Data processing terms
Last changed 16 September 2026.
When a check looks at your site it may see data that belongs to your customers. For that data you are the controller and we are the processor. These terms say what that means and they are part of our terms of service for every customer, with nothing to sign.
1. Roles
You decide what data your app holds and why. We process whatever a check encounters only to run the check and report on it to you. We act only on your instructions, which are: run the checks you asked for, on the sites you added, at the schedule you chose.
2. What is processed, and for how long
During a check: whatever your site shows a visitor or, for the deeper checks, a signed-in test user. That passes through memory and is not written down. What is stored: a count, column names, and one sample record blanked past its first two characters, plus blanked pictures. Stored findings are kept for as long as your account exists and for thirty days after.
3. Whose data, and what kind
Your users and customers. The kinds depend on your app; a check may encounter names, contact details, addresses, order and payment records, and whatever else your app holds. We do not seek out any category and we keep none of the values.
4. Security
- Keys you give us are encrypted at rest and never displayed again.
- Findings never hold a full record; the limit is enforced in the code that saves them.
- Access to production systems is limited to the people who run the service, with individual accounts.
- Everything travels over encrypted connections.
5. Who else processes it
We use these companies to run the service. Each sees only what its column says. We will tell account holders by email at least fourteen days before adding one, and you may close your account if you object.
| Company | What it does for us | What it sees |
|---|---|---|
| Supabase | Sign-in and the database that holds accounts, sites and findings | Your email address, your sites, your findings and scores |
| Stripe | Payments | Your email, your card details (which we never see), what you bought |
| Anthropic | Polishing the wording of a finding | Table names, column names and counts from a finding. Never a record, never a customer’s details |
| Resend | Sending email | Your email address and the message we send you |
| Google (PageSpeed Insights) | Measuring how fast your pages load | The public addresses of the pages we measure |
| Slack | Alerts, only if you connect it | The alert text you asked us to post |
6. Where it goes
Some of the companies above run in the United States. Where data about people in the UK or the European Union is transferred there, it is under the standard contractual clauses those companies publish, or an adequacy decision where one applies.
7. Requests from your customers
If one of your customers asks you to show, correct or delete their data and any of it is in a finding of yours, email us and we will do it within ten working days. In practice there is little to find: a finding holds one blanked sample, not their record.
8. If something goes wrong
If we learn of a breach of our systems affecting data we hold for you, we tell you by email within seventy-two hours of confirming it, with what we know, what it affects and what we are doing.
9. Checking on us
Once a year, on request, we will answer written questions about how we handle data and show you what this page describes in practice. We do not host on-site audits.
10. When it ends
When you close your account, or thirty days after you ask, everything we hold for you is deleted and removed from backups within a further thirty days. On request we confirm in writing.
11. The parties
The customer: whoever holds the account. The processor: HexSpire, HexSpire, Gujranwala, Punjab, Pakistan, reachable at support@guardcue.com. These terms apply from the moment an account is created and need no signature. If you need a signed copy for your own records, email us and we will send one.