Transparent Security Architecture

SnipeDomains only requests the minimum permissions required to authenticate users and sync subscriptions securely.

Google OAuth Only No Gmail Access No Drive Access TLS 1.3 Encrypted Zero-Leak Policy Paddle Secured Billing

Transparent Data Architecture

Here is exactly what SnipeDomains collects — and what it explicitly cannot access.

What We Collect
  • Email address

    Account creation and subscription matching.

  • Basic profile info

    Name and avatar personalization via OAuth.

  • Subscription status

    Sync usage limits securely with Paddle.

  • Usage counters

    Enforce daily domain analysis quotas.

  • Domain analysis requests

    Real-time AI scoring on active domains.

  • Authentication token

    Secure browser session validation.

What We NEVER Access
  • Gmail emails

  • Google Drive files

  • Contacts

  • Passwords

  • Banking information

  • Credit card numbers

  • Personal messages

  • Browsing history outside supported sites

  • Private browsing activity

Targeted Execution Model

The extension remains dormant unless activated on supported domain research platforms.

Browser
Whitelisted Domain
Secure Analysis API
AI Scoring Engine

Active Only On

  • expireddomains.net
  • supported registrar pages
  • domain marketplaces
  • whitelisted research environments

Inactive On

  • Banking websites
  • Gmail & Workspace
  • Social media
  • Personal browsing
  • Unrelated websites
  • Internal/private systems

Enterprise Security Infrastructure

Modern authentication and encrypted communication standards.

Google OAuth Authentication

Uses secure OAuth 2.0 authentication. No passwords stored locally.

Token-Based Sessions

JWT-based session validation ensuring strictly authorized API access.

TLS 1.3 Encryption

All requests and domain data are strictly encrypted in transit.

No Password Storage

Passwords never touch SnipeDomains database infrastructure.

Secure Subscription Sync

Subscription limits verified securely server-side.

Paddle Merchant of Record

Payment and compliance handling fully delegated to Paddle.

Data Minimization

We only collect data strictly necessary for providing and maintaining the core service.

Zero-Leak Policy

User research data and watchlists are never sold, exposed, or reused for public models.

Investor Confidentiality

Your sniping strategies remain yours. We do not front-run your searches.

Does SnipeDomains read my Gmail?
No. We request the absolute minimum Google OAuth scopes (basic profile and email). We cannot read, send, or delete your emails.
Why does the extension require Google login?
Google login securely links your browser extension to your active subscription limits without requiring you to manage another password.
Does the extension monitor my browsing?
No. The extension is completely dormant unless you are actively navigating one of the explicitly supported domain marketplaces.
Is my domain research private?
Yes. Your analyzed domains and watchlists are strictly siloed and confidential.
Does SnipeDomains sell user data?
Never. We are an infrastructure tool for investors, not a data broker.
What permissions are required?
The extension requires host permissions strictly limited to the domains of our supported integrations (e.g., expireddomains.net).
Can I revoke access anytime?
Yes. You can revoke Google OAuth access instantly via your Google Account Security settings.
Is payment data stored?
No. Payment processing is completely offloaded to Paddle.com. We do not store or process credit cards.

Ready to use SnipeDomains securely?