

DNS Kit stores your recent searches, scan history, and preferences locally on your device. You can clear this local history through the app settings. Queries are still sent to the services described above, and content displayed on screen may appear in session replays. Cloud monitoring records and analytics are separate from local history; clearing local history does not delete those server records.

Device Attestation

To prevent abuse and ensure fair access to the Service, we use platform-provided device attestation mechanisms (Apple App Attest on iOS, Google Play Integrity on Android, and Cloudflare Turnstile on the web). These services verify that requests come from legitimate app installations and real devices. The attestation produces a per-installation identifier that we use to issue a short-lived session token and, in hashed form, to count usage per device and detect abuse. It is not linked to your name, email or any account.

Subscriptions

When subscription purchasing is available, RevenueCat processes store transaction information using your Firebase account identifier to verify and restore Pro access. Our backend stores your verified plan, entitlement expiration and last verification time. Apple or Google handles payment; DNS Kit does not receive your card details. We do not send monitored domains or diagnostic findings to RevenueCat.

Third-Party Services

DNS Kit relies on the following third-party services to function:

Each of these services has its own privacy policy governing how they handle data.

Delete Your DNS Kit Account and Data

Request deletion in the app under Settings → Delete account and cloud data, or use our account deletion request form without reinstalling the app. Include your account email or account identifier. We verify ownership before removing your authentication account, monitors, stored monitoring results, notification preferences and push registrations. You may also request deletion of specific data without deleting your account.

This is a manually processed request; submitting it does not immediately delete your account. We confirm completion after ownership verification. We also request removal of associated records held by our service providers where they can be identified. Transaction records required for legal or accounting obligations may be retained for the applicable statutory period. Apple and Google control their own purchase records. Deleting your DNS Kit account does not cancel a store subscription; manage renewal in Apple or Google Play separately. Local history can be cleared in the app settings.

Data Security

All communication between your device and our servers is encrypted using TLS. API requests are authenticated and signed to prevent tampering and replay attacks. We follow industry best practices to keep the Service secure.

Children's Privacy

DNS Kit is not directed at children under 13. We do not knowingly collect any information from children under 13. If you believe a child has provided us with information, please contact us and we will promptly address it.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this page periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy, please contact us at [email protected].