Privacy Policy
Last updated: July 2026
This policy is written in English; translations are provided for convenience only. If a translation conflicts with the English version, the English version governs.
Who We Are
a1l.com (“DMARC/25 SPF”) is a hosted SPF control-plane and email infrastructure checkup service — a TwoFive, Inc. product.
What We Collect
- Account data — When you sign in with a social provider (currently LinkedIn), we store the name and email address the provider shares with us. We never see or store a password.
- Organization and domain configuration — Organization names, domains, sender authorizations, mail streams, and policies you configure in the portal.
- Checker submissions — When you use the free homepage checkers: the domain you ask us to test, the email address the report should be sent to, your IP address, browser user-agent, browser language, and referring page (used for abuse prevention and rate limiting).
- Test email headers — For the “check your email sending” tool we analyze and store the headers of the test email you send to testme@a1l.com. We never store the message body or attachments.
- Audit trail — Administrative actions in the portal (requests, approvals, changes, revocations) are recorded in a tamper-evident log; that is a core product feature.
- DNS query metadata — Answering SPF lookups necessarily exposes the querying resolver’s IP address and the query name to our authoritative DNS servers; we use this operational data to run and protect the service.
Cookies
We do not use tracking or analytics cookies. The only cookie we set is a secure, httponly session cookie for signed-in users.
How We Use Your Data
- To provide the service and deliver the reports you request.
- Checker reports are also copied (BCC) to our operations mailbox for quality assurance and abuse monitoring.
- For security: rate limiting, anti-abuse, and incident investigation.
- For service communications. We do not send marketing email from checker submissions, and we never sell your data.
Data Retention
- Account and organization data — retained while your account is active.
- Audit trail — retained long-term; tamper-evidence is the point of the feature.
- Checker submissions and reports — retained for operations and abuse prevention; you may request deletion of your report email address.
Third-Party Sharing
We do not sell your data. We share data only with the processors needed to run the service (for example your social sign-in provider during login, and our hosting and DNS infrastructure), and when required by law.
Your Rights
You may request access to, correction of, or deletion of your personal data (for example your report email address) at any time by contacting us. Configuration and audit records that are not personal data may be retained.
Security
- TLS 1.3 encryption for all connections.
- No stored passwords; passkey and step-up checks protect sensitive changes.
- Minimal collection — we cannot leak what we do not store.
Changes to This Policy
We may update this policy from time to time. Significant changes will be announced on our website with at least 30 days notice. Continued use of the service after the notice period constitutes acceptance.
Contact
For privacy inquiries: privacy@a1l.com