Skip to content

Privacy

What the guard stores about you, and what it never stores.

What we store

Your account and what you and your agents put under it. Wallet addresses can identify a person, so we treat them as personal data.

  • Your account: the email you signed up with, the account name, and a hash of your password, held by the sign-in service. For a Google sign-in, the name, email address, picture, and sign-in tokens Google passes us, held the same way.
  • Your notification settings: the email address that hold notices go to, the webhook URL and the secret that signs each post to it, and the push address and keys your browser hands us when you turn on push notifications.
  • The agents you create, the policy you set, and your payee allow and deny lists, each entry a wallet address, its network, and the label you gave it.
  • Every decision: what your agent proposed (the seller URL, the price and payment terms, the payee wallet address, and the paying wallet address when your agent sends it), what your rules said, the content check's verdict with the first 2000 characters of the page your agent cited and the passages the check flagged, if your agent sent the page text with the payment, and for a held payment, who approved or denied it and any note they wrote.
  • Every page, document, or tool output your agent files: where it came from, a hash of it, the complete submitted text, and each check's result, score, configuration, and response. A repeated filing has its own record, including whether it reused an earlier result. The proxy also keeps the original seller payment-request body and payment terms used to prepare the text. Background comparisons have separate records and never replace earlier results.
  • Changes an administrator makes to content-check settings: the previous and new values, when they changed, and the administrator's account identity.
  • The settlements you or your agent report: the network, the transaction hash, the payer and payee wallet addresses, and the amount.

What we do not store

The guard does not request your wallet private keys and never holds funds. Content history does not copy the Guard API key, authorization headers, or cookies used to authenticate a request. It does retain secrets included in submitted text or seller data. It contains only the text and seller information submitted to us, not other pages your agent reads. We do not sell any of it.

What goes to the content check, and what we keep

The whole page, document, or tool output your agent files with us, up to 64 KiB, goes to the content check, a service we run for this product on Microsoft Azure. It comes back as flagged, clear, or unavailable. The dashboard shows the first 2000 characters and up to three passages of up to 4000 characters that the check flagged. The private history keeps the complete submitted text and check responses, including model versions, calibration, failures, and reuse of earlier results. An optional background model receives the same text and keeps its own result; it never changes a payment decision. These are model predictions, not verified labels. You can download your records through the API and from linked decisions. Another account cannot download your history.

Analytics

Two Vercel tools count visits to this site. Neither sets a cookie, and none of it carries a name, an email, or an IP address.

  • Web Analytics: the page, the referrer, the city the request came from, and the browser and device. It tells visitors apart with a hash of the request that it discards after a day.
  • Speed Insights: how fast the page drew, on about half of the visits, with the page, the connection speed, the browser, the device and its system, and the country. Nothing in it tells one visitor from another.

Cookies

Four kinds of cookie, all for the site to work and none for advertising.

  • __Secure-neon-auth.session_token and __Secure-neon-auth.local.session_data: your session, until it ends or you sign out, and a signed copy of it that lasts five minutes and is renewed while you use the site. A third, __Secure-neon-auth.session_challenge, lasts only while a Google sign-in is in flight.
  • vg_in: a mark that you are signed in, so the header can show the Dashboard link. Seven days.
  • agent: which of your agents the signed-in pages show. Until you close the browser.
  • demo-visitor: a random id that lets the demo meter its runs per browser. One year. It reaches the demo's rows only as a salted hash.

Signing in

Signing in creates a session record at the sign-in service that holds the session's network address and browser. For a Google sign-in that is your own address and browser. For a password sign-in the address and browser are our server's, because our server makes that call. Signing out removes it; a session that runs out on its own goes with the account when the account is deleted. Sign-in, sign-up, and password reset attempts are counted by a salted hash of your network address, so a burst from one network can be paused.

How long we keep it

Decisions and the complete submitted content history stay while your account is open. Removing an agent or expiring the working cache does not remove that history. The working cache can drop unflagged pages after 30 days without a reading; this does not delete saved inputs or check records. Settings change history remains for operating the service, with the editor's account identity removed when that account is deleted. Sign-in counts are dropped after a day.

Who processes it

Hosting and analytics are on Vercel, the database and the sign-in service on Neon (on Amazon Web Services), the content check on Microsoft Azure, and email through Resend. Our servers and data are in the United States. Google handles Google sign-in. A push notification travels through your browser maker's push service, encrypted so that service cannot read it.

Deleting your data

Write to info@vulsight.com and ask. Within 30 days we delete the account, its sign-in record, and everything under it, which is every item listed under What we store. Settings change history keeps the configuration values with your editor identity removed. Our processors' own logs follow their retention.

Who we are

VulSight runs this service. It is for people 18 and over. Write to info@vulsight.com about anything on this page, including for a copy of what we hold about you. When this page changes we update it here and change this date. Last updated 17 September 2026.