1. Overview
This Privacy Policy describes how CyberWardion ('we', 'us') processes data in connection with G.A.I.N., its browser extension, optional endpoint agent and web dashboard for AI visibility and policy control. Coverage depends on the components installed, the policies enabled and the integrations configured on each device.
2. Data We Process
G.A.I.N. processes the following categories of data: • Account email and organization membership, used for authentication and workspace access. • Organization and installation identifiers, device labels, and optional user or department associations supplied by the organization. • AI tool or API protocol and destination domain, used for visibility and reporting. A generic API protocol does not establish which application sent a request. • Event type, detector category, recorded policy action, severity, timestamp and content length. Event records can also include file type and size without the file body. • Sync, heartbeat, version and delivery status, used to monitor installations. • Credentials, policies, pending metadata records and deployment settings cached locally in browser storage or the agent's device profile for connection and offline operation.
3. Content and Event Records
G.A.I.N. event records contain metadata, not the original prompt text, sensitive values or file bodies. Supported content is inspected locally for policy decisions. The optional agent's enabled clipboard checks may read clipboard text locally; they do not add the clipboard body to event records. G.A.I.N. does not provide a keystroke or screenshot recording feature. Content that is allowed can still be sent to the AI provider by the user's application; that provider's processing and retention are governed separately.
4. How We Use Data
Data is used solely to provide the G.A.I.N. service: AI visibility across the organization, policy enforcement and warnings, deployment health monitoring, security incident response, and reporting (including Trust Reports). We do not sell data. We do not use data for advertising. We do not use data for creditworthiness or lending decisions.
5. Local Processing and Coverage
The extension inspects supported prompt inputs and supported files in the browser. The optional endpoint agent inspects requests routed through its configured integrations. Native applications and coding tools require an appropriate agent integration; installing an extension does not cover them. Unsupported file formats or requests may be blocked under restrictive policies. In hosted mode, event metadata is sent to the configured G.A.I.N. backend. In self-hosted mode, that backend is operated by the customer. Local credentials, cached policies and pending metadata records support operation between connections. A successful heartbeat reports connectivity, not proof that every application is covered.
6. Dashboard and Organization Admins
Authorized organization administrators can review event metadata, installation identifiers and labels, ownership and last check-in through the dashboard. They can filter and export supported metadata to review AI usage and recorded policy actions. Event records do not provide the original prompt or file body. Revoking an installation's access disconnects its enrollment; it does not establish that its software has been uninstalled.
7. Data Sharing
Infrastructure providers used to operate the hosted product include Supabase for authentication, database storage and backend functions, and Vercel for the website and dashboard. Organizations can request the applicable data processing terms and subprocessor information from CyberWardion. We do not share event data with advertisers, data brokers or analytics vendors for their own purposes.
8. Data Retention
Workspace administrators can enable an event-retention schedule of 30, 90, 180 or 365 days. An enabled schedule removes active event records older than the selected period; enabling it requires confirmation because it can delete historical records. Where automatic retention is not enabled, records remain until deletion is arranged with the organization. Trial expiry alone is not confirmation of deletion. Existing contractual deletion obligations and verified deletion requests continue to apply. Infrastructure backups have a separate lifecycle, so deletion from the active database does not immediately remove every backup copy. Account and configuration data is retained as needed to provide the service, handle account requests and meet applicable obligations. Contact support@cyberwardion.com to confirm the applicable schedule or request deletion.
9. Security
The hosted service uses TLS for network connections and access controls for workspace data. Its primary Supabase database is in eu-west-1 (Ireland). Authorized administrators can access device identifiers and installation status for deployment and incident review. Infrastructure backups are maintained separately from the active event records; deleting a record does not mean that every backup copy disappears immediately.
10. Your Choices and Requests
Users and organizations can request access to their data, correction of inaccurate data, or deletion of their data by contacting CyberWardion directly. We will respond to verifiable requests in accordance with applicable data protection law, including the GDPR.
11. Contact
If you have questions or concerns about this Privacy Policy or our data practices, contact us at: CyberWardion George Washington St 24, 1000 Sofia, Bulgaria Email: support@cyberwardion.com Website: https://www.cyberwardion.com