krz/krz.sh

clone: git clone https://gitbay.org/krz/krz.sh.git

main: content/privacy/domain-dig.md · raw

 1+++
 2title = "Domain Dig — Privacy Policy"
 3description = "Privacy policy for Domain Dig, the DNS and SSL inspector for iOS."
 4weight = 2
 5+++
 6
 7_last updated: 2 august 2026_
 8
 9Domain Dig inspects DNS records, SSL/TLS certificates, ownership, and related
10signals for domains you enter. every lookup runs from your device. we operate no
11servers, and we receive none of your data.
12
13## what we collect
14
15nothing. no account, no analytics, no ads, no third-party trackers or SDKs.
16
17## what stays on your device
18
19recent lookups and their results are stored locally on your device so you can
20revisit them. deleting the app removes the local copy. if you turn on iCloud
21sync (off by default), your settings, monitoring configuration, domain notes,
22and history metadata are stored in your own private iCloud account so they carry
23across your devices — that data goes to Apple's iCloud, never to us, and you can
24turn it off in Settings.
25
26## network connections
27
28to answer a lookup, Domain Dig queries public DNS resolvers and connects to the
29hosts you inspect in order to read their certificates. it also contacts a few
30third-party lookup services to enrich the results — an IP-geolocation provider
31(ipapi.co), RDAP registries (via rdap.org), Certificate Transparency logs
32(crt.sh), and the HSTS preload list (hstspreload.org). the domains and IP
33addresses you look up are therefore visible to these resolvers and services, and
34may be logged by them under their own policies. we do not see or record any of
35it.
36
37if you configure a Webhook or Slack integration, Domain Dig sends alerts to the
38URL you provide; that destination is chosen and controlled by you.
39
40## changes
41
42if this policy changes, the updated version will be posted here with a new date.
43
44## contact
45
46questions: [root@krz.sh](mailto:root@krz.sh).