Privacy Policy
Last updated: September 2026
This Privacy Policy is provided by ClearDNS, LLC, a Delaware limited liability company located at 8 The Green STE D, Dover, DE, US (referred to herein as "ClearDNS," "we," "us," or "our"). It describes how we handle information when you use the ClearDNS DNS filtering service ("Service"), our website, and our mobile applications.
At ClearDNS, privacy is not just a feature - it's our foundation. We've built our service from the ground up to minimize data collection while maximizing your protection online.
Our Privacy Philosophy
ClearDNS operates on a Zero-Identity principle. We believe effective DNS filtering doesn't require knowing who you are. ClearDNS works without any account or registration: no name, no email, no username, no password.
Zero-Identity does not mean zero data. ClearDNS is a DNS resolver and a commercial product: operating it necessarily means processing network and DNS information, and some product features deliberately retain technical information so the feature can exist. Instead of promising "no data", this policy tells you plainly what ClearDNS sees, what it forgets, what it retains, and why. The identifiers ClearDNS uses are pseudonymous technical identifiers that keep policies, members and devices working; they are not, and never become, a conventional personal identity such as your name or email.
For the full technical treatment of everything on this page, see the ClearDNS Transparency Center.
What We Don't Collect
- No account identity: ClearDNS does not require or maintain a name, email, username, password, postal address, or phone number as the identity of a DNS policy or device. There is no ClearDNS account database of personal profiles. (Information you voluntarily send us, for example by emailing support, is a separate matter; see "Communications You Initiate" below.)
- No browsing-history profiles: we do not build advertising or behavioral profiles from your DNS queries, and DNS data is never sold or shared with advertisers or data brokers.
- No third-party analytics on DNS: your DNS queries are never sent to advertisers, data brokers, or third-party analytics companies.
- No cross-device advertising tracking: we never track you across devices for advertising or share data with ad networks.
What a DNS Resolver Necessarily Sees
When your device asks ClearDNS to resolve a domain, we necessarily process, in real time: the domain name and record type being asked; the IP address the request comes from; the pseudonymous policy, member and device identifiers the request authenticates as; the time and protocol context of the request; and the filtering decision and answer we return.
Encrypted DNS (DNS-over-HTTPS and DNS-over-TLS) protects this exchange between your device and ClearDNS so networks in between can't read it. It does not mean the resolver itself can't see the question it is being asked to answer; answering the question is the service.
Processing this information to answer a request is not the same as keeping it. The sections below say exactly what is retained, by which feature, and for how long.
IP Addresses
Our resolvers necessarily receive the IP address your device connects from. An IP address identifies a network connection and does not by itself tell us your name. However, an IP address combined with an accurate timestamp can sometimes be correlated with subscriber records held by your internet provider or another party, so it can constitute personal data under applicable privacy law. We treat it accordingly. We process IP addresses for:
- Service delivery: routing your DNS queries and returning filtered responses.
- Approximate location: deriving an approximate country- and city-level location for dashboard features such as the activity map and network context. To do this we send the IP address to a third-party geolocation provider (ip-api.com).
- Security and abuse prevention: detecting and mitigating attacks, rate-limit evasion, and policy abuse. Records created for these purposes may include the IP address.
- Historical analytics: in product states that include historical analytics (see the next section), the network context of per-query analytics records can include the connecting IP address.
- Network History: a per-device record of network address changes (see "Network History and Device Activity" below).
We do not sell IP addresses, use them for advertising, or share them with data brokers.
Historical Query Analytics: Which Product States Retain History
Whether ClearDNS retains a history of your DNS queries depends on the product state you are in. Stated per state:
- Trial: the ClearDNS trial is a full-product trial. It includes historical analytics so you can evaluate the complete product before choosing a plan, so query analytics are recorded during the trial.
- Essential: no historical query analytics are retained.
- Analyze: historical query analytics are retained; that is the plan's defining feature.
- Stream: live visibility only (see below); no historical query analytics are retained.
- Full: historical analytics plus live features.
Choosing a plan with historical analytics is the product decision to retain query analytics; there is no separate off switch inside those plans, because history is what those plans are. Plans without historical analytics do not retain historical DNS analytics merely because ClearDNS is installed.
Historical records may include the DNS question, the time, the filtering result, pseudonymous policy/device context, and the network context needed to provide the feature. ClearDNS does not sell this history or use it for advertising. They are made available to you through your dashboard and its exports, and historical DNS query data is retained for no more than 90 days, then ages out automatically. Moving to a product state without historical analytics stops new historical query collection; if historical analytics is enabled again later, an earlier ended history period is not restored as part of the new history period. These are policy-linked technical records: they are keyed to your ClearDNS policy identifiers rather than to a name or email account, and ClearDNS does not use that technical linkage to construct a conventional human identity profile.
Live Visibility (Stream and Full)
Real-time features (Instant Logs, the Live Traffic Map) show recent DNS activity to an authorized dashboard while the feature is in use. They are separate from historical analytics and are not retained as 90-day historical query history.
Network History and Device Activity
Separately from any DNS query history, ClearDNS keeps a per-device record of network address changes: when a device's connecting IP address changes, we record the device relationship, the new address, and the time. The dashboard can show network name and approximate location for that context. This record contains no domain names and exists for device and network visibility.
ClearDNS uses recent service activity and lightweight connectivity checks to show whether a device has recently reached ClearDNS. These signals are used for device status, troubleshooting, and family and device administration; in rare family-safety situations they can help a parent see whether a child's device is still protected and connected. They are not DNS browsing history, and they do not provide GPS or precise physical location.
Security and Abuse Records
ClearDNS may retain limited technical and network metadata needed to prevent abuse, protect authentication, investigate incidents and secure the service. These records can include the connecting IP address. They are not DNS query history, do not include the domains you visit, and are retained for a limited period appropriate to their security purpose.
De-identified Service Intelligence
ClearDNS may use de-identified DNS observations to maintain and improve filtering quality. Before use in this service-intelligence context, ClearDNS policy/member/device identifiers and the client IP are removed. This data is separate from your policy-linked query history and is not used to reconstruct your browsing history. We use the term de-identified for this service-intelligence data because, after the stated identifiers are removed, it cannot be looked up by a ClearDNS policy/member/device identifier or client IP. It remains individual DNS observations and is not used to reconstruct a user's browsing history.
Aggregate Usage
We separately count coarse product and service usage (for example, how many queries a policy answered per hour). These counts contain no domain names and no IP addresses.
Mobile App
- Reinstall recovery identifier: the app may derive a one-way, device-scoped recovery identifier from platform-provided information so that an existing enrollment can be recovered after reinstall. It is not used for advertising or cross-app tracking.
- Device model and brand: basic device information (for example "iPhone" or "Pixel") is stored with your device identifier so you can recognize your devices in the dashboard.
- Subscriptions: if you subscribe through the app, purchase records are managed by Apple or Google. We receive the pseudonymous policy reference, store transaction identifiers, and subscription status; we do not receive your name, email, or payment details.
We do not use reinstall-recovery identifiers or store transaction identifiers for cross-app tracking or advertising. Operational policy, member and device identifiers may participate in ClearDNS's own first-party product attribution as described below.
Website and Product Analytics (First-Party)
ClearDNS is funded by paid subscriptions rather than by selling DNS data or running advertising against you. That means we need to understand which marketing and product investments actually produce trials and paying customers. We say this plainly: we measure customer acquisition and return on marketing investment, and we built our own first-party analytics system to do it without handing your data to an advertising platform.
This analytics runs on our own infrastructure. We do not use Google Analytics, the Meta pixel, or any third-party tracking scripts; nothing is sent to an external analytics provider; nothing is sold or shared with data brokers or advertisers. It is entirely separate from the DNS service and never receives your DNS queries. It collects:
- A random visitor identifier: stored in a first-party cookie and local storage; a random value that contains no name, email address, account credential, or other directly identifying account information, expiring after at most 180 days.
- Pages and events: the pages you view on our website, dashboard, block pages, and apps, and basic product interactions.
- Referrer and campaign information: the referring site, campaign parameters (UTM tags), and advertising click identifiers (such as gclid or fbclid) when present in the link you arrived from, used solely to measure which campaigns work. We may also record, at policy creation, which campaign or referral first brought you to ClearDNS.
- Approximate device and browser context: such as screen size, browser language, time zone, and browser type.
- IP address (transient): the connecting IP may be used transiently for approximate location and pseudonymous analytics and security processing; the raw IP is not retained in the first-party product-analytics record.
Linking to your product state: when you use the dashboard or app, we associate the visitor identifier with your pseudonymous policy, member, and device identifiers and plan state, so we can attribute a subscription to the marketing that produced it. These are the same pseudonymous tokens the DNS service uses, never your name or email, and this linking never leaves our first-party system. Attribution tells us "this campaign produced this subscription"; it does not read or contain DNS-query history.
Your choice: our analytics honors the Global Privacy Control and Do Not Track signals; if your browser sends either, no analytics cookie is set and no analytics data is collected. You can also clear cookies and local storage at any time.
Payments
Payment providers may know who paid; ClearDNS does not require your payment identity to become the identity used by the DNS service. The boundaries:
- Stripe processes web payments. Stripe receives your payment method details and a reference to your pseudonymous policy identifier. ClearDNS does not send Stripe your name or email.
- Apple and Google process in-app subscriptions under their own privacy policies. We receive the pseudonymous policy reference and subscription status, not your store account identity.
- Banks and payment networks behind these providers process payment data under their own obligations.
We cannot and do not claim to anonymize records held by Stripe, Apple, Google, or banks. What we can and do promise is on our side: inside ClearDNS, billing references attach to your pseudonymous policy, a DNS request never carries payment data, and payment information alone is never accepted as proof of policy ownership.
Communications You Initiate
If you contact ClearDNS (for example by emailing contact@cleardns.io), we receive the contact details and message contents you choose to provide. We use them to respond to you and support the interaction. Contacting us does not create a ClearDNS account, and we do not automatically make your contact details the identity of your DNS policy or devices.
Lawful Requests
Like any company, ClearDNS may receive legally valid requests for information. We can only provide information we actually possess, and the retention described on this page exists for product and security purposes, not for responding to such requests. Operating without a conventional personal account means there is no database of names, emails and passwords to produce. It does not make retained technical records immune from lawful process: where a retained record contains an IP address and a timestamp, a party holding subscriber records (such as an ISP) may in some circumstances be able to correlate it with a subscriber. We state this honestly rather than claiming there is nothing to ask for.
Third-Party Services
- Cloudflare: provides the global edge network our service runs on. Infrastructure involved in transporting or resolving requests can observe what its role technically requires.
- Stripe, Apple App Store, Google Play: payments, as described under "Payments".
- ip-api.com: IP geolocation, as described under "IP Addresses". We send the IP address being located and nothing else.
Each provider's practices are governed by its own privacy policy.
Data Retention
- Historical DNS query analytics (trial, Analyze, Full): no more than 90 days, then ages out automatically
- DNS queries (product states without historical analytics): processed in real time, not retained as query history
- Live visibility (Stream, Full): a real-time feature, not a historical query archive
- Device and network operational history: retained according to its operational and service purpose
- Security records: limited period appropriate to their security purpose
- Website and product analytics: visitor identifier up to 180 days; other records retained for product and campaign analysis
- Normal policy and device state: retained as needed to operate the active service and its lifecycle
Your Controls
- You control historical DNS collection through the ClearDNS product state you use: moving to a plan without historical analytics stops new historical query collection.
- You can remove a device or member from your policy at any time; this immediately ends that device's service authority. Ending a policy stops future policy-linked service activity. Records already created follow the retention rules described above and are not kept indefinitely.
- Removing the ClearDNS resolver configuration from a device stops further DNS-service activity from that configuration; ordinary website and app analytics can still occur if you later use those surfaces.
- You can opt out of website and product analytics via Global Privacy Control or Do Not Track, or by clearing cookies and local storage.
If you are located in the European Economic Area, you may have rights under the GDPR, including access, rectification, erasure, and data portability of personal data we hold. Because DNS policy records are pseudonymous and are not keyed to a name or email address, we may not always be able to connect a request from a person to a particular policy or retained record unless the requester provides information that allows us to verify that relationship. We do not require users to create additional identity information solely to make that linkage; where identification is not required for our processing, GDPR Article 11 may limit what we are obliged or able to do with an unverifiable request. Where we can verify a request and applicable law gives the requester a right, we will respond accordingly. You can reach us at contact@cleardns.io.
Children's Privacy
ClearDNS does not ask children to establish a conventional personal identity or provide a name, email, username or password. When a child's device uses a ClearDNS policy, the same technical network and DNS data described in this policy is processed pseudonymously, exactly as it is for adults. It is not used to build advertising or behavioral profiles.
Changes to This Policy
We may update this Privacy Policy from time to time and will post changes here with an updated revision date.
Contact
If you have questions about this Privacy Policy or our privacy practices, you can reach us at contact@cleardns.io.
By using ClearDNS, you acknowledge that you have read and understood this Privacy Policy.