Privacy Policy
Last updated: July 29, 2026
1. What this covers
This policy explains what DMARCcore, operated by TheBRHub ("we", "us"), collects when you use the Service, and what your options are. It applies to the DMARCcore web application and its API.
2. What we collect
- Account data: the email and password you register with, and an optional name used to label your workspace.
- Domains and DNS-facing data: the domains you add for monitoring, and the DMARC/SPF/DKIM records the Service reads or generates for them.
- Aggregate authentication reports: DMARC aggregate reports that mail receivers (Google, Microsoft, and similar) send to the dedicated report address DMARCcore issues for each domain. These reports contain sending IP addresses, message volumes, and SPF/DKIM/DMARC pass-fail results. They do not contain the content, subject line, or recipients of any individual email.
- Client records you choose to enter: if you use the Clients feature, the contact details and notes you type in for your own clients.
- Branding assets: if you configure white-label branding, the company name, colors, and logo you upload.
- Alert configuration: the alert rules and notification destinations you set up.
We do not read the content of your email. DMARC aggregate reporting, by design, never includes message bodies.
3. How we use it
- To operate the Service: authenticate you, show your domains' authentication posture, and generate the records and report addresses DMARCcore issues.
- To send alert notifications to the destinations you configure, when a rule you created is triggered.
- To maintain and improve the Service.
We do not sell your data, and we do not use it for advertising.
4. Where it is stored
DMARCcore runs on Cloudflare's infrastructure (Workers and D1). Cloudflare acts as our infrastructure provider and processes data on our behalf to run the Service; it does not use your data for its own purposes. All traffic to the Service is encrypted in transit over HTTPS.
5. Sessions and cookies
DMARCcore does not use tracking or advertising cookies. When you sign in, a session token is stored in your browser's local storage, not in a cookie, and is used only to authenticate your requests to the API.
6. Sharing
We do not share your data with third parties except: (a) Cloudflare, as the infrastructure provider described above, and (b) where required by law. If a future integration would share data with another third party, this policy will be updated first.
7. Retention
We keep your data for as long as your account is active. If you delete your organization, all associated domains, reports, client records, and user data are permanently deleted immediately; this cannot be undone.
8. Your rights and controls
- Export: you can download a copy of your organization's data (domains, clients, sources, and report metadata) at any time from Settings.
- Deletion: you can permanently delete your organization and all its data at any time from Settings. This is a self-serve action; it does not require contacting us.
- Access and correction: your account and client records are directly editable in the app. For anything you cannot change yourself, contact us using the address below.
9. Security
Passwords are stored hashed, not in plain text. Access to the Service requires authentication, and the API rejects unauthenticated requests.
10. Children
DMARCcore is a business tool and is not directed at, or intended for use by, anyone under 18.
11. Changes to this policy
We may update this policy as the Service evolves out of early access. Material changes will be reflected here with an updated date at the top of this page.
12. Contact
Questions about this policy, or to exercise a right described above: support@thebrhub.com