INTO VERIFY · PRIVACY

Privacy, plainly stated.

IntoVerify checks domain registration and DNS information when you ask it to. We do not build a search history or keep lookup reports.

Information used for a lookup

The domain you submit is sent to the registry's RDAP or WHOIS service and to the configured public DNS resolvers (Google Public DNS and Cloudflare DNS). Those services receive the domain and ordinary connection metadata needed to answer. Their own privacy and retention practices apply.

Registration responses can include contact details or other information the registry publishes. IntoVerify displays the fields returned by those sources; redactions made by a registry remain redacted.

What IntoVerify stores

IntoVerify does not store domain names, lookup responses, or a user-facing lookup history. A short-lived rate limiter stores an HMAC-protected client identifier and a request count for the current one-minute window in private server storage. It is used only to slow abusive traffic; the identifier cannot be read back as an IP address from that file.

The hosting provider may keep standard web-server access or security logs under its own settings. Domain names are submitted in the request body, not in the public page URL.

API credentials

API tokens are stored as one-way SHA-256 hashes in private server configuration. Send a token only in the HTTPS Authorization header. Never put it in a URL or browser code.

Cookies, analytics, and advertising

The lookup pages do not use advertising trackers, third-party analytics, or cookies for profiling. Browser language selection uses a URL route and does not create a preference cookie.

Planned features

Future hosting and security checks will have their own data-flow and retention description before they are enabled.