Privacy & logging

This is a plain-language product summary for the private beta, last updated 2 August 2026. It is not yet the complete legal privacy notice required before a paid public launch.

What happens by default

  • MoonDNS processes DNS requests and source network addresses to answer and protect the service.
  • Profiles keep aggregate query and block counters for analytics and reliability.
  • Raw query history starts Off for every profile.
  • Live-log events are processed for connected dashboard viewers and are not replayed as history by default.

Optional raw history

  • You can explicitly choose Off, 1 hour, 24 hours, 7 days, or 30 days per profile.
  • When enabled, query names and related DNS event metadata are stored in batches in EU-jurisdiction storage.
  • The dashboard can export retained history as NDJSON or delete it immediately from the live product.
  • MoonDNS does not promise recovery of raw query history from backups.

Accounts and profile identity

  • Account and profile settings, authentication sessions, rules, and setup metadata are stored to operate the service.
  • DoH and DoT identify a profile through a path or hostname.
  • Plain DNS can use a linked public IP; MoonDNS stores that address only when you configure linking or a dynamic updater.
  • Unlinked public-resolver clients receive normal, unfiltered DNS answers.

Infrastructure and upstream DNS

  • Cloudflare, Vultr, Rage4, and email-delivery providers process limited data needed to host, route, secure, or operate MoonDNS.
  • MoonDNS does not sell browsing data or use DNS query history for advertising.
  • The resolver uses QNAME minimization and does not deliberately add client-subnet data to upstream DNS queries.
  • Worker/runtime security telemetry is separate from customer raw DNS history.

Private-beta cleanup disclosure

A legacy backlog of expired retained-log chunks and historical private-beta raw-event backup copies is awaiting a controlled, verified purge. Product history reads already honor the selected retention window, but MoonDNS is not claiming guaranteed physical deletion on that schedule until the purge and backup transition are complete.

Your controls and the legal notice still required

The customer app provides a per-account storage summary, raw-history export/delete controls, and support-handled account deletion during private beta. Contact hello@moondns.io for access, correction, deletion, or another privacy request.

Before paid public launch, MoonDNS still needs a formal notice naming the legal controller, purposes and legal bases, recipient categories and transfers, retention rules, applicable rights, and complaint route. The detailed current product behavior is also documented at my.moondns.io/privacy.