Privacy Policy
Last updated 2026-09-29
Maazul (https://maazul.com) lets you register a free subdomain under maazul.space and point it at a server you control. This policy explains what we collect, why, and what we do with it.
What we collect
- Account data. Your email address, and if you sign in with Google, the identifier Google assigns to your account. If you set a password we store only a salted hash of it, never the password itself.
- Subdomains and DNS records. The names you register and the IP addresses or hostnames you point them at. DNS records are public by nature: anyone on the internet can look them up.
- Dynamic DNS updates. When a device updates a record through the API, we store the IP address it submitted and the time of the update.
- Technical logs. IP address, user agent, requested URL, timestamp and outcome of requests. We use these to run the service, prevent abuse, enforce rate limits and debug problems.
- Payments. Card and wallet details are entered on Kashier's payment page and never reach our servers. We keep the order, amount, status and, for auto-renewing card subscriptions, an encrypted reference to the saved card plus its last four digits and brand.
- Cookies. One session cookie that keeps you signed in, and your language preference in your browser's local storage. We do not use advertising or tracking cookies.
How we use it
- To provide the service: publishing your DNS records, showing your dashboard, processing API calls.
- To keep the service safe: detecting abuse, phishing and malware, enforcing our Terms, and suspending accounts that break them.
- To contact you about your account, security issues or changes to the service. We do not send marketing email.
Who else sees your data
- Cloudflare hosts the application and database and sees request metadata as our infrastructure provider.
- Bunny.net operates the authoritative DNS servers. Your DNS records are published there and, like all DNS records, are visible to the public.
- Kashier processes payments and stores saved cards for auto-renewing subscriptions.
- Google, if you use Google sign-in, tells us your email address and account identifier. We never receive your Google password.
- We do not sell or share your data with anyone else, except when the law requires it or to respond to abuse reports.
How long we keep it
Account data stays until you delete your account or ask us to. Deleted subdomains are removed from DNS immediately; the record of the deletion is kept for a short period so the same name cannot be used to evade an abuse action. Technical logs are kept for a limited time, typically under 30 days, unless needed for an ongoing abuse investigation.
Your rights
You can see and edit your subdomains and DNS records from your dashboard at any time. To export or delete your account data, email us at ahmed.yaseen.dev@gmail.com from the address on the account. We answer within a reasonable time.
Security
Passwords are hashed with a slow, salted algorithm. Sessions and API tokens are stored only as keyed hashes. All traffic is encrypted in transit. No system is perfectly secure, so please use a unique password and keep your Dynamic DNS tokens private.
Children
The service is not directed at children under 16, and we do not knowingly collect their data.
Changes
If this policy changes in a meaningful way we will update the date above and, for significant changes, notify you by email.
Questions? Email ahmed.yaseen.dev@gmail.com. See also our Privacy Policy, Terms of Service and Refund Policy.