Privacy Policy
Last updated: 18 September 2026.
1. Who we are
Vault operates from 4087 Richmond Avenue, Staten Island, New York 10312, United States. For anything in this policy, write to support@guarder.io.
Vault watches a network you own or administer and tells you what is wrong with it. That means the sensor sees your network in detail, and this page is an honest account of what that detail is.
2. What the sensor collects
A sensor runs on your own premises and reports to the hub. It collects:
- Devices on the network — MAC address, IP address, hostname, manufacturer as inferred from the MAC, open ports, and when each was last seen.
- DNS lookups, if you turn DNS filtering on — the domain requested, which device asked, whether it was blocked, and when. This is the most revealing thing Vault holds, which is why it has the shortest retention below.
- Service checks — whether a site, host or certificate you asked Vault to watch is reachable, and the error when it is not.
- Presence — whether a known device is on the network, used to answer "is anyone home".
- Cameras and recorders — that they exist, whether they are reachable and whether they appear to be recording. Vault does not receive video or still images.
- Account data — your email address, the tenant name, and the sign-in and change history.
3. What Vault does not collect
- The contents of your traffic. Vault records that a lookup happened, not what was sent or received afterwards.
- Video, audio or images from cameras.
- Files from the devices it watches.
- Card numbers. Payments go to Stripe and no card detail reaches Vault.
Credentials the sensor needs to repair something are held on the sensor, on your premises. They are stripped from the payload before it is stored, not removed afterwards.
4. Why we hold it
To provide the product you asked for: to show the dashboard, raise alerts, run repairs you approve, and produce reports. We also keep an audit record of administrative changes so you can see who changed what. We do not sell it, and we do not use it to advertise.
5. How long it is kept
These are the product's defaults and are configurable per account:
- Raw DNS lookups: 7 days. After that they are aggregated into counts per domain and the individual rows are deleted.
- Aggregated DNS counts: 365 days.
- Metrics, events and presence samples: 90 days.
- Audit log: 365 days.
Alerts, devices and account records are kept while the account exists. Delete the account and they go with it.
6. Who else sees it
Vault uses a small number of processors and no advertising or analytics trackers:
- Stripe — payments and subscriptions. Stripe receives your billing details directly; we receive a reference, not a card.
- Zoho Mail — the mailbox that sends and receives Vault's email.
- Our hosting provider — runs the hub and holds the database.
We disclose data otherwise only where the law requires it.
7. Where it is stored
On servers in the United States. Data reaches them over TLS, and the sensor authenticates to the hub with a token rather than a password.
8. Your choices
- DNS filtering is off unless you enable it. Leave it off and no lookups are recorded.
- Export. Ask and we will give you your data before deleting it.
- Deletion. Ask and we delete the account and its data.
- Retention. The windows in section 5 can be shortened for your account.
If you are in the UK, EU or another region with statutory data rights, those rights apply and the same address reaches us.
9. Telling the people on the network
If you install Vault on a network other people use — an office, a shared house — you are responsible for telling them it is there and for having a basis to watch it. Vault gives you the tool; it cannot give you that permission.
10. Security
We report vulnerabilities and accept reports at /.well-known/security.txt.
11. Children
Vault is sold to adults for networks they administer and is not directed at children.
12. Changes
If this policy changes in a way that matters, we will say so in the product rather than only editing this page.