Skip to main content
Datante

Legal

Privacy policy

Last updated: August 13, 2025

The short version: Datante does not log your DNS queries. We do not store your browsing history. We only keep the minimum data needed to run your subscription.

1. Who we are

Datante (“Datante,” “we,” “our,” or “us”) operates the website datante.com and the associated home-network privacy service. Our service routes your home router’s DNS through filtering profiles we manage on your behalf to block trackers built into smart-home and IoT devices.

2. What we collect

We collect the minimum information needed to operate your account and provide the service:

  • Email address — to create your account and send transactional messages (such as payment receipts).
  • Subscription status — whether your subscription is active or inactive, and your chosen privacy preset (Light, Balanced, or Strict).
  • DNS device ID — a randomly generated identifier used to route your router’s DNS queries to the correct filtering configuration.
  • Stripe customer ID — a reference ID used by our payment processor to manage your subscription. We do not store full payment card details.

We do not collect your name, phone number, home address, or any other personal identifiers beyond what is listed above.

3. What we do NOT collect

We are explicit about this because it matters:

  • DNS query logs — Datante does not log, store, or inspect the DNS queries made by your router or any device on your network. The analytics you see in your dashboard (blocked count, top domains) are fetched in real-time from our DNS resolver using your device ID and are never stored by us.
  • Browsing history — We do not track, record, or retain any record of the websites you visit or the domains your devices look up.
  • IP addresses — We do not log your IP address for tracking, advertising, or profiling purposes. We do keep a short-lived security request log that includes IP addresses solely for abuse prevention — see “Security and abuse-prevention logging” below. It is not used for tracking and is deleted after 30 days.
  • Device information — We do not fingerprint your browser or collect information about the devices on your network.

4. How we use your data

We use the data we collect exclusively to:

  • Create and maintain your account.
  • Provision and manage your DNS filtering profile with the privacy rules you selected.
  • Process subscription payments and send payment-related emails via Stripe.
  • Provide customer support when you contact us.
  • Comply with legal obligations.

We do not sell your data, share it with advertisers, or use it for any purpose beyond operating the service.

5. Third-party services

To provide the service, we share limited data with the following trusted third parties:

  • Supabase — hosts our database (email, subscription status, profile IDs). Data is stored in the US and protected by row-level security. See Supabase’s privacy policy.
  • Stripe — processes subscription payments. We share your email with Stripe so they can send payment receipts. We do not store your card number. See Stripe’s privacy policy.
  • DNS infrastructure provider — provides the DNS resolver infrastructure that processes your router’s filtering queries. We provision your profile with query logging disabled so your browsing activity is not recorded at the resolver level.

6. Data retention

We retain your account data (email, subscription status, DNS device ID) for as long as your account is active. If you cancel your subscription and request account deletion, we will delete your account data within 30 days, except where retention is required by law (e.g., invoice records required for tax compliance, which are retained for 7 years).

7. Your rights

Depending on your location, you may have the right to access, correct, or delete your personal data. To exercise these rights, email us at privacy@datante.com. We will respond within 30 days.

8. Security

We use industry-standard security practices including encrypted connections (HTTPS/TLS), row-level security in our database, and separation of service keys. No system is perfectly secure, but we take reasonable measures to protect your data from unauthorized access, alteration, or disclosure.

9. Security and abuse-prevention logging

To protect the service from bots, scraping, and abuse, our web servers keep a security request log of visits to our public (marketing) pages. Dashboard and account pages are not included, and visitors who have enabled “Disable activity recording” are excluded from this log except when a request is classified as automated (bot) traffic or comes from a network on our deny list. For each logged request we record:

  • The timestamp of the request
  • The requesting IP address
  • The HTTP method and response status (e.g., GET, 200 or 403)
  • The URL path requested (never query-string parameters)
  • The browser user-agent string
  • The referrer, reduced to its origin and path (never query strings or fragments); not recorded for blocked requests
  • Network information — the network operator (ASN and organization name) and country associated with the IP address, when available
  • For regular (non-bot) visitors, your anonymous session ID — the same random cookie identifier described in the analytics section, so automated traffic can be distinguished from real visits. Bot and deny-listed requests are never assigned a session ID.

Requests from networks on our abuse deny list are refused with an error and recorded in the same log regardless of which page was requested, so blocked traffic can be audited. For those blocked requests only the timestamp, IP address, method and status, path, and user-agent string are recorded.

This log never contains request bodies, cookies, session tokens, auth headers, or any other credentials.

Retention: entries are automatically deleted after 30 days.

Legal basis: we process this data under our legitimate interest in keeping the service secure and available (GDPR Art. 6(1)(f)). It is used only for security and abuse-prevention purposes — never for advertising, profiling, or tracking.

Access: the log is accessible only to Datante administrators and is never shared with third parties, except where required by law.

10. Product analytics and experimentation

Datante collects a small set of product events to measure service reliability and understand how features are used. All events are fired server-side — they cannot be intercepted or blocked by browser extensions or DNS-level ad blockers.

Events we collect:

  • visit.page_view — anonymous visit to a public page; contains the URL path (never query-string parameters).
  • op.preset_changed — you changed your protection level (e.g., Essential → Standard); contains the from/to level names only.
  • op.filtering_paused / op.filtering_resumed — you paused filtering (contains the duration) or filtering resumed.
  • conversion.subscribe — your subscription became active.
  • conversion.install — you downloaded the optional desktop extension ZIP. Fired server-side when you click the download link in your dashboard.

Every event payload contains only your anonymous session ID, your account ID (for authenticated events), the event type, and the URL path. No query-string parameters are ever included.

What we NEVER collect in analytics events:

  • Page content or DOM snapshots
  • Browsing history or previously visited URLs
  • URL query-string parameters
  • DNS query history or blocked-domain lists
  • Search queries (including queries typed in the /help search box)
  • AI prompts or AI-generated responses
  • Session tokens, auth tokens, API keys, or passwords
  • IndexedDB contents or localStorage values
  • Your household ID or resolver IP address

A note on the desktop extension: The optional Datante Remote browser extension has no analytics runtime of its own. It cannot see your browsing history, tabs, or page content. The only analytics event associated with the extension isextension_downloaded, which is fired server-side when you download the ZIP from your dashboard — not by the extension itself.

How to opt out: Go to Dashboard → Account → Privacy and enable “Disable activity recording.” When this option is on, no analytics events are sent — not even page views. Operator accounts (ISP support staff) are excluded from analytics automatically and do not need to opt out.

We do not share analytics data with third-party advertising networks. Events are processed by our own internal analytics platform.

11. Changes to this policy

We may update this policy as the service evolves. Material changes will be announced by email to active subscribers at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the current version.

12. Contact

Questions about this policy? Reach us at privacy@datante.com.

Privacy Policy — How Datante Protects Your Home Data — Datante