Privacy
What the guard stores about you, and what it never stores.
What we store
Your account and what you and your agents put under it. Wallet addresses can identify a person, so we treat them as personal data.
What we do not store
The guard does not request your wallet private keys and never holds funds. Content history does not copy the Guard API key, authorization headers, or cookies used to authenticate a request. It does retain secrets included in submitted text or seller data. It contains the text your agent submits and every answer the proxy files, not pages your agent reads some other way. We do not sell any of it.
What goes to the content check, and what we keep
The whole page, document, or tool output your agent files with us, and each answer the proxy files for it, up to 64 KiB, goes to the content check. It comes back as flagged, clear, or unavailable. The dashboard lets you read the complete submitted text and any saved flagged passages. Each result can include up to three passages of up to 4000 characters. The private history keeps the complete submitted text and check responses, including the settings each check ran under, failures, and reuse of earlier results. A second check we may run to compare results receives the same text and keeps its own result. It never changes a payment decision. A result is an automated judgment and can be wrong. Another account cannot see your history. For a copy of your records, write to info@vulsight.com.
Analytics
Two Vercel tools measure visits to public pages on this site. Private pages are not sent. Neither tool sets a cookie, and none of this data carries a name, an email, or an IP address.
Cookies
Four kinds of cookie, all for the site to work and none for advertising.
Signing in
Signing in creates a session record at the sign-in service that holds the session's network address and browser. For a Google sign-in that is your own address and browser. For a password sign-in the address and browser are our server's, because our server makes that call. Signing out removes it; a session that runs out on its own goes with the account when the account is deleted. Sign-in, sign-up, and password reset attempts are counted by a salted hash of your network address, so a burst from one network can be paused.
How long we keep it
Decisions and the complete submitted content history stay while your account is open. Removing an agent or expiring the working cache does not remove that history. The working cache can drop unflagged pages after 30 days without a reading; this does not delete saved inputs or check records. Settings change history remains for operating the service, with the editor's account identity removed when that account is deleted. Sign-in counts are dropped after a day. The public demo keeps its runs, with the salted hashes of the browser and network that ran each one, as the demo's record.
Who processes it
These services process your data for us. Our servers and the data we store are in the United States.
Deleting your data
Write to info@vulsight.com and ask. Within 30 days we delete the account, its sign-in record, and everything under it, which is every item listed under What we store. Settings change history keeps the configuration values with your editor identity removed. Our processors' own logs follow their retention.
Who we are
VulSight runs this service. It is for people 18 and over. Write to info@vulsight.com about anything on this page, including for a copy of what we hold about you. When this page changes we update it here and change this date. Last updated 28 September 2026.