Privacy
What the guard stores about you, and what it never stores.
What we store
Your account and what you and your agents put under it. Wallet addresses can identify a person, so we treat them as personal data.
What we do not store
The guard does not request your wallet private keys and never holds funds. Content history does not copy the Guard API key, authorization headers, or cookies used to authenticate a request. It does retain secrets included in submitted text or seller data. It contains only the text and seller information submitted to us, not other pages your agent reads. We do not sell any of it.
What goes to the content check, and what we keep
The whole page, document, or tool output your agent files with us, up to 64 KiB, goes to the content check, a service we run for this product on Microsoft Azure. It comes back as flagged, clear, or unavailable. The dashboard shows the first 2000 characters and up to three passages of up to 4000 characters that the check flagged. The private history keeps the complete submitted text and check responses, including model versions, calibration, failures, and reuse of earlier results. An optional background model receives the same text and keeps its own result; it never changes a payment decision. These are model predictions, not verified labels. You can download your records through the API and from linked decisions. Another account cannot download your history.
Analytics
Two Vercel tools count visits to this site. Neither sets a cookie, and none of it carries a name, an email, or an IP address.
Cookies
Four kinds of cookie, all for the site to work and none for advertising.
Signing in
Signing in creates a session record at the sign-in service that holds the session's network address and browser. For a Google sign-in that is your own address and browser. For a password sign-in the address and browser are our server's, because our server makes that call. Signing out removes it; a session that runs out on its own goes with the account when the account is deleted. Sign-in, sign-up, and password reset attempts are counted by a salted hash of your network address, so a burst from one network can be paused.
How long we keep it
Decisions and the complete submitted content history stay while your account is open. Removing an agent or expiring the working cache does not remove that history. The working cache can drop unflagged pages after 30 days without a reading; this does not delete saved inputs or check records. Settings change history remains for operating the service, with the editor's account identity removed when that account is deleted. Sign-in counts are dropped after a day.
Who processes it
Hosting and analytics are on Vercel, the database and the sign-in service on Neon (on Amazon Web Services), the content check on Microsoft Azure, and email through Resend. Our servers and data are in the United States. Google handles Google sign-in. A push notification travels through your browser maker's push service, encrypted so that service cannot read it.
Deleting your data
Write to info@vulsight.com and ask. Within 30 days we delete the account, its sign-in record, and everything under it, which is every item listed under What we store. Settings change history keeps the configuration values with your editor identity removed. Our processors' own logs follow their retention.
Who we are
VulSight runs this service. It is for people 18 and over. Write to info@vulsight.com about anything on this page, including for a copy of what we hold about you. When this page changes we update it here and change this date. Last updated 17 September 2026.