Legal
Privacy Policy
Last updated: August 12, 2026. Contact: hello@ad.ms
ad.ms is a small personal project, not a corporation. This policy is written to be read, not to be endured. Here is exactly what we collect, why, and how we handle it. We do not sell your data — not now, not ever.
1. What We Collect
Email address
Required to create an account. We use it for authentication and for service notifications — things like email verification, subdomain expiry reminders, and security alerts. We do not use it for marketing.
Name (optional)
If you provide a display name when setting up your account, we store it. You do not have to.
Subdomain names and DNS records
We store the subdomain labels you register and the DNS records you configure (A, AAAA, CNAME, TXT). This data is what makes the service work.
IP addresses — hashed, never plaintext
When an IP address needs to be logged for abuse-prevention purposes, it is passed through a one-way cryptographic hash before being stored. We never store your IP address in plaintext. That means we can detect repeated abuse patterns without being able to reconstruct the original address from our logs.
Session data
A session cookie is set when you sign in to keep you authenticated. It is removed when you sign out or when your session expires.
Usage analytics (anonymized)
We use Google Analytics to understand how people use the site — which pages get traffic, general usage patterns. IP anonymization is enabled. Google Analytics does not receive your email, your subdomain names, or any account data. If you prefer to opt out, browser extensions like uBlock Origin or the Google Analytics Opt-out Add-on will do it.
2. What We Do Not Collect
- Plaintext IP addresses
- Payment information (the service is free; premium names are arranged directly by email)
- Device fingerprints or advertising identifiers
- Location data beyond what is inherent in IP hashing
- The content hosted at your subdomain
3. How We Use Your Data
- Email — to authenticate your account and send service notifications
- Subdomain and DNS data — to operate the service
- Hashed IPs — to detect and prevent abuse only
- Analytics — to understand usage patterns and improve the service
4. We Do Not Sell Your Data
We do not sell, rent, trade, or otherwise share your personal information with third parties for commercial purposes. We never have and do not intend to.
5. Third-Party Services
We use a small number of third-party services to run ad.ms:
Microsoft Azure
Our cloud infrastructure runs on Azure. This covers hosting, databases, and transactional email via Azure Communication Services (used to send verification emails and service notices). Your email address is processed by Azure to deliver those messages.
Google Analytics
Anonymized usage analytics. IP anonymization is enabled. Analytics data is not linked to your account. You can opt out at any time using a browser extension.
There are no other third-party data processors.
6. Cookies
We use two types of cookies:
- A session cookie for authentication — set when you sign in, removed when you sign out
- Google Analytics cookies — used for anonymized analytics only, not advertising
We do not use tracking cookies or advertising cookies.
7. Data Retention
Account data (email, subdomains, DNS records) is retained for as long as your account is active. When you delete a subdomain it is soft-deleted for up to 90 days — during which it cannot be re-registered — and then permanently purged.
To delete your account and all associated data, email hello@ad.ms. We will action it within a reasonable time.
8. Your Rights
- Access your account data from the dashboard at any time
- Export your DNS configuration from the dashboard
- Request full account deletion by emailing hello@ad.ms
9. Security
- Passwords are hashed with bcrypt
- IP addresses are one-way hashed before storage — never stored in plaintext
- All traffic is served over HTTPS
- Infrastructure is managed by Azure with standard enterprise security controls
No system is perfectly secure. If you discover a security issue, please email hello@ad.ms.
10. Changes to This Policy
This policy may be updated occasionally. The date at the top of this page will reflect the latest revision. For material changes, we will make reasonable efforts to notify registered users by email.
11. Contact
Privacy questions, data requests, or anything else — email hello@ad.ms.