Privacy Policy
Last updated: August 14, 2026
1. Overview
HM Domains is committed to protecting your privacy. We believe in minimal data collection and only process the essential information required to operate our DNS provisioning infrastructure and authenticate developer accounts.
2. Information We Collect
When you authenticate and use HM Domains, we collect:
- GitHub Profile Information: Your public GitHub username, avatar URL, and user ID provided via Firebase Authentication OAuth.
- Domain & DNS Records: The subdomain handles you register, along with associated DNS records (A, CNAME, TXT, MX, NS records, target IPs, and TTL values).
- Technical Telemetry: Anonymized server access logs including IP address, request timestamp, and latency metrics for DDoS mitigation and abuse monitoring.
3. How We Use Your Information
We use the collected information exclusively to:
- Verify developer accounts and prevent bot-driven domain hoarding.
- Create, sync, and maintain DNS records on Cloudflare edge nameservers.
- Enforce quota limits (maximum subdomains per user) in Google Cloud Firestore.
- Respond to abuse, copyright infringement, or legal inquiries.
We never sell, rent, or monetize your personal data or browsing activity.
4. Third-Party Service Providers
We partner with enterprise cloud providers to deliver reliable infrastructure:
- Cloudflare Inc: For global Anycast authoritative DNS hosting, DDoS mitigation, and SSL edge termination.
- Google Firebase / GCP: For secure OAuth authentication and Firestore database storage.
- Vercel Inc: For serverless application hosting and SSR compute.
5. Data Retention & Deletion
Your DNS records and account metadata are retained for as long as your subdomains remain active. When you delete a subdomain from the console, its corresponding DNS records are immediately deleted from Cloudflare and removed from our active database.
