Account data
We store your account name, sign-in email, plan, API-key records, sessions and usage counters to provide the service. Email sign-in sends your address and a verification code to Resend for delivery. Codes expire after 10 minutes; Disban stores a keyed hash rather than the readable code.
Email checks
The web service processes the email you submit, but sends only its domain to the checker. Saved check activity contains the domain, classification, evidence and timing, not the email local part. We do not access mailboxes. DNS queries reveal the queried domain to the configured resolver. The response can echo the submitted email to the caller.
Retention
Activity follows your current plan: Free 15 days, Launch 30 days, Growth 60 days and Scale 90 days. Only Free is currently available. Expired activity is excluded from history and exports and removed by cleanup. A downgrade warns about deletion and removes the oldest affected records after confirmation. An upgrade cannot restore deleted activity. Retained results are snapshots and are not recalculated.
Backend diagnostic check logs contain domains rather than complete email addresses and have a 15-day retention setting. Cleanup is asynchronous. Provider/domain intelligence is separate from customer activity and may retain historical associations for reassessment.
Support tickets
Support stores the subject, topic, messages, status and timestamps linked to your account. Messages may contain information you choose to share; do not include API keys, passwords or verification codes. Authorized administrators can read and reply to tickets. Open tickets remain available; resolved tickets are deleted after 90 days by asynchronous cleanup. Reopening a ticket cancels its resolution deadline. Account deletion removes your tickets and their messages.
Privileged account and support actions are recorded in a separate operational audit log. Account deletion removes the actor identity link from that log; event IDs and action timestamps may remain for system accountability.
Your controls
Export activity from the dashboard. Account controls let you delete activity, sign out all sessions or delete your account after email verification. Deleting activity does not reset usage. Account deletion removes active account records, sessions, keys, usage and associated activity; it does not promise immediate removal from any existing backup copies. Backup retention and restore-erasure arrangements must be finalized before public launch.
Cookies and delivery
Disban uses a session cookie for sign-in and browser storage for your theme preference. After you verify an email code, a security cookie remembers that browser for up to 90 days so delivery limits caused by other people do not block it. This cookie cannot sign you in without a new email code. Ordinary logout keeps it; signing out all sessions, account suspension, deletion or operator recovery revokes it. The server stores only a hash of the token. Hosting, DNS resolution and email-delivery providers process the information required for those services.
Public tools
The public checker and CSV profiler send only selected domain names to our checker. Full email addresses and CSV files stay in your browser. Public tool checks are not added to account history. To limit abuse, we keep counts linked to a daily keyed network identifier, not a raw IP address, until the end of the UTC day; expired counter records are removed on the next public check. Domain intelligence may be cached by the checker, and domain-only requests may appear in operational checker logs. The alias explorer, policy lab, credit calculator, and code generator run locally in your browser.
Referral rewards
Referral links identify the inviting account. We store the referral relationship, reward status, and bonus credit balance and expiry dates. Inviters see aggregate counts, not invited users’ email addresses. Account deletion removes your referral link, bonus balance and account links in referral records. We retain keyed hashes of the referred email identity and domain, along with reward records to prevent repeated rewards through account deletion and re-registration.
Product usage and coverage reports
A first-party cookie remembers only a limited acquisition-source label (direct, organic, outreach or referral) for 30 days. We count public-page requests by day, source and page type without storing visitor identifiers or full URLs. These aggregate counts are kept for 90 days. We record account-linked signup, API-key creation, successful-check and daily-use milestones to improve onboarding. Events contain timestamps and a limited acquisition-source label, never checked email addresses, domains, codes or keys. Events are retained for up to 90 days and cleaned hourly while the service runs and on growth-dashboard access; account deletion removes them. Integration progress is retained while your account exists. Coverage reports store the submitted domain, note and review response until account deletion. Do not include credentials or personal information in report notes. Usage alerts appear in the workspace; we do not send marketing or usage-alert emails through this feature.
Website analytics
With your consent, Disban uses Google Analytics 4 to understand how visitors find the site and move from a first visit to signup and API-key creation. Until you choose “Accept analytics”, no request is made to Google and no analytics cookies are set. If you accept, Google Analytics cookies (such as _ga) are set and Google receives page paths (never query strings), referring pages, device and browser details, approximate location derived from your IP address, and three product events: signup started, signup completed and API key created. Email addresses, checked domains, verification codes and API keys are never sent. Analytics is never loaded on administration pages. Advertising features are disabled. Your choice is stored in this browser for 12 months; rejecting removes existing Google Analytics cookies.
Contact and operator
Avagama Consulting