Privacy policy
Privacy for domain intelligence workflows: how Titan Research Ltd. handles personal data in Domain Atlas, from your account, API keys, and lookups to cookies and your rights under UK data protection law.
Last updated
On this page20 sections
Who we are
#Domain Atlas is provided by Titan Research Ltd., a company in the United Kingdom ("we", "us"). We are the controller of the personal data this policy describes, under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Where we process personal data on a customer's behalf and on its instructions, such as a domain dataset an Enterprise customer imports, we act as that customer's processor, and the customer's own privacy notice applies to that data.
Account data
#We use account identifiers, email addresses, sessions, and Google sign-in profile information (name, email, whether the email is verified) to authenticate users and protect access to the console and customer API. Your account also keeps the link to your Google profile photo and the sign-in tokens Google returns, and session records can include the IP address and browser user agent a session started from. For separately provisioned review accounts, we store a salted password hash to check sign-in. If you join an organization on Domain Atlas, we keep your membership and role.
API keys
#Customer API keys are shown once, stored as hashes, and tracked with aggregate usage metadata such as last-used time and request counters.
Billing and email
#Pro subscriptions are processed by Stripe; we store your Stripe customer and subscription identifiers and never see card numbers. Watchlist digests go to your verified account email through Cloudflare Email Sending and can be turned off in the console.
AI assistants
#If you connect Domain Atlas to an AI assistant such as Claude (Anthropic), ChatGPT (OpenAI), Grok (xAI), or Cursor (Anysphere), the domains it asks about and the Domain Atlas results it receives pass to that assistant's provider, whose own privacy policy then applies to them. You approve each connection on a Domain Atlas page. We keep a record of it (the assistant's name and what you approved) and its credentials, stored only as hashes, to authorize its requests; they draw on your plan's credits like API requests. You can revoke an OAuth connection from Connected assistants in your Domain Atlas account, which deletes its access and refresh tokens. Removing a connection from an assistant may not revoke credentials it already holds; unused credentials expire within 30 days. With additional permissions you approve, the assistant can read saved domains and recent searches, change your watchlist, and configure email updates to your verified account email when you request them. API-key connections are revoked through your API keys. Connection records are included in your data export and erased with your account.
Lookup activity
#Domain queries and request metadata may be processed to operate the service, enforce limits, investigate failures, and improve reliability. That covers:
- The domains you look up, save, and watch, and the watchlist digests you set up.
- Your monthly credit usage, and when each domain was last charged, so opening it again within 30 minutes is not charged twice.
- Request metadata, such as request IDs, endpoints, status codes, and timings, in short-lived operational logs.
- Error reports the console sends when something breaks: the error name and a code fingerprint, the page path, a request ID, and your account ID if you are signed in. They never include your IP address, browser user agent, or the error message.
Domain data
#Domain intelligence is requested only from our licensed domain data service. Source coverage identifies missing capabilities; Domain Atlas does not fill them from secondary feeds. The service receives the domain names requested, never your name, email address, or account details.
When a profile shows a site's icon, Domain Atlas fetches it from the site, or from the address the site names for it, and serves it to you itself. The site sees a request from Domain Atlas, never your IP address or account.
People in domain records
#Domain registration and DNS records can contain personal data, such as a registrant's name or contact details where a registry or registrar publishes them. Domain Atlas obtains these records through our licensed domain data service and shows them as published; many registries now redact registrant details at the source.
We process this data because we and our customers have a legitimate interest in security research, brand protection, and due diligence on domains. If a record names you, you can object or use the other rights below by writing to privacy@domainatlas.com.
Lawful bases
#We rely on these lawful bases under the UK GDPR:
- Contract: to provide the account, console, API, credits, watchlist digests, and assistant connections you sign up for, and to bill a Pro subscription.
- Legitimate interests: to keep Domain Atlas secure (sign-in, rate limits, abuse prevention, audit events, and error reports), to run and improve it from usage counts and request metadata, and to provide domain intelligence that can include personal data from domain records. We weigh these interests against your rights, and you can object to them.
- Legal obligation: to keep financial records and to respond to lawful requests from authorities.
We do not sell personal data or use it for advertising, and we make no decisions about you by automated means that have legal or similarly significant effects.
International transfers
#Titan Research Ltd. is based in the UK. Cloudflare, Stripe, and Google process personal data in the United States and other countries outside the UK, and Cloudflare may handle your requests in a data center near you.
Where personal data leaves the UK, we rely on UK adequacy regulations, including the UK Extension to the EU-U.S. Data Privacy Framework for providers certified under it, or on the International Data Transfer Addendum to the EU standard contractual clauses in each provider's data processing terms.
Data retention
#Account data is retained while your account is active and during the deletion process below. Aggregated API-key usage is retained for up to 400 days and account audit events for up to 730 days, unless removed earlier when your account is permanently erased.
- Recent searches: your last 8 lookups; each new one replaces the oldest.
- Console error reports: up to 90 days.
- Operational logs: kept by our hosting provider for a short period, then deleted.
- Payment records: Stripe keeps them under its own legal obligations; we keep your Stripe identifiers while your account exists.
Your rights
#Under the UK GDPR you can ask us to:
- Give you a copy of your personal data (access). Export your data on your Account page gives you a machine-readable copy you can take elsewhere (portability).
- Correct personal data that is wrong (rectification).
- Delete your personal data (erasure). Delete account on the same page starts this; see Export and deletion.
- Restrict how we use your data, or object to processing based on our legitimate interests.
For anything the Account page does not cover, write to privacy@domainatlas.com. We reply within one month, may ask you to confirm your identity first, and do not charge unless a request is manifestly unfounded or excessive.
Export and deletion
#Download a machine-readable copy of your account data or request deletion from your Account page. Deletion disables access and signs you out immediately. Signing in within 30 days restores your account. Permanent erasure is handled by our team after that window; it does not happen automatically on day 30. Records that belong to an organization you were part of, such as its audit trail and credit totals, are kept without your account attached.
Complaints
#If you are unhappy with how we handle your personal data, write to privacy@domainatlas.com and we will try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator, at ico.org.uk or on 0303 123 1113.
Cookies and local storage
#Domain Atlas sets no advertising or analytics cookies and loads no third-party trackers. It uses the cookies and browser storage below to keep you signed in, keep the service secure, or remember a setting or recent activity for you.
__Secure-better-auth.session_token(cookie): keeps you signed in. It lasts up to 7 days, renews while you use Domain Atlas, and is removed when you sign out.__Secure-better-auth.session_data(cookie): a signed copy of your session that saves a database read. It lasts 5 minutes.- Sign-in security cookies: set while you sign in with Google or approve an AI assistant, to protect that step against forgery. They last 10 minutes or less.
atlas-theme(local storage): your light, dark, or system theme.domain-atlas.recent-domains(local storage): the last 8 domains you looked up in this browser.atlas-session-hint(local storage): whether this browser was last signed in, so pages open in the right layout. It never holds your email address and is cleared when you sign out.atlas.apiLang(local storage): the programming language you chose for API code examples.colorMode(local storage): the light or dark setting of the API reference.scalar-reference-selected-client-v2(local storage): the code-sample language you chose in the API reference.atlas.previewTour(session storage): that the home page's product tour has already played.atlas.account.restorableUntil(session storage): the restore deadline shown after you delete your account.
Session storage clears when you close the tab, and you can clear the rest in your browser settings at any time; without the session cookie you cannot sign in, but public pages still work. Cloudflare, which runs our network, may set its own security cookie to tell people from automated traffic.
One thing loads from outside Domain Atlas: the API reference loads its viewer from the jsDelivr content delivery network, which receives your IP address and browser details to deliver the file. Site icons on domain profiles are served by Domain Atlas itself, so the sites you research never receive your IP address or browser details.
Security
#We encrypt traffic with HTTPS, store API keys and assistant credentials only as hashes, and record security-relevant account events. Internal data credentials stay server-side. They are not exposed in browser bundles, API responses, OpenAPI output, or customer key material. Our Security page describes these controls.
Children
#Domain Atlas is a professional tool and is not intended for children. You must be 18 or older to create an account, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to privacy@domainatlas.com and we will delete it.
Changes to this policy
#When we change this policy, we update its Last updated date. If a change materially affects how we use your personal data, we tell account holders by email or in the console before it takes effect.
Contact
#Questions about privacy, deletion, or enterprise review can be sent to privacy@domainatlas.com. Titan Research Ltd. is the controller responsible for your personal data.