Privacy Policy

Last updated 2026-09-04

RDAPWatch checks the public DNS, TLS and registration configuration of domains. Most of what the service handles is public infrastructure data, not personal data. This page describes exactly what we do store about you.

What we collect

What we do not collect

Running a check on a domain you don't own

Every check reads only publicly published records — DNS, the certificate a server presents, RDAP registration data, and public DNS blocklists. Report pages are public and may be indexed by search engines, so treat a report URL as public. If a report about a domain you control should not be public, email us and we will remove it and block it from being regenerated.

How long we keep things

Who else processes this data

Your choices

You can see everything we hold about you from your dashboard, remove any monitored domain at any time, and delete your account — which erases your email, domains, check history and alerts. Alert emails relate to a service you asked for; to stop them, remove the domain or close the account. For access, correction, export or deletion requests, email privacy@rdapwatch.com and we will respond within 30 days.

Children

The service is for domain owners and operators and is not directed at children under 16.

Changes

If this policy changes materially we will update the date above and, for account holders, say so by email before the change takes effect.

This policy describes our actual practices in plain language. It is not legal advice; if you need a policy audited against a specific regime (GDPR, CCPA, or your own DPA), have a lawyer review it.