← Back to GuardHound
Privacy Policy
Last updated: April 2026
1. Data We Collect
GuardHound collects the following categories of data:
- Account data: Email address and hashed password when you register. We never store plaintext passwords.
- Scan data: Domain names you scan, security scores, and findings. For monitored domains, scan history is retained according to your plan tier.
- WHOIS/RDAP data: Registrar name, nameserver lists, and domain expiry dates. We do not store personal registrant contact details (name, address, phone).
- Scan leads: If you provide your email during a free scan, we store it alongside the scanned domain and score to deliver your results.
- Organization membership data: If you create or join a team organization, we store the organization name, your membership role, and the date you joined. Invitation tokens are stored as a SHA-256 hash — the plaintext token is never retained after it is consumed.
- Payment data: Stripe handles all payment processing. We store only your Stripe customer ID and subscription ID — never credit card numbers.
- Server logs: IP addresses, timestamps, and request metadata for security and debugging. Logs are purged after 90 days.
2. How We Use Your Data
- To perform domain security scans and deliver results
- To send security alerts when issues are detected on your monitored domains
- To process payments and manage your subscription
- To improve the service and fix bugs
3. Third-Party Data Sources
GuardHound queries the following external services during scans:
- NVD (National Vulnerability Database): CVE vulnerability data provided by NIST. See nvd.nist.gov.
- RDAP (Registration Data Access Protocol): Public domain registration data via rdap.org. We only extract registrar, nameservers, and expiry — no personal data.
- Google DNS: DNSSEC validation and Safe Browsing status via Google Public DNS.
- CISA KEV: Known Exploited Vulnerabilities catalog from CISA.
- XposedOrNot: Public data breach records via the XposedOrNot free API. We query domain-level breach data only — no individual email addresses or passwords are transmitted or stored.
- crt.sh: Certificate Transparency logs for subdomain discovery via crt.sh.
4. Data Retention
- Account data: Retained until you delete your account.
- Scan results: Free: 7 days. Starter: 30 days. Pro, Business & Agency: full history.
- Scan leads: Retained for 12 months, then automatically purged.
- WHOIS snapshots: Retained for 1 year per domain, then purged.
- Organization membership records & invitation history: Deleted when you delete your account. If you are a member (not the owner), your membership record is removed; the organization and its other members are unaffected.
- Alerts: Retained for 90 days after acknowledgment.
- Server logs: 90 days.
5. Lawful Basis for Processing (GDPR Article 6)
We process your personal data under the following lawful bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the GuardHound service you signed up for, including domain scanning, monitoring, and alert delivery.
- Legitimate interest (Art. 6(1)(f)): Security logging, fraud prevention, and service improvement. We balance our interests against your rights and do not process sensitive data under this basis.
- Consent (Art. 6(1)(a)): Marketing emails and scan lead capture. You may withdraw consent at any time by unsubscribing or contacting us.
- Legal obligation (Art. 6(1)(c)): Where we are required to retain data for tax, fraud prevention, or regulatory compliance.
6. Data Controller
The data controller responsible for your personal data is:
If you are located in the EEA and have concerns about our data practices that we cannot resolve, you have the right to lodge a complaint with your local Data Protection Authority.
7. International Data Transfers
Your data may be processed in the United States or other countries where our infrastructure providers operate. When transferring data outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs): Approved by the European Commission for transfers to third countries.
- Adequacy decisions: Where the European Commission has determined that a country provides adequate data protection.
- Service provider agreements: Our infrastructure providers (database hosting, email delivery, payment processing) maintain appropriate safeguards for international transfers.
8. Your Rights (GDPR / CCPA)
You have the right to:
- Access: Request a copy of your data at any time.
- Deletion: Request deletion of your account and all associated data.
- Portability: Export your scan data in a machine-readable format.
- Correction: Update your email or account information.
- Opt-out: Unsubscribe from marketing emails at any time.
If you are in the European Economic Area, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not complied with applicable data protection laws.
To exercise any of these rights, contact us at privacy@guardhound.io.
9. Cookies & Tracking
GuardHound does not use third-party analytics scripts, advertising pixels, or cross-site tracking of any kind. We use essential browser storage (localStorage) for authentication tokens, and a small number of first-party cookies:
- Unlock cookie: set after you unlock a free scan report, so the report stays visible to you. Essential to that feature.
- Scan-session cookie (
gh_vsid): a random identifier (no personal data) that groups the free scans run from your browser over a 30-day period so we can tailor what we show to how you use the scanner, and to understand — in aggregate — how visitors first arrive at GuardHound. For that purpose we record, once per session, the first page you landed on, the referring website address (without any query parameters), campaign tags in the link you clicked (utm_* / ad-click identifiers), your approximate country (from a standard network header, never from IP lookup), and a coarse device type (desktop / mobile / tablet). It is never shared with third parties, never used across other websites, and the associated scan-session records (including the arrival details above) are automatically deleted after 90 days of inactivity, and the identifier is removed from any retained scan history and usage-event records at the same time. If your browser sends a Do Not Track or Global Privacy Control signal, this cookie is not set at all. You can also delete or block cookies in your browser at any time — the scanner works fully without it.
- Email open & click measurement: our marketing/outreach emails (never security alert emails) may contain a tiny invisible image and wrapped links so we can measure — per email campaign — whether the message was opened or a link was clicked. The measurement records carry only a truncated one-way hash of your email address, never the address itself, and are used solely to judge whether a campaign is useful. Every such email has a working one-click unsubscribe that stops all marketing email instantly.
10. Security
All data is transmitted over TLS. Passwords are hashed with bcrypt (12 rounds). Database access is restricted to the application server. We follow security best practices including input validation, rate limiting, and JWT token invalidation.
11. Children's Privacy
GuardHound is not intended for use by anyone under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will take steps to promptly delete that information. If you believe we have collected data from a child under 16, please contact us at privacy@guardhound.io.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to registered users. The "last updated" date at the top reflects the most recent revision.
13. Contact
For privacy inquiries: privacy@guardhound.io