Privacy policy
Last updated 1 August 2026
analyze.domains is operated by Realtime Comms Ltd, a company incorporated in England and Wales (company number 15584611, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ), which is the data controller for the personal data described here. This policy explains what we collect, why, and who else sees it. Contact us at support@realtimecomms.co.uk.
What we collect
- Your email address, because that is how you sign in. There are no passwords. Optionally a display name.
- Your saved domains and alert rules, so we can show them back to you and tell you when something matches.
- Subscription status, and identifiers issued by Stripe. We never see or store card numbers.
- Usage measurements for each chat turn: how many tokens it used, how long it took, how many results it returned. These are numbers only.
- A hashed identifier for rate limiting. For signed-out visitors this is derived from your IP address using a one-way hash. We do not store raw IP addresses, and the table is cleared every two days.
What we do not collect
We do not store the contents of your conversations. What you type in the chat is sent to the model that answers it and is not written to our database. We keep the count of messages and tokens, not the messages.
We do not use advertising cookies, we do not run third-party trackers, and we do not sell or share personal data for marketing.
Cookies
One cookie, ad_session, which keeps you signed in for 30 days. It is strictly necessary for the site to work and holds no personal data beyond a random token. Sign out and it is deleted.
Our analytics are self-hosted and cookieless. They record page views and referrers in aggregate, with no cookie and no identifier that follows you between sites, which is why you are not asked to accept a banner.
Who else processes your data
- Stripe (payments). Receives your email address and handles card details directly. Stripe is the controller for its own payment records.
- Resend (email delivery). Receives your email address and the contents of sign-in links, alerts and reports.
- DeepSeek (the language model behind the chat and the scoring). Receives the text of your chat messages in order to answer them. DeepSeek processes data outside the UK, in China. That is an international transfer, and it is the reason we ask you not to type anything confidential or personally sensitive into the chat. The chat is a search box for domain names; it does not need, and should not be given, personal information.
Everything else, including the domain inventory, your watchlist and your alerts, runs on our own servers.
Why we are allowed to hold it
- Contract: your account, saved domains, alerts and subscription. We cannot provide the service without them.
- Legitimate interests: rate limiting and aggregate usage measurement, to keep the service available and affordable, balanced against your privacy by hashing identifiers and storing no message content.
- Consent: optional emails. Alerts, reports and product updates are each off by default and switched on by you, and every one can be turned off again in your notification settings.
- Legal obligation: keeping records of payments.
How long we keep it
- Sign-in links expire after 15 minutes and can be used once.
- Sessions expire after 30 days.
- Rate-limit records are deleted after 2 days.
- Account data is kept while your account exists. Ask us to delete it and we will, apart from payment records we are required to retain.
- Encrypted database backups are kept on a rolling 7-day cycle, so deleted data can persist in a backup for up to a week before ageing out.
Your rights
Under UK data protection law you may ask us for a copy of your data, ask us to correct or delete it, object to or restrict processing, or ask for it in a portable form. Where we rely on consent you can withdraw it at any time. Email support@realtimecomms.co.uk and we will respond within one month.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.
Security
The site is served over HTTPS. Sign-in tokens and session tokens are stored hashed, never in the clear, so a copy of our database would not let someone sign in as you. Access to the database is limited, and the component that answers public chat queries holds a read-only credential.
Changes
If we change this policy materially we will tell account holders by email. The date at the top always reflects the current version.
See also our terms and conditions.