Privacy Policy
Last updated: February 2026
1. Introduction
Data Guardian ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our secure data sharing platform.
2. Information We Collect
We collect the following information:
- Account Information: Your name and email address from your Google account when you sign in.
- Usage Data: Audit logs of link creation, access, and revocation events for security purposes.
- Shared Data: The data you choose to share through our platform, which is encrypted at rest using AES-256-GCM.
3. Zero-Knowledge Architecture
Data Guardian operates on a zero-knowledge principle. Your shared data is encrypted before storage, and we do not have the ability to read the content of your shared files or data. Encryption keys are derived per-session and never stored on our servers.
4. Data Retention
Shared data is automatically deleted when the secure link expires or is revoked. Account information is retained as long as your account is active. Audit logs are retained for security and compliance purposes.
5. Data Security
We implement industry-leading security measures including:
- AES-256-GCM encryption for all shared data
- HMAC-SHA256 for OTP hashing
- Rate limiting to prevent brute-force attacks
- Device and email binding for access control
- Screenshot detection and automatic revocation
6. Third-Party Services
We use the following third-party services:
- Google OAuth: For secure authentication
- Upstash Redis: For rate limiting and session management
7. Contact
For privacy-related inquiries, please contact us at privacy@dataguardian.app.