Privacy Policy

What we collect, why, and the control you keep.

Gardien is a security product. We collect what the checkpoint, dashboards, and account need to work — and design to store hashes and status rather than raw sensitive data wherever we can.

Last updated July 11, 2026

This policy explains how Gardien handles personal information across our website, dashboards, and the checkpoint that businesses embed on their own sites. For the personal data of a business customer's own end users, that business is the controller and Gardien acts as its processor under the terms below and the Data Processing Addendum.

What we collect

Data grouped by why it exists.

Account data

Name, email address, organization/workspace name, authentication provider, and role. Created when you sign up with Google or an email magic link.

Website & checkpoint config

Website names, domains you register, verifier rules, required verification levels, tracker settings, and webhook endpoints you configure.

Verifier & audit records

Agent passport IDs, site IDs, decision outcomes (allowed/blocked), reasons, request-timestamp and nonce, hashed IP and user-agent, and safe route/action patterns. Raw request bodies are not stored — only a hash.

Website analytics

When optional analytics are enabled and consented to: page path, query-free URL and referrer, page title, pseudonymous visitor and rotating session identifiers stored in the browser, screen size, language, timezone, bounded user-agent, coarse location derived from IP (the raw IP is not retained), and whether the request looks automated.

Operational performance telemetry

Cloudflare injects a cookie-free Web Analytics beacon for real-user page-performance measurement. Cloudflare states that Web Analytics does not collect or use visitors' personal data. This beacon does not create Gardien's pseudonymous visitor or session identifiers.

Protected customer vault (optional)

If a customer uses the vault, contact fields (name, email, phone, address) are encrypted at rest with AES-256-GCM, with a consent basis and a retention deadline recorded. Access is logged.

Support & billing

Messages you send us, and — once paid plans are enabled — subscription status. Card details are handled by our payment processor; Gardien does not store full card numbers.

Legal bases

Why we are allowed to process it.

ContractTo create your account, run the verifier, serve dashboards, and provide support you have requested.
Legitimate interestsTo secure the service, prevent abuse and fraud, debug, and improve reliability — balanced against your rights.
ConsentFor non-essential analytics/tracking cookies where consent is legally required, and for optional features. You may withdraw consent at any time.
Legal obligationTo meet security, tax, accounting, and lawful-request obligations.

How we use it

Operate, secure, support, comply.

We use information to run and secure the product: create and authenticate accounts, evaluate verifier decisions, enforce the policies you configure, produce your analytics, provide support, investigate abuse and security incidents, meet legal obligations, and communicate service and account information. We do not use your data to train advertising models, and we do not sell it.

Sharing & subprocessors

Who else touches the data.

CloudflareDNS, network security, edge delivery, and cookie-free Web Analytics performance measurement.
VercelApplication hosting, edge delivery, and product analytics (United States).
NeonManaged Postgres database storing account, configuration, verifier, and analytics records.
GoogleOAuth sign-in when you choose "Continue with Google."
ResendDelivery of transactional email such as magic-link sign-in messages.
Payment processorSubscription billing and card processing — activated only when paid plans launch.
ID verification providerThird-party identity checks for fully-verified passports — activated only when ID verification launches. Gardien receives a pass/fail result and safe metadata, never your ID document.

We share data with the vendors above only to run the service, each under a data-processing contract. We also disclose data when legally required, to protect Gardien or others from harm, or as part of a corporate transaction with notice. International transfers rely on Standard Contractual Clauses or an equivalent safeguard.

Retention

Kept only as long as needed.

Analytics event logs are retained for up to 90 days where lawful, then deleted. Durable verifier-log storage is not yet enabled for public customers; its retention schedule will be published and enforced before that feature launches. Account and configuration records are kept while your account is active and for a short period afterward for security and legal needs. Protected-vault records are deleted at the retention deadline set for each record. You can request earlier deletion; some records are retained where required for security, dispute resolution, or law.

Identity verification

We never store your ID document.

Fully-verified passports use a third-party identity-verification provider. The provider performs the document/ID check; Gardien receives only the result and safe metadata (for example, that a check passed and when). Raw identity documents, driver licenses, and passport scans are not sent to or stored by Gardien.

Your rights

Requests we honor.

  • Access a copy of your personal data
  • Correct inaccurate data
  • Delete data (subject to legal/security retention)
  • Export portable data
  • Restrict or object to certain processing
  • Withdraw consent you previously gave
  • Complain to your data-protection authority
  • Opt out — Gardien does not sell or share personal data for cross-context advertising

To exercise any right, contact us through the contact page. We will verify your request and respond within the timeframe the applicable law requires. Do not include passwords, private keys, or full customer records in your message.

Contact

Reach the privacy team.

Privacy questions and data requests: the contact page or admin.gardien.io@gmail.com. Gardien is currently an owner-operated project based in California and is not yet a separately registered legal entity. The operator's verified legal name and any legally required business notice details will be published before paid launch.