Privacy Policy
Last updated: August 14, 2026
1. Overview
HM Domains is committed to protecting your privacy. We believe in minimal data collection and only process the essential information required to operate our DNS provisioning infrastructure and authenticate developer accounts.
2. Information We Collect
When you authenticate and use HM Domains, we collect:
Public GitHub username, avatar URL, and user ID provided via Firebase OAuth.
Registered domain names, DNS records (A, CNAME, TXT, MX, NS), and TTL configs.
Anonymized server telemetry (IP, timestamp, latency) for DDoS filtering and uptime monitoring.
3. How We Use Your Information
We use the collected information exclusively to:
- Verify developer accounts and prevent bot-driven domain hoarding.
- Create, sync, and maintain DNS records on Cloudflare Anycast edge nameservers.
- Enforce quota limits (maximum domains per user) in Google Cloud Firestore.
- Respond to abuse, copyright infringement, or security inquiries.
4. Infrastructure Providers
We partner with enterprise cloud providers to deliver high-availability services:
- Cloudflare Inc: For global Anycast authoritative DNS hosting, DDoS mitigation, and SSL edge termination.
- Google Firebase / GCP: For secure OAuth authentication and Firestore database storage.
- Vercel Inc: For serverless application hosting and SSR compute.
5. Data Retention & Deletion
Your DNS records and account metadata are retained for as long as your domains remain active. When you delete a domain from the console, its corresponding DNS records are immediately deleted from Cloudflare and purged from our database.
