guides

Privacy and data handling

What isBusinessEmail stores when you check an address (domain and an HMAC, never the full email), retention, EU hosting, processors and your obligations.

View as Markdown

You send us your users’ email addresses. Here’s exactly what happens to them. The legal version is in the Privacy Policy and the DPA.

What we store per check

Data Stored? Where and how long
Full email address Never Processed in memory to compute the verdict, then discarded. Logs redact it.
Domain (acme.io) Yes Domain records (verdict, DNS signals, lookup counts) to cache and improve verdicts
Local part (jane) Only as an HMAC A keyed hash (HMAC with a secret pepper) feeds a probabilistic counter of distinct users per domain. It can’t be reversed or listed.
Request analytics Yes, 90 days Account, key ID, domain, category, cached or not, status, latency, and the network (ASN) and country of the calling server. No email addresses.
Your recent requests Yes, rolling The last 1,000 requests per account, domain only, for your dashboard
Daily usage counters Yes Per account and category, for quotas and charts
Feedback reports Yes Domain, expected category, your comment

The crowd counter is how we notice a domain that behaves like a shared provider: many distinct local parts, from many unrelated customer accounts. It only ever flags a domain for human review.

Why POST

Use POST /v1/check with a JSON body. With GET, addresses land in URLs, and URLs get logged by proxies, load balancers, CDNs and browser history: places neither of us controls. Our own logs redact email, Authorization, X-API-Key and cookies either way.

Where data lives

  • API and website: Cloudflare’s global edge network. Requests are processed at the data center nearest the caller.
  • Database: Postgres on Hetzner in the EU (Germany/Finland), reachable only through an encrypted tunnel, with no public ports. Backups stay on Hetzner, encrypted, kept 30 days.
  • Processors: Cloudflare (hosting, edge, DNS-over-HTTPS), Hetzner (database), Brevo (account emails), Google and Microsoft (sign-in; Google Analytics 4 on the website only with consent), and Slack for internal notifications about new accounts (account holders only, never checked addresses). The current list is on Subprocessors.

DNS and enrichment lookups

To classify a domain we query public DNS over HTTPS (Cloudflare 1.1.1.1, falling back to Google Public DNS), Microsoft’s public discovery endpoints, and with deep=true RDAP and the domain’s homepage. These requests carry the domain only. Microsoft’s home-realm lookup uses a placeholder username, never your user’s address.

Blocklist matches

is_blocked comes from blocklists our admins maintain after reviewing spam and abuse reports and verdict feedback. Blocked addresses are stored only as SHA-256 hashes. Exact-address matches (blocked_email) are returned to secret-key holders only, sweeps of one domain are flagged, and the hash list is never exported or published.

No mailbox probing

We don’t connect to your users’ mail servers, don’t send RCPT TO probes, and don’t ask Google or Microsoft whether a particular person has an account. That’s user enumeration: it breaks provider terms and tells third parties that someone signed up somewhere.

Your side of it

Under the GDPR, for the addresses you check you’re typically the controller and we act as your processor for producing the verdict. That means:

  • Have a legal basis to check signup emails (fraud prevention and service eligibility usually rest on legitimate interests) and mention the check in your privacy notice.
  • Our verdicts are informational. You decide what to do with them, and you stay responsible for decisions about your users. If a check can block someone from your service, give them a way to reach a person.
  • Need a Data Processing Agreement? Our DPA is available; email privacy@isbusinessemail.com.

Questions or a data request: privacy@isbusinessemail.com.