Updated September 26, 2026
Privacy policy
Who this notice covers
This notice explains how HealthCheckEmail handles information through its website, dashboard, API, MCP server and companion skills. Contact privacy@healthcheckemail.com with privacy questions or requests.
Information we handle
Account and team email addresses; domains and DNS records you submit; DMARC aggregate reports, sending IP addresses and authentication results; messages and headers sent to our diagnostic inbox; alert destinations and configuration; public-status settings; subscription and support records. We also process technical request information, such as IP addresses, timestamps and errors, to operate and protect the service. Do not submit information that you are not authorized to share.
Why we use it
We use this information to authenticate you, provide the features you request, maintain account and workspace access, measure usage, administer subscriptions, troubleshoot failures and prevent abuse. Support messages are used to respond to your request. Optional features process data when you configure or invoke them.
MCP and AI connections
Connecting an AI client requires sign-in and explicit OAuth consent. The HealthCheckEmail MCP server receives the tool name and arguments sent by that client and returns the authorized result to it. The connection can read or change resources only through its declared tools and granted permissions. Review the permissions before connecting. Your AI provider handles prompts, conversations and tool results under its own policies; disconnecting here does not erase copies already received by that provider. Companion skills contain instructions, not a separate account database.
Service providers and recipients
Cloudflare provides hosting, network, storage and related infrastructure. Payment processors handle checkout and billing information when you subscribe. Account emails and configured notifications are delivered through email infrastructure. Information is shared with an AI client only when you connect and use it, and with teammates or destinations you authorize. We may disclose information when required by law or necessary to investigate abuse. Data may be processed outside your country by these providers.
Feature-specific disclosure
Public status pages expose the status information you choose to publish. Alert tools can send notifications to configured recipients. Domain diagnostics query public DNS and other relevant infrastructure. Review destinations and visibility settings before enabling these features.
Retention
Account and workspace records remain while needed to provide your account and configured features, unless you delete them or request closure. OAuth authorization flows expire after 10 minutes; access tokens after one hour; refresh tokens after 28 days; dynamically registered clients after 90 days. Continued use can renew authorization state. Operational records may remain separately where needed for security, billing, dispute resolution or legal obligations. Removing an active record does not necessarily remove earlier backups or copies held by your AI provider immediately.
Your choices and requests
You can manage your data in the dashboard, disconnect an AI client and request account closure or deletion at privacy@healthcheckemail.com. Include the account email and the request, but never send passwords, API keys or access tokens. We verify identity before disclosing or deleting account data and explain any records we must retain. You may also request access or correction and exercise rights available under the law that applies to you.
Security and updates
OAuth credentials and account sessions grant access: keep them private and revoke a connection you no longer trust. We restrict account access and use encrypted network connections, but no online service can promise absolute security. We update this notice as the service changes and show the updated date here.