Security and data handling
Last updated: 2026-10-04
DemiSignal is built and run by Demi Solutions OÜ, a company registered in Estonia, in the European Union. Its founder, Jan Demsar, has built software since 2007.
What DemiSignal reads
Public DNS records. A domain check reads the email records your domain publishes in public DNS (SPF, DKIM, DMARC, MX, MTA-STS and BIMI) and the public files they point to, such as an MTA-STS policy or a BIMI logo. These are the same records any receiving mail server reads. A check changes nothing on your domain and sends no email.
DMARC aggregate reports. When you add your DemiSignal reporting address to your DMARC record, mailbox providers send it aggregate reports. These reports are designed as summaries: they list the IP addresses that sent email using your domain, how many messages each sent, the sending and receiving domains where the provider includes them, and whether the messages passed SPF, DKIM and DMARC. DemiSignal stores each report file it receives and the details it reads from it.
DemiSignal does not ask for access to your mailboxes, your DNS provider or your email platform.
Your account and checker details
You can sign in with an email address and password, or with Google or Microsoft. Google and Microsoft share basic profile details with us, such as your name, email address and profile picture. We do not request access to your mailbox.
The free checker asks for an email address to open the full report. That address is stored encrypted, kept for 180 days and deleted earlier on request.
The privacy policy lists what we collect, why, and how long we keep it.
Payments
Paddle is our merchant of record. You enter card details in Paddle's checkout; they are never sent to or stored by DemiSignal. Paddle issues invoices and handles refunds under Paddle's Refund Policy.
Where your data is stored
DemiSignal runs on a server we rent from Hetzner in Ashburn, Virginia, in the United States. The application and its database run on that server. Browsers reach it through Cloudflare over HTTPS, and the site tells browsers to use HTTPS only.
Backup copies of the database are encrypted before upload to Backblaze B2 storage in the EU. Other backup copies are kept on a Netcup server we run in Singapore.
Some of our providers process data outside the EU. Section 1.4 of the privacy policy explains how those transfers are safeguarded.
Encryption
- Connections to demisignal.com use HTTPS.
- Passwords are stored as one-way hashes, never in readable form.
- Email addresses given to the free checker are encrypted in our database.
- Backup copies in Backblaze B2 are encrypted before upload.
Service providers
These providers process data for DemiSignal:
| Provider | What it does for DemiSignal |
|---|---|
| Hetzner | Server hosting for the application and database (United States) |
| Netcup | Server holding backup copies (Singapore) |
| Backblaze | Encrypted backup storage (EU) |
| Cloudflare | DNS, network delivery and bot checks on public forms |
| Postmark | Sends account and alert emails; receives DMARC reports |
| Amazon Web Services | Sends account and alert emails if Postmark is unavailable (United States) |
| Paddle | Checkout, payments, invoices and refunds as merchant of record |
| Sentry | Error monitoring (United States) |
| PostHog | Product analytics (United States) |
| Optional sign-in; our support and security mailboxes | |
| Microsoft | Optional sign-in |
| Telegram and Pushover | Internal alerts to our team about errors and service health |
Your rights
As an EU company we process personal data under the GDPR. To access, correct or delete your data, or to object to how we use it, email [email protected]. Section 9 of the privacy policy explains the process, including how to complain to the Estonian Data Protection Inspectorate.
Report a security issue
Email [email protected]. The same contact is published in our security.txt file.