Privacy Policy

Last updated: July 6, 2026

This Privacy Policy explains what information EmailControl ("we", "us", "our") collects when you use emailcontrol.net (the "Service"), why we collect it, how we use and protect it, and the choices you have. The short version: we collect the minimum needed to run a monitoring service, we do not sell your data, and the list of domains you monitor is treated as confidential business information.

What Information Do We Collect?

Account information. When you create an account we collect your email address, your name if you provide one, and a hashed version of your password. We never store passwords in plain text — they are hashed with bcrypt, an industry-standard one-way algorithm, and cannot be recovered by us or anyone else.

Monitoring data. The core of the Service is the list of domains you ask us to monitor and the results of the checks we run against them: blacklist query outcomes, SPF/DKIM/DMARC record contents and statuses, computed health scores, and the timestamps of each check. Note that the DNS records we read are already public — anyone on the internet can query them — but the fact that you monitor a particular set of domains is not public, and we treat that association as confidential.

Payment information. Paid subscriptions are processed by Stripe. Your card number never touches our servers; we store only Stripe's customer and subscription identifiers so we can associate your account with your plan. Stripe's handling of your payment details is governed by Stripe's privacy policy.

Technical logs. Like nearly every web service, our servers record IP addresses and request metadata for security and troubleshooting. We also record failed login attempts (IP address and attempted email) for a maximum of 24 hours to enforce rate limiting against brute-force attacks.

How Do We Use Your Information?

We use your information to operate the Service: running scheduled checks on your domains, sending you alert emails when something breaks, showing you dashboards and history, processing subscription payments, and responding when you contact support. We may send occasional product update emails to account holders; every such email includes a way to opt out. We do not sell, rent, or trade your personal information, and we do not share your monitored-domain list with advertisers or data brokers.

What Cookies Do We Use?

We use a single first-party session cookie (ec_session) to keep you logged in; it is flagged HttpOnly, Secure, and SameSite=Strict. A small localStorage flag remembers that you dismissed the cookie notice. If we display advertising through Google AdSense, Google and its partners may set cookies to serve ads; you can control personalized advertising at Google Ads Settings.

Who Do We Share Data With?

Only the processors required to run the Service: our hosting provider (server infrastructure), Stripe (payments), and our transactional email provider (alert delivery). Each receives only what it needs to perform its function. We will disclose information if required by law, court order, or to protect the security of the Service and its users.

How Long Do We Keep Data?

Check history is retained for your plan's history window (7 days to 1 year). Account data is kept while your account is active. If you delete your account, your domains, check history, and alerts are deleted with it (database constraints cascade the deletion). Backup copies age out of our backup rotation within 30 days.

What Are Your Rights?

You can access and update your account details from the dashboard at any time. You can request a copy of the data we hold about you, or request deletion of your account and associated data, by contacting us via the contact page. If you are in the EU/EEA, UK, or California, you may have additional statutory rights (access, rectification, erasure, portability, objection); we honor these requests regardless of where you live.

Security

Passwords are bcrypt-hashed, sessions use hardened cookies, all database access uses parameterized queries, API keys are stored only as SHA-256 hashes, and secrets are kept outside the web root with restrictive file permissions. No internet service can promise perfect security, but we build with the assumption that every layer must fail safely.

Changes to This Policy

If we make material changes, we will update the date at the top of this page and, for significant changes, notify account holders by email. Continued use of the Service after changes take effect constitutes acceptance.

Contact

Questions about this policy or your data? Reach us through the contact page and we'll respond within one business day.