Privacy Policy

Last updated: September 30, 2026

Who We Are

DomainLens Pro ("the app") is operated by Aegyrix LLC ("we", "us", "our"), a Pennsylvania limited liability company. Aegyrix LLC is the data controller for the limited personal data described below. Contact: domainlenspro.com/support.

Summary

What the App Collects

Domain queries you scan are sent from your device directly (or via our scan backend) to public services so we can return results. The only data transmitted is the domain, IP, or URL you choose to scan. We do not record what you scan unless you are signed in and choose to save scan history.

Optional sign-in. If you choose to sign in, the app supports five methods: Sign in with Apple, Google, Microsoft, GitHub, and email one-time code (a 6-digit code sent to the address you enter — no password). You only ever use one. Whichever you choose, the only personal data we receive and store is the email address and display name returned by that provider, plus an opaque provider-issued user identifier so we can recognize you on next sign-in. We do not collect or store passwords. We do not request access to your contacts, calendar, files, social graph, or any other data from these providers.

Sign in with Apple — note on private email relay. If you use Apple's private-relay email option, we receive the relay address Apple generates for you, never your real email. Replies we send to that address are forwarded by Apple to your real inbox.

Scan history (signed-in users only). When signed in, scan results you choose to save are encrypted in transit (TLS 1.2+) and at rest (AES-256) on our backend, retained for up to 90 days, and deletable at any time from inside the app. The list of domains you have scanned, taken together, constitutes a per-account search history in the sense Apple uses that term in its App Store privacy questionnaire; it is linked to your account, used solely to power the in-app history and re-scan features, and never sold, rented, shared with advertisers, or used to build a profile about you.

Shared report links (optional). If you share a saved report, we create a link to a read-only copy of it. Anyone with the link can view that report until it expires (after 1 to 90 days, your choice) or you revoke it in Settings → Shared Links. The page doesn’t show your name or email address. We keep a count of how many times each link was viewed, and when it was last viewed, so you can see them; we don’t record who viewed it. Shared pages tell search engines not to index them. Deleting the scan or your account turns the link off.

Crash diagnostics (signed-in users only). If the app encounters an unhandled error, the app sends a single crash report to api.domainlenspro.app containing: the redacted exception message and stack trace, the device model name, the platform (iOS, macOS, Android, Windows), and the app version. The report is associated with your account so we can correlate the fix with the user who hit the bug. Before the report leaves your device it is run through our in-app log redactor, which removes OAuth codes, JWTs, Bearer tokens, provider-issued secrets, RFC 1918 / loopback / link-local IP addresses, and any infrastructure or brand identifiers. Public IP addresses are preserved so the bug report carries useful network context. Crash reports are used solely to fix bugs (“App Functionality” in Apple’s taxonomy); they are never used for analytics, marketing, ad targeting, or tracking. Signed-out users send no crash reports at all.

On-Device AI

iPhone, iPad and Mac. Where Apple Intelligence is available, Analyze This Scan and the Intel summary run on Apple's on-device model. The scan and the answer stay on your device; nothing is sent to us or to Apple.

Android. On phones that support Gemini Nano, the same features run on Google's on-device model through Google's ML Kit GenAI library and Android's AICore service. The scan and the answer are processed on your phone and are not sent to us or to Google. ML Kit does send Google diagnostics about its own use, whether or not you are signed in: the device manufacturer, model and Android version; the app's package name and version; a per-installation identifier that Google says is not intended to identify you or your device; performance metrics, feature events and error codes; and the configured languages. Google uses them for diagnostics and usage analytics, encrypts them in transit, and says it does not transfer them to third parties (ML Kit data disclosure; Google Privacy Policy). We never receive this data. Android may also download the Gemini Nano model from Google the first time the feature is used. On phones without Gemini Nano, and everywhere else, Analyze This Scan gives you the AI Prompt export instead, and nothing is sent.

Locally on your device. Theme, language, and preference settings, and any reports you export (JSON, CSV, Markdown, HTML, Plain Text, AI Prompt, PDF) are stored on your device by your explicit action. We never receive a copy.

Browser Extension

The optional DomainLens Pro browser extension (Chrome, Edge, and Firefox) connects to your account when you choose Sign In: it opens a DomainLens Pro sign-in window on domainlenspro.app, where you sign in the usual way (Apple, Google, Microsoft, GitHub, a passkey, or an email code) and choose Allow. The extension never sees your password or your sign-in provider’s data; it receives its own API token, which is listed in the web app under Settings → Connected Extensions and can be revoked there at any time. Signing in is the only way to connect the extension: API access is available only through the official DomainLens Pro apps and browser extension, automated or scripted use of API tokens is prohibited, and tokens used outside the extension are revoked (see the Terms of Service).

What This Website Collects

The marketing website at domainlenspro.com serves static pages and runs no analytics or advertising. The only personal data processing happens on the support page, where we collect:

Support submissions are emailed to our internal support inbox and retained while needed to handle your request, then deleted. We do not use any information you submit for marketing.

Website visits. The web app at domainlenspro.app records each page view anonymously, without cookies or third-party analytics: the page path and referrer, browser, operating system and device type (parsed from the user agent), the country your connection comes from, and a daily-rotating visit hash that lets us count unique visitors without recognizing you from one day to the next. Your IP address is stored with the page view only to detect abuse. Page views are deleted after 90 days; only daily totals are kept after that. When you are signed in, we also note which apps you used (web, iPhone/iPad, Mac, Windows, Android, browser extension, API) on each day, for 90 days, so we can count active users.

Country lookup. The country recorded with a page view or a sign-in is derived on our own server from a local copy of a free IP-to-country database; your IP address is never sent to a third party to do this, and we do not look up your city or region. IP geolocation by DB-IP, used under the Creative Commons Attribution 4.0 license.

Abuse prevention. So that DomainLens Pro can't be used to flood other people's websites, scans are rate-limited per account, per network and per scanned site: a site gets at most one fresh scan every few minutes, and a recent result is shared instead of scanning it again. These counters live only in our server's memory, for at most a day. When a limit is reached we record it in our security log (your account, the site's registered domain, and your IP address and browser user-agent), which is kept for 90 days. To slow down automated sign-ups we count new accounts per network using a keyed hash of your IP address, not the address itself, and the email sign-in form on domainlenspro.app uses the same Cloudflare Turnstile bot check as our support page; Turnstile may set short-lived technical cookies, and we receive only a pass/fail signal.

Third-Party Services Your Scans Reach

To answer a scan, the app or our scan backend contacts public Internet services. The query they receive is the domain, IP, or URL you submitted — never your name, email, account, or location:

These services have their own privacy policies. We do not control how they handle the queries you send.

Data Retention

We keep personal data only as long as it serves the purpose it was collected for, then delete it. Specific schedules:

If a legal obligation (for example, a tax record, a court order, or an active fraud investigation) requires us to keep specific data longer than the schedules above, we retain only what the obligation requires and delete the rest.

Legal Basis (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases are:

Your Rights

Subject to applicable law, you have the right to:

To exercise any right, send us a request through domainlenspro.com/support. We respond within 30 days.

California Residents (CCPA / CPRA)

We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act, and we have not done so in the preceding 12 months. We do not use personal information for cross-context behavioral advertising. California residents have the same access, deletion, and correction rights described above and the right not to be discriminated against for exercising them.

Children's Privacy

DomainLens Pro is not directed to children under 13 (or under 16 in the EEA / UK). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.

International Transfers

We are based in the United States. If you access the service from outside the United States, your data is transferred to and processed in the United States. We rely on appropriate safeguards including Standard Contractual Clauses where required.

Security

The app pins TLS to our scan backend. Data in transit uses TLS 1.2+ with modern AEAD ciphers and post-quantum hybrid key exchange where the server supports it. Stored personal data is encrypted at rest with AES-256. Access to backend systems is restricted by least-privilege controls and audited. No system is perfectly secure; if we ever discover a breach affecting your data, we will notify you and the relevant authorities as required by law.

App Distribution

DomainLens Pro is distributed via the Apple App Store for iPhone, iPad, and Mac, Google Play for Android, and (coming soon) the Microsoft Store for Windows. The browser extension is distributed through the Chrome Web Store (Microsoft Edge Add-ons and Firefox Add-ons coming soon), whose operators handle installs and updates under their own privacy policies. Apple, Google and Microsoft may collect data related to app installation, crashes, and updates as described in Apple's Privacy Policy, the Google Privacy Policy and the Microsoft Privacy Statement. We receive only aggregate, non-identifying download and crash metrics from these stores.

Changes to This Policy

We may update this policy from time to time. Material changes will be reflected on this page with an updated date. Continued use of the app or website after the effective date constitutes acceptance of the revised policy.

Contact

Questions, requests, or complaints? Reach us at domainlenspro.com/support. We typically reply within one business day.

Aegyrix LLC · Pennsylvania, USA · governing law: Commonwealth of Pennsylvania.