# Privacy and data handling

> What isBusinessEmail stores when you check an address (domain and an HMAC, never the full email), retention, EU hosting, processors and your obligations.

Source: https://isbusinessemail.com/docs/privacy-and-data

You send us your users' email addresses. Here's exactly what happens to them. The legal version is in the [Privacy Policy](https://isbusinessemail.com/privacy) and the [DPA](https://isbusinessemail.com/dpa).

## What we store per check

| Data | Stored? | Where and how long |
|---|---|---|
| Full email address | **Never** | Processed in memory to compute the verdict, then discarded. Logs redact it. |
| Domain (`acme.io`) | Yes | Domain records (verdict, DNS signals, lookup counts) to cache and improve verdicts |
| Local part (`jane`) | Only as an HMAC | A keyed hash (HMAC with a secret pepper) feeds a probabilistic counter of distinct users per domain. It can't be reversed or listed. |
| Request analytics | Yes, 90 days | Account, key ID, domain, category, cached or not, status, latency, and the network (ASN) and country of the calling server. No email addresses. |
| Your recent requests | Yes, rolling | The last 1,000 requests per account, **domain only**, for your dashboard |
| Daily usage counters | Yes | Per account and category, for quotas and charts |
| Feedback reports | Yes | Domain, expected category, your comment |

The crowd counter is how we notice a domain that behaves like a shared provider: many distinct local parts, from many unrelated customer accounts. It only ever flags a domain for human review.

## Why `POST`

Use `POST /v1/check` with a JSON body. With `GET`, addresses land in URLs, and URLs get logged by proxies, load balancers, CDNs and browser history: places neither of us controls. Our own logs redact `email`, `Authorization`, `X-API-Key` and cookies either way.

## Where data lives

- **API and website:** Cloudflare's global edge network. Requests are processed at the data center nearest the caller.
- **Database:** Postgres on Hetzner in the EU (Germany/Finland), reachable only through an encrypted tunnel, with no public ports. Backups stay on Hetzner, encrypted, kept 30 days.
- **Processors:** Cloudflare (hosting, edge, DNS-over-HTTPS), Hetzner (database), Brevo (account emails), Google and Microsoft (sign-in; Google Analytics 4 on the website only with consent), and Slack for internal notifications about new accounts (account holders only, never checked addresses). The current list is on [Subprocessors](https://isbusinessemail.com/subprocessors).

## DNS and enrichment lookups

To classify a domain we query public DNS over HTTPS (Cloudflare 1.1.1.1, falling back to Google Public DNS), Microsoft's public discovery endpoints, and with `deep=true` RDAP and the domain's homepage. These requests carry the **domain only**. Microsoft's home-realm lookup uses a placeholder username, never your user's address.

## Blocklist matches

`is_blocked` comes from blocklists our admins maintain after reviewing spam and abuse reports and verdict feedback. Blocked addresses are stored only as SHA-256 hashes. Exact-address matches (`blocked_email`) are returned to secret-key holders only, sweeps of one domain are flagged, and the hash list is never exported or published.

## No mailbox probing

We don't connect to your users' mail servers, don't send `RCPT TO` probes, and don't ask Google or Microsoft whether a particular person has an account. That's user enumeration: it breaks provider terms and tells third parties that someone signed up somewhere.

## Your side of it

Under the GDPR, for the addresses you check you're typically the **controller** and we act as your **processor** for producing the verdict. That means:

- Have a legal basis to check signup emails (fraud prevention and service eligibility usually rest on legitimate interests) and mention the check in your privacy notice.
- Our verdicts are **informational**. You decide what to do with them, and you stay responsible for decisions about your users. If a check can block someone from your service, give them a way to reach a person.
- Need a Data Processing Agreement? Our [DPA](https://isbusinessemail.com/dpa) is available; email [privacy@isbusinessemail.com](mailto:privacy@isbusinessemail.com).

Questions or a data request: [privacy@isbusinessemail.com](mailto:privacy@isbusinessemail.com).
