Privacy policy
Last updated
This policy explains what Trees and Rain LLC collects when you use the PapiDNS app and the www.papidns.app website, how we use and protect it, who else is involved, how long we keep it, and how to delete it.
At a glance
- Who we are. PapiDNS is made by Trees and Rain LLC. Questions go through our contact form.
- Sign-in. You sign in with Apple or Google. PapiDNS has no passwords of its own.
- Your API keys are encrypted before we get them. Your GoDaddy API key and secret are encrypted on your device with a passphrase that never leaves it. We store only the encrypted result and can’t read your keys.
- Your DNS stays between you and GoDaddy. The app talks to GoDaddy directly. Your domains and DNS records aren’t sent to or stored on our servers.
- What we do collect. Your sign-in details, your encrypted keys and their names, bug reports and feature requests you choose to send, and server logs.
- No ads, analytics or tracking. The app has no analytics, crash-reporting or advertising tools. We don’t sell your personal information or share it for advertising.
- You can delete it. Delete your account at any time in the app (Delete Account, in the app’s menu) or from our website. See how deletion works.
Who we are
PapiDNS is an app for iPhone and iPad that lets you view and edit the DNS records of domains in your GoDaddy account, using a GoDaddy API key you create. The app and the website at www.papidns.app are provided by Trees and Rain LLC (“we”, “us”, “our”). Trees and Rain LLC is the controller of the personal information described in this policy, which means we decide how and why it’s used.
This policy covers the PapiDNS app, this website and its forms, and emails you exchange with us. It doesn’t cover services run by others that you use with PapiDNS, such as GoDaddy, Apple, Google or the App Store. Their own privacy policies apply. PapiDNS isn’t made by, affiliated with or endorsed by GoDaddy.
PapiDNS is currently available for iPhone and iPad. If we release it on another platform, we’ll update this policy before we do. For any privacy question or request, use our contact form.
Information we collect
We collect only what we need to run PapiDNS. Here is all of it, grouped by where it comes from.
From your sign-in provider
PapiDNS has no passwords. You sign in with Apple or Google, and our authentication service receives:
- A user ID from the provider, so we can recognize you next time.
- Your email address. If you use Sign in with Apple and choose Hide My Email, we get a private relay address from Apple instead of your real one.
- If you sign in with Google, your name and a link to your Google profile photo. Our authentication service stores them with your sign-in record; the app doesn’t show or use them. The app asks Apple for your name when you sign in with Apple, but doesn’t keep it.
We also record when your account was created and when you last signed in.
Your GoDaddy API keys
When you add a GoDaddy API key, the app checks it with GoDaddy and then encrypts the key and secret on your device before saving anything. We store:
- The encrypted key and secret, and the encrypted data key that protects them (plus a second encrypted copy of that data key if you create a recovery code).
- The random values and settings needed to unlock them: salts, nonces and the encryption settings used.
- The name you give the key (for example, “Personal”), whether it’s a Production or OTE (GoDaddy test) key, and when it was created and changed.
We never receive your passphrase, your recovery code or the unencrypted key and secret. How your API keys are protected explains the details.
Bug reports and feature requests
If you have Premium, you can send these from the app’s menu. They’re always optional.
- Bug reports: a title, a description and, if you add one, a screenshot you pick from your photos. The app saves the screenshot as an image in private storage. It doesn’t attach device details or logs. A screenshot shows whatever was on your screen, such as domain names and records, so choose one that doesn’t show anything you want to keep private.
- Feature requests: a title and a description.
Purchases
PapiDNS Premium is an optional auto-renewing subscription, monthly or yearly, sold through the App Store. Apple handles the payment, and the app checks your subscription with Apple on your device. We don’t receive your purchase history, your Apple Account details or your payment details.
Server logs
- Our backend service keeps logs of requests the app makes to our servers, including the IP address, device or browser type (user agent) and time. While the app is open, it checks with our servers about once a minute that you’re still signed in, which adds to these logs.
- Our authentication service records each signed-in session with its IP address and device type (user agent), until you sign out or delete your account.
- It also keeps an audit log of sign-ins, sign-outs and session refreshes, with your account ID, email address and, for Google sign-ins, your name. These entries aren’t deleted automatically, even after you delete your account; you can ask us to delete yours.
What stays on your device
- Your domains and DNS records. The app gets them from GoDaddy and holds them in memory while it’s running. It doesn’t save them itself or send them to us. Like most apps, it uses the standard iOS network cache, which can keep recent lookups, such as your domains’ nameserver checks, on this device for a while.
- Your sign-in session, in the iOS Keychain.
- Unlocked keys. When you unlock an API key, it’s held in memory. If you choose “Remember on this device” (the default when you unlock), the key that unlocks it is saved in this device’s Keychain so you don’t need your passphrase each time. It stays on this device only and can be read only while the device is unlocked. “Forget passphrase on this device” in Settings removes it.
- Which key is active, in the Keychain.
From our website and support
- Contact form. Your first and last name, email address, topic and message, your device and app version if you add them, and any screenshots you attach.
- Data deletion request form. Your account email address, your first name (and last name if you add it), how you sign in, whether you want full or partial deletion, any details you add and, if you choose, your Facebook app-scoped user ID.
- Messages. Anything you include in a form or in a reply to our emails.
- Website visits. Our hosting provider, Vercel, keeps short-lived request logs with your IP address, browser type (user agent) and the pages requested. When you submit a form, Vercel BotID uses signals from your browser and device to check that you’re a person, not a bot. If it can’t tell, the form asks you to tick a box that runs a short proof-of-work check in your browser, issued and verified by our own servers; no third party is involved.
- Cookies. This website doesn’t use advertising or analytics cookies.
What we don’t collect
The app has no analytics, crash-reporting or advertising tools, and it doesn’t send push notifications. We don’t collect your location, contacts, phone number, advertising identifier, payment card details, camera or microphone input, health information or passwords. PapiDNS doesn’t track you, so it never shows the App Tracking Transparency prompt.
How we use your information
- To run PapiDNS. Create your account and sign you in, and keep your encrypted API keys available on each device where you sign in.
- To help you. Answer your questions, look into bug reports, and carry out privacy and deletion requests.
- To improve PapiDNS. Fix the bugs you report and consider the features you ask for.
- To keep PapiDNS safe. Prevent abuse, protect accounts, investigate problems and enforce our Terms of service.
- To meet legal obligations, such as keeping records of requests and responding to lawful requests from authorities.
We don’t sell your personal information, use it to show you ads, or let advertisers use it. We don’t use it to make automated decisions that have legal or similarly significant effects on you.
How your GoDaddy API keys are protected
A GoDaddy API key and secret can change the DNS of every domain they reach, so PapiDNS is built so that we can’t read them.
- Encrypted on your device. The app encrypts your key and secret with a random data key (XChaCha20-Poly1305). It then encrypts that data key with a key derived from your passphrase (Argon2id, with a random salt). Both steps use the open-source libsodium library and happen on your device.
- Your passphrase stays with you. You set a passphrase for each key: at least 12 characters, using at least three of lowercase letters, uppercase letters, numbers and symbols. It’s never saved or sent anywhere.
- Recovery code. When you add a key, you can choose to create a recovery code, which is shown only once. It unlocks the key if you forget your passphrase, so keep it somewhere safe, such as a password manager. Anyone who has it can unlock that key. Changing your passphrase doesn’t change your recovery code, so if you think your recovery code has been seen by someone else, delete the key and add it again.
- We can’t recover it for you. Because we never have your passphrase or recovery code, we can’t decrypt your keys, and neither can anyone who gets into our database. If you lose both, delete the key in PapiDNS and add it again. You can create a new key at GoDaddy at any time.
- Used only on your device. The app unlocks a key on your device and uses it to call GoDaddy directly over HTTPS. Unencrypted keys and your DNS data never pass through our servers.
- You can revoke a key at GoDaddy. Deleting or revoking a key at developer.godaddy.com/keys stops it working everywhere, including in PapiDNS.
Services the app contacts directly
Some features work by your device talking directly to other companies’ services. They receive your device’s IP address, as any website or service you connect to does, and their own privacy policies apply.
- GoDaddy. When you use an API key, your device sends requests straight to GoDaddy’s API (
api.godaddy.com, orapi.ote-godaddy.comfor OTE keys). Those requests carry your key and secret, and the domains and records you view or change. Your GoDaddy account and GoDaddy’s privacy policy govern what GoDaddy does with them. - Google Public DNS and rdap.org. To show whether each domain’s DNS is hosted at GoDaddy, the app looks up the domain’s nameservers through Google Public DNS (
dns.google) and its public registration record throughrdap.org, which redirects the app to the registry for that domain’s ending (for example, Verisign for .com). These services receive the domain name. They don’t receive your API key or your account details. - Apple and Google. Sign-in happens with Apple or Google, and Apple handles App Store purchases.
Service providers and sharing
We use the service providers below to run PapiDNS and this website. They handle personal information on our behalf, under terms that require them to protect it and to use it only to provide their services to us. Apple handles payments as an independent company under its own privacy policy.
| Provider | What they do | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage and server functions for the app. Hosted in the United States (California). | Your sign-in record (provider user ID, email address, the details your provider shares, and the IP address and device type of each signed-in session), your encrypted API keys with their names and settings, bug reports, screenshots and feature requests, and server and sign-in logs. |
| Vercel | Hosts this website and runs its forms. Vercel BotID checks that form submissions come from a person, not a bot. | Short-lived request logs (IP address, user agent, pages requested), form submissions as they pass through, and browser and device signals for the bot check when you submit a form. |
| Resend | Delivers website form submissions to our support mailbox. | Everything you enter in a form, including any screenshots you attach. |
| Microsoft 365 | Our support mailbox and email. | Emails and form submissions you send us, and our replies. |
Other disclosures
- Legal reasons. To comply with the law, a court order or other valid legal process, or to protect the rights, safety and property of our users, the public or us.
- Business transfers. If Trees and Rain LLC is involved in a merger, acquisition or sale of assets, your information may transfer as part of it. We’ll tell you before your information becomes subject to a different privacy policy.
- With your permission, in any other case.
PapiDNS has no social features: other users can’t see your account, your keys or your domains. We don’t sell your personal information and we don’t share it for cross-context behavioral advertising.
Google user data
When you choose Continue with Google, you sign in with Google in a secure browser window. PapiDNS asks Google only for the basic sign-in information: your email address and basic profile. We don’t request access to Gmail, Google Drive, Contacts, Calendar or any other Google data.
- What we access: your Google account ID, email address, name and profile photo link.
- How we use it: only to create your PapiDNS account and sign you in, and to contact you about your account or requests you make.
- How we store it: in our authentication service, protected as described in Security. It’s deleted when you delete your account, except for the records described in How long we keep your information: backups (which roll off within 30 days), our sign-in audit log (kept until you ask us to delete it) and emails you’ve exchanged with us.
- How we share it: only with the service providers that host PapiDNS and deliver our email, and when the law requires it. Other users can’t see it.
- What we don’t do: we don’t sell Google user data, use it for advertising, transfer it to data brokers, or use it to train AI or machine-learning models. People at Trees and Rain LLC don’t read it except with your permission, for security, to comply with the law, or to handle a request you make.
PapiDNS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
To remove PapiDNS’s access to your Google account, go to the third-party connections page in your Google Account. This stops PapiDNS from using your Google sign-in but doesn’t delete your PapiDNS account. To do that, see Delete your account or data.
Sign in with Apple
- We receive a user ID from Apple and the email address you choose to share. If you choose Hide My Email, we get a private relay address (ending in
privaterelay.appleid.com) and Apple forwards our emails to your real address. We don’t learn your real address unless you give it to us. - The app asks Apple for your name when you sign in, but doesn’t keep it.
- If you use Hide My Email, give us the relay address as your account email when you contact us or request deletion.
To stop using your Apple Account with PapiDNS, on your iPhone or iPad open Settings, tap your name, then Sign-In & Security → Sign in with Apple. Choose PapiDNS and tap the option to stop using it. This doesn’t delete your PapiDNS account or data. To do that, see Delete your account or data.
PapiDNS doesn’t currently offer Facebook Login, and we don’t receive information from Facebook. If we add it, it will work like our other sign-in methods: we’ll receive your app-scoped Facebook user ID, name, email address (if your Facebook account has one and you allow it) and profile photo link, and use them only to create your account and sign you in. We’ll update this policy before then. Our deletion page explains how to delete any account, including one created with Facebook.
How long we keep your information
We keep personal information only as long as we need it for the purposes in this policy. This table shows how long, including the few things kept for a limited time after you delete your account.
| Data | How long | Why |
|---|---|---|
| Your sign-in record (including the IP address and device type of each signed-in session), your encrypted API keys with their names and settings, bug reports with their screenshots, and feature requests | Until you delete the item or your account. In-app account deletion removes all of this immediately. For requests made on our website, it’s removed within 30 days of you confirming the request. | To provide PapiDNS. |
| Our sign-in audit log entries (account ID, email address, the name your sign-in provider shares, and the time and type of each sign-in event) | Not deleted automatically, including when you delete your account. Ask through our contact form and we’ll delete yours within 30 days. | Security and investigating account problems. |
| Database backups | Roll off automatically within 30 days. | Recovering from outages or data loss. |
| Server, authentication and website request logs (for example, IP address and user agent) | Up to 30 days. | Security and troubleshooting. |
| Support emails, form submissions, deletion requests and the record that a deletion was completed | Up to 24 months. | Handling your request, and showing we met our legal and compliance obligations. |
| Purchase and subscription records held by Apple | Kept by Apple under its own policies. | Apple’s billing, tax and legal needs. |
Deleting your PapiDNS account doesn’t cancel a Premium subscription. Apple keeps billing you until you cancel it in your Apple Account settings.
Delete your account or data
What in-app deletion removes
These are deleted from our servers immediately and permanently:
- Your account and sign-in record
- Your encrypted API keys, with their names and settings
- Your bug reports and their screenshots, and your feature requests
A few things are kept after that, such as backups, logs, our sign-in audit log and the record of your request. See How long we keep your information. Deleting your account doesn’t delete anything at GoDaddy: your domains, records and GoDaddy API keys stay as they are. Delete the API key at GoDaddy too if you no longer need it.
Request deletion on the web
If you no longer have the app or can’t sign in, use our data deletion request form.
- Enter your PapiDNS account email address (your relay address if you use Hide My Email), how you sign in, and whether you want everything or only some of your data deleted.
- We email that address to check the request is really from you. We act only after you confirm.
- We complete the deletion within 30 days and email you when it’s done.
Delete only some of your data
You don’t have to delete your account to remove information. In the app you can:
- Delete a saved API key: in Settings, open the key’s menu and tap Delete. Its encrypted data is removed from our servers right away.
- Remove a remembered key from your device: in Settings, open the key’s menu and tap Forget passphrase on this device. Deactivate on this device, in the same menu, removes the note of which key is active.
To delete bug reports, screenshots or feature requests you’ve sent, choose “Delete only some of my data and keep my account” on the data deletion request form and tell us what to delete. We verify and complete partial requests the same way, within 30 days.
Your privacy rights
Wherever you live, you can delete your saved keys or your whole account at any time, and ask for a copy of your data or other help through our contact form. We don’t charge for this.
EEA, UK and Switzerland
Under the GDPR and similar laws, you have the right to:
- Access your personal information and get a copy of it
- Rectification: have inaccurate information corrected
- Erasure: have your information deleted
- Restriction: ask us to limit how we use your information
- Object to processing based on legitimate interests
- Portability: receive the information you gave us in a machine-readable format
- Complain to a data protection authority, in particular where you live or work, or where you think a violation happened
California
If you live in California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), gives you the right to:
- Know what personal information we collect, use and disclose, including the categories and specific pieces, the sources, the purposes and the categories of recipients
- Delete personal information we collected from you
- Correct inaccurate personal information
- Opt out of the sale or sharing of your personal information. We don’t sell or share it.
- Limit the use of sensitive personal information. We use it only in the ways described below, which this right doesn’t cover.
- Non-discrimination for using any of these rights
Categories of personal information we collect
In the past 12 months, we collected the categories below for the purposes in How we use your information, and disclosed them for business purposes only to the service providers shown. How long we keep each is in How long we keep your information.
| Category | What this means for PapiDNS | Sources | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers | Email address, PapiDNS account ID, your Apple or Google user ID, and IP address | You, your device, and Apple or Google when you sign in | Supabase, Vercel, Resend, Microsoft |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name and email address | You and your sign-in provider | Supabase, Resend, Microsoft |
| Internet or other electronic network activity information | Server, sign-in and website request logs | Your device and browser | Supabase, Vercel |
| Audio, electronic, visual or similar information | Screenshots you attach to bug reports or support messages, and the Google profile photo link | You and Google | Supabase, Resend, Microsoft |
| Sensitive personal information | Account credentials: your GoDaddy API key and secret, which we hold only in encrypted form we can’t read, and the session credentials that keep you signed in | You and your device | Supabase (encrypted form only for API keys) |
We don’t collect commercial information about you (Apple keeps your purchase records), geolocation, protected classification characteristics, biometric information, professional or employment information, or education information, and we don’t create inferences or profiles about you.
No selling or sharing
We don’t sell personal information, and we don’t share it for cross-context behavioral advertising. We haven’t done either in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16.
Sensitive personal information
The only sensitive personal information we handle is account credentials: your GoDaddy API key and secret, which we hold only in encrypted form that we can’t read, and the session credentials that keep you signed in. We use them only to provide PapiDNS, as California law permits, and never to infer characteristics about you.
How to make a request
- Use our contact form and choose “Other privacy question or request”. Enter the email address on your PapiDNS account so we can match your request to it.
- To delete your data, use the app or our data deletion request form.
Verification. To protect your account, we verify requests by emailing the address on your PapiDNS account and asking you to confirm. If we can’t verify a request that way, we may ask for more information, which we use only to verify you.
Authorized agents. You can have someone else make a request for you. We’ll ask the agent for your signed permission, and we may ask you to verify your identity with us directly, unless the agent holds a valid power of attorney.
Timing. We confirm California requests within 10 business days and respond within 45 days. We respond to GDPR requests within one month. Where the law allows us more time, we’ll tell you why.
Global Privacy Control. We honor GPC signals. See Do Not Track and Global Privacy Control.
Non-discrimination. We won’t deny you service, charge you a different price or give you a different level of service because you used your privacy rights.
Other US states
If you live in another state with a privacy law, you may have similar rights. Make a request the same way. If we decline it, you can appeal by replying to our decision, and we’ll respond within the time your state’s law requires.
Canada
If you live in Canada, you can ask to see the personal information we hold about you, ask us to correct it, and withdraw your consent to how we use it, subject to legal and contractual limits. Withdrawing consent may mean we can no longer provide PapiDNS. Make a request through our contact form. We store and process your information in the United States, where courts, law enforcement and national security authorities may be able to access it under U.S. law. If you aren’t satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada.
Legal bases for processing (EEA, UK and Switzerland)
If you’re in the EEA, the UK or Switzerland, we rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Creating your account, signing you in, and storing your encrypted API keys so they’re available on your devices | Performance of our contract with you (the Terms of service). |
| Checking whether each domain’s DNS is hosted at GoDaddy (the lookups described below) | Performance of our contract with you; it’s part of the domain list you asked to see. |
| Receiving and acting on bug reports and feature requests | Performance of our contract with you; legitimate interests in fixing and improving PapiDNS. |
| Security, abuse prevention, sign-in logs and website bot checks | Legitimate interests in protecting PapiDNS and its users; legal obligation where it applies. |
| Answering support, privacy and deletion requests, and keeping records of them | Performance of our contract with you; legal obligation; legitimate interests in showing that we handled your request. |
| Complying with the law and responding to lawful requests | Legal obligation. |
What’s required. To create a PapiDNS account, you need an Apple or Google account, and we need the user ID and email address your provider shares. To manage DNS, you need a GoDaddy API key. Bug reports, screenshots and feature requests are optional.
No automated decisions. We don’t make decisions about you based solely on automated processing, including profiling, that have legal or similarly significant effects on you.
Do Not Track and Global Privacy Control
Some browsers send a “Do Not Track” (DNT) signal. There’s no agreed standard for responding to it, so the website doesn’t change what it does when it receives one. The website doesn’t use advertising or analytics cookies, and we don’t allow third parties to collect information about your activity on our website across other websites over time.
We honor Global Privacy Control (GPC). If your browser sends a GPC signal, we treat it as a request to opt out of the sale or sharing of your personal information for that browser and, if we can link it to you, your account. We don’t sell or share personal information, so today it changes nothing, but we’ll keep honoring it.
The PapiDNS app doesn’t track you across other companies’ apps or websites.
International transfers
PapiDNS account data is stored in the United States. Our service providers may process information in the United States and other countries. If you use PapiDNS from outside the United States, your information is transferred to and processed in the United States, where data protection laws may differ from those where you live.
When we transfer personal information from the EEA, the UK or Switzerland, we rely on the safeguards our providers offer, such as the European Commission’s Standard Contractual Clauses (with the UK and Swiss additions) and, where a provider is certified, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. Contact us through our contact form for more information about these safeguards.
Security
We protect your information with:
- End-to-end encryption of your GoDaddy API keys, as described above
- Encryption in transit (TLS) between the app, this website and our servers
- Encryption at rest, provided by our hosting providers
- Database rules that let each account reach only its own data
- Access controls that limit who can reach production systems, with server keys kept off users’ devices
- No passwords to steal: you sign in through Apple or Google
No method of sending or storing data is completely secure, so we can’t guarantee absolute security. If a breach affects your personal information, we’ll notify you and the authorities as the law requires. To report a security problem, use our contact form.
Children
PapiDNS isn’t directed to children under 13, and you must be at least 13 to use it. If you’re under 18, or under the age of majority where you live, you may use PapiDNS only with your parent’s or guardian’s permission, as our Terms of service explain.
We don’t knowingly collect personal information from children under 13. If we learn that we have, we delete it. If you’re a parent or guardian and think your child has given us information, tell us through our contact form and we’ll delete it.
Changes to this policy
We may update this policy when PapiDNS or the law changes. When we do, we change the “Last updated” date at the top of this page. If a change is significant, we’ll also tell you in the app or by email before it takes effect.
Contact us
Trees and Rain LLC is responsible for PapiDNS and this policy. For privacy questions, requests or complaints:
- Contact form: www.papidns.app/support/
- Account or data deletion: www.papidns.app/deletion/
If you’re in the EEA, the UK or Switzerland and aren’t satisfied with our response, you can complain to your local data protection authority.
