Legal
Privacy Policy
How we handle your data and the data we process for the apps you monitor.
Last updated: 16 June 2026
1. Who we are
Guardification (“we”, “us”) provides application monitoring and security tooling. The data controller is [Legal entity name], [registered address]. For privacy questions, contact privacy@guardification.com.
2. Data we collect
We collect three broad categories of data:
a) Account data — when you sign in with Google, we receive your name, email address, and avatar URL from Google OAuth. We do not receive or store your Google password.
b) Telemetry from the apps you monitor — through our SDK and ingestion API, we collect:
- request metadata: route/path, HTTP method, status code, and response duration;
- the IP address and user-agent of clients making requests to your app, used to detect and attribute attacks (brute-force, scanning, abusive traffic);
- error events: error messages and stack traces;
- security events: detected attack signatures, recon probes, and missing security headers;
- results of code scans you run against repositories you connect.
c) Integration & billing data — encrypted OAuth tokens for connected services (e.g. GitHub), and billing details processed by Stripe (we store customer/subscription identifiers, not card numbers).
3. IP addresses & your end-users' data (controller / processor)
The telemetry above can include personal data of your end users — most notably their IP addresses. For that data, you are the data controller and we act as a data processor, processing it on your instructions to provide the monitoring and threat-detection service. You are responsible for having a lawful basis to send us this data and for informing your users in your own privacy notice. We process it only to deliver the service, never sell it, and make a Data Processing Agreement available on request.
4. How we use data
- to provide monitoring, dashboards, threat detection, and code scanning;
- to detect, attribute, and alert you to attacks and abuse against your apps;
- to authenticate you, manage your account, and process subscriptions;
- to secure, maintain, and improve the service.
Our lawful bases (where GDPR/UK GDPR applies) are: performance of our contract with you, our legitimate interests in securing and improving the service, and consent where required.
6. Data retention
Account data is kept while your account is active. High-volume time-series telemetry (requests, errors, security events — including client IP addresses) is retained for a rolling window of [retention period, e.g. 90 days]and then deleted or aggregated. You can request earlier deletion of a project’s data at any time.
7. How we protect data
- encryption in transit (TLS) and of sensitive secrets at rest (AES-256-GCM);
- API keys are stored only as salted hashes, never in plaintext;
- database row-level security and tenant isolation between organisations;
- security headers, rate limiting, audit logging, and dependency scanning.
To report a vulnerability, see our security.txt.
8. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, email privacy@guardification.com. For data about your end users that we process on your behalf, please direct requests to the customer (controller) whose app collected it.
10. International transfers
Our providers may process data in regions outside your own. Where required, such transfers are covered by appropriate safeguards (e.g. Standard Contractual Clauses).
11. Children
The service is not directed to children under 16, and we do not knowingly collect their data.
12. Changes to this policy
We may update this policy; material changes will be reflected by the “last updated” date above and, where appropriate, notified to you.
13. Contact
Questions about this policy or your data: privacy@guardification.com.