guardyn.dev

Privacy policy

Draft — have a lawyer review before you take payment.

What we collect

Account data

Your name, email address, a scrypt hash of your password, and if you enable two-factor, a TOTP secret and hashes of your recovery codes. Sign-in times and the IP address and user agent of each session, for the audit log.

Evidence from your machines

Whatever the checks you or the analyst run return. This can include process names and command lines, listening ports and connection endpoints, local account names, logon times, autorun entries, installed packages, browser extension names, browsing history and download metadata, cookie hosts (never values), file paths and hashes, and the contents of a small allowlist of forensic configuration files.

Much of this is personal data about whoever uses the machine. Deciding to collect it is your decision as the controller; we process it on your instruction.

Usage data

For each model call: which model, token counts, latency, what it cost us and what we charged you. This is what makes your bill explainable.

What we do not collect

Who we share it with

Evidence needed to answer a question is sent to the model provider you selected for that conversation — Anthropic, OpenAI, Google, or another provider your administrator configured. Nowhere else. It is not used to train any model.

Payment details are handled by Stripe and never reach our servers. Our sub-processors are listed at /legal/subprocessors.

How long we keep it

Conversations, tool results, snapshots and findings are kept for the history window your plan specifies — 14 days on Free, up to two years on Enterprise — then deleted. The credit ledger and the audit log are kept for seven years, because they are financial and security records. Deleting your workspace deletes everything except those two.

Your rights

Export, correction and deletion on request to privacy@guardyn.dev. If you are in the UK, EU or a comparable jurisdiction you also have the right to object, to restrict processing, and to complain to your supervisory authority.

Security

Everything we hand you is stored as a hash. Provider keys are encrypted at rest with AES-256-GCM. Traffic is TLS-only. The agent refuses to send anything over plain HTTP to a non-loopback host. Details in our security model.

Contact

privacy@guardyn.dev