This policy describes what data trustyourinbox collects, why we collect it, who we share it with, and your rights. Plain English, no legalese theater. If something here is unclear, and we'll fix it.
Who we are
trustyourinbox is a DMARC monitoring service. We do not share data with advertisers. We do not run behavioral tracking for advertising. The product is built around the principle that what you publish in DNS is yours, and what flows through DMARC reports is yours.
What we collect
From customers who sign up:
- Account info: your email address and any name you provide, managed by Clerk (our authentication provider). We see what Clerk sees.
- Domain names you add to monitor.
- DMARC aggregate reports sent to your unique RUA address. These XML reports contain sending IPs, alignment results, and message counts: they do not contain message bodies, recipients, subject lines, or any private email content. They are themselves designed to be aggregate data only.
- Audit log entries for actions you take in the dashboard (domain added, paused, deleted, sender identified, digest preferences changed, etc.).
- Product-usage analytics, collected first-party and used only to operate and improve the product, never for advertising and never shared. For signed-in use we record which dashboard pages and features are used and by which account seat, how long a page was actually visible, the path taken between pages within one browser tab, and named interface interactions from a fixed list (for example "opened the DMARC explainer" or "copied the SPF record"). We never record what you type: no keystrokes, no free-text field contents, no search-query text, and no screen or session recording of any kind. When you search our documentation or help center we record that a search happened, how long it was and how many words, how many results came back, and which article you opened, so we can find the questions our writing does not answer. The words you searched for are never stored. Pages viewed in one visit are grouped by a random id that lives only in your browser tab and expires when you close it. We also record coarse context about the visit (device class, browser family, country, and timezone), page-speed timings, and whether a visit arrived from one of our own emails or notifications, which is marked as such. Operator staff see this data account-by-account to support you and improve the product; it is covered by our data-processing terms with your organization.
- Plan + billing info when paid tiers launch (handled by Stripe).
From anonymous visitors using our public tools:
- Domain names you paste into the DMARC audit, SPF tester, or DKIM verifier. These are public-DNS lookups; we don't store them long-term.
- IP address for rate limiting (10 audits per hour per IP). Stored in memory only, evicted within an hour.
- Aggregate page-view and tool-usage data, collected first-party on our own servers. For each page view we record the page URL, the referring site, any campaign tags in the URL, the country/region/city, timezone, and network (the autonomous-system number and operator name, which tells us datacenter traffic from human traffic) that Cloudflare derives from the request, your browser and device type, language and screen size, and how the page was used: how long it was actually visible and how far you scrolled. When you run a free tool we record which tool ran and whether it succeeded, never what you typed into it. If the address you arrived on carries an ad-platform click marker we record that the visit was an ad click, never the marker's value. We never store your IP address. Daily visitor counts use a hash that rotates every 24 hours, so it cannot identify you or follow you across days. Pages viewed in one visit are grouped by a random id that contains nothing about you and cannot connect two visits. It is held both in your browser tab and in a cookie on our own domains that expires when you close your browser, so that one visit still reads as one visit when it carries on into our app, documentation, or help center. If you sign in during that visit, we link it to your account from that moment onward, so we can tell whether the pages you read answered your question. That link is never applied backwards: anything you read before signing in stays anonymous permanently, including earlier the same day. No cross-site tracking, no advertising identifiers.
What we don't collect
- Message bodies, recipient addresses, subject lines, or any PII from inside emails.
- Tracking cookies for advertising. We set three kinds of first-party cookies: Clerk's session cookie (essential for authentication); a small "first page" cookie on the marketing site that remembers the first page and referring site that brought you here, so if you later sign up we know which content worked, which contains no identifier of any kind and expires after 90 days; and a random visit id that lets one visit read as one visit across our sites and expires when you close your browser. None are shared with third parties, and none are used for advertising.
- Third-party trackers (Google Analytics, Facebook Pixel, Mixpanel, etc.).
- Personally identifiable behavioral data linked to your identity for marketing.
Who we share it with
We use a small number of trusted vendors to operate the service:
- Clerk: authentication. Stores your email + password hash + session.
- Cloudflare: hosting, DNS, R2 (raw RUA reports for 7 days), Workers, Email Routing.
- Neon: Postgres database hosting.
- Anthropic: Claude API for plain-English summaries on dashboard pages and the AI audit. We send domain names + parsed DMARC tags, not message content. We operate under a Zero Data Retention (ZDR) agreement with Anthropic, which means Anthropic does not log or store our API inputs and outputs.
- Resend: outbound transactional email (digest reports, alerts).
- Stripe: payment processing (when paid tiers launch). They see card details; we don't.
We do not sell data. We do not share customer data with anyone outside the vendors listed above. We comply with lawful requests for data only when legally required, and will notify the affected customer unless legally prohibited.
How long we keep it
- Account data: while your account is active, plus 30 days after deletion (then permanently purged).
- Raw .eml files in Cloudflare R2: 7 days, then auto-deleted by lifecycle rule. We only persist the parsed report data, not the raw mail.
- Parsed DMARC reports: kept while your workspace is active, deleted with your workspace.
- Audit log: kept while your workspace is active.
- AI audit / SPF / DKIM tool inputs: not persisted; only the IP address is held in memory for rate limiting (max 1 hour).
- Data sent to Anthropic: not retained by Anthropic. Our Zero Data Retention agreement means API inputs and outputs are not logged or stored on Anthropic's side.
Your rights
You can do any of the following. For data access, export, deletion, or objection requests, :
- See and edit your account info via the dashboard, or ask us to.
- Export your data: we'll provide a JSON export within 7 days of your request.
- Delete your account at any time. Soft-deleted domains are hard-purged after 7 days; account data is purged after 30 days.
- Object to specific data uses.
Residents of the EU/UK have the rights described under GDPR (access, rectification, erasure, portability, objection). California residents have rights under CCPA. We treat all customers to the higher of any applicable standard.
Children
trustyourinbox is intended for business use. We do not knowingly collect data from anyone under 13. If you believe a child has signed up, and we'll delete the account.
Changes to this policy
If we materially change what we collect or how we use it, we'll email customers in advance and update the "Last updated" date at the top. Material changes apply only prospectively.
Contact
Questions, requests, or concerns? . We reply within 2 business days.
See also: Terms of Service · Acceptable Use Policy · Security.