Privacy Policy
Last Updated: January 3, 2026 | GDPR, CCPA & LGPD Compliant
Global Privacy Compliance: This policy complies with GDPR (EU), CCPA (California), LGPD (Brazil), and other international privacy regulations. IronGuard's threat detection runs entirely on your device and never collects your browsing data. Personal data is processed only if you choose to create an optional Pro account.
1. Overview
IronGuard is designed with privacy as a fundamental principle, compliant with international privacy regulations including GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), and LGPD (Lei Geral de Proteção de Dados). This policy explains the two distinct parts of IronGuard and how each handles data: (1) the browser extension, which performs all threat detection locally on your device, and (2) our website and optional Pro accounts, which process limited personal data only when you sign up or subscribe.
2. Core Privacy Principles
2.1 Local, On-Device Threat Detection
All threat detection and analysis performed by the IronGuard extension happens entirely on your device. Your browsing history, the URLs you visit, and the contents of pages are never transmitted to us or to any third party for threat analysis.
2.2 No Tracking or Profiling
IronGuard does not use advertising networks, behavioral tracking, or analytics that profile you. We do not sell or rent personal data to anyone.
2.3 Accounts Are Optional
You can install and use IronGuard's protection for free without creating an account. An account is required only if you choose to purchase a Pro or Business subscription. When you create one, we process the personal data described in Section 3B below.
2.4 Data Minimization
For account holders, we collect only what is necessary to provide login, licensing, and billing—your email address, a securely hashed password, and subscription status. We do not collect your browsing activity even when you are signed in.
3A. Data Stored Locally by the Extension
The extension stores the following data locally on your device using the browser's local storage. This data stays on your device and is never transmitted to us:
- Protection Settings: Your protection preferences (enabled/disabled, protection mode)
- Whitelist: Domains you've explicitly whitelisted
- Statistics: Local counts of blocks, warnings, and allowed requests (no URLs or personal data)
- History: Recent threat detections (stored locally, not transmitted)
- Notification Preferences: Whether you've enabled desktop notifications
All of this data remains on your device. Uninstalling the extension removes it.
3B. Data We Process for Optional Accounts & Billing
If you create a Pro/Business account or make a purchase, we process the following personal data on our servers to provide the service (GDPR lawful basis: performance of a contract):
- Account: Email address, a securely hashed password (bcrypt), display name (optional), and your license key.
- Subscription: Plan, status, and billing period, so we can grant the features you paid for.
- Payments: Card payments are processed by Stripe and cryptocurrency payments by Coinbase Commerce. We do not store your full card number; those processors handle payment data under their own privacy policies. We retain a payment/transaction reference for accounting.
- Security logs: Limited technical logs (e.g., request metadata and IP address) are processed transiently to operate the API securely and prevent abuse.
We retain account and billing records for as long as your account is active and as required for tax and legal obligations, then delete or anonymize them.
4. Optional Threat Feed (Opt-In)
IronGuard includes an optional threat intelligence feed feature. This feature is disabled by default and requires explicit user opt-in.
If enabled:
- Threat feed data is fetched from external sources (configured by user)
- Feed data is cached locally on your device
- No personal information is transmitted when fetching feeds
- You can disable this feature at any time
If disabled (default), no external network requests are made for threat intelligence.
5. Permissions Explained
IronGuard requests the following browser permissions:
- webRequest: Required to intercept and analyze network requests
- webRequestBlocking: Required to block malicious requests
- storage: Required to store settings locally on your device
- tabs: Required to display threat information in browser tabs
- notifications: Required to show desktop alerts when threats are blocked
- <all_urls>: Required to protect all websites you visit
These permissions are used exclusively for threat protection and local storage. No data collected through these permissions is transmitted externally.
6. Third-Party Services
The extension does not use third-party analytics, advertising, or tracking. For our website and optional accounts we rely on a small number of processors strictly to deliver the service:
- Stripe — card payment processing.
- Coinbase Commerce — cryptocurrency payment processing.
- Cloudflare — CDN, DNS, and DDoS protection for our website and API.
Each processor handles data under its own privacy policy and applicable data-processing terms. We do not use advertising or cross-site tracking cookies.
7. Data Sharing
We do not sell or rent your personal data. We share the limited account and billing data described in Section 3B only with the payment and infrastructure processors listed above, and only as needed to operate the service, or where required by law.
8. Data Security
Extension data stays on your device under your browser's security model. For accounts, we protect data in transit with TLS/HTTPS, store passwords using bcrypt hashing, restrict administrative access, apply API rate limiting and security headers, and take regular encrypted database backups. No system is perfectly secure, but we follow industry-standard safeguards.
9. Children's Privacy
IronGuard is not directed to children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.
12. Your Rights (GDPR, CCPA, LGPD)
If you do not have an account, we hold no personal data about you and there is nothing to access or delete beyond the local data on your own device. If you are an account holder, you have the following rights over the data in Section 3B:
- Right to Access: Request a copy of the account and billing data we hold about you.
- Right to Deletion: Request deletion of your account and associated data, subject to legal/tax retention requirements.
- Right to Data Portability: Receive your account data in a portable, machine-readable format.
- Right to Rectification: Correct inaccurate account information such as your email or name.
- Right to Object / Restrict Processing: Object to or restrict certain processing where applicable.
- CCPA Right to Know / Delete / Opt-Out: California residents may request disclosure or deletion of personal information; we do not sell personal information.
- LGPD Rights: Brazilian residents may exercise the equivalent rights over their account data.
How to Exercise Your Rights: Contact us through our contact page (select "Privacy Inquiry"), or delete your account from your dashboard. We respond within the timeframes required by applicable law.
13. International Data Transfers
Extension: Threat detection runs locally on your device, so no browsing data crosses borders.
Accounts & billing: Account data is processed on our infrastructure and by our processors (Stripe, Coinbase Commerce, Cloudflare), which may process data outside your country. Where required, these transfers rely on appropriate safeguards such as Standard Contractual Clauses (SCCs).
14. Cookie Policy
Essential Cookies Only: IronGuard.ai uses only essential cookies for site functionality. We do NOT use:
- Tracking cookies
- Analytics cookies
- Advertising cookies
- Third-party cookies
- Social media cookies
Cookie Consent: In compliance with GDPR Article 7 and ePrivacy Directive, we request your consent before setting any cookies. You can accept or decline cookies through our cookie consent banner.
15. Data Protection Officer (DPO)
Given the limited scope of personal data we process (account and billing only), a designated DPO is not required under GDPR Article 37. For any privacy inquiry, please contact us through our contact page.
16. Supervisory Authority
GDPR: EU residents have the right to lodge a complaint with their local supervisory authority regarding how we process account data.
CCPA: California residents can contact the California Attorney General's office for CCPA-related inquiries.
LGPD: Brazilian residents can contact the Autoridade Nacional de Proteção de Dados (ANPD) for LGPD-related inquiries.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in regulations or our practices. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Continued use of IronGuard after changes constitutes acceptance of the updated policy.
18. Contact Us
For privacy-related questions, GDPR inquiries, CCPA requests, or LGPD concerns, please contact us through our contact page.
Privacy Email: For urgent privacy matters, please use our contact form and select "Privacy Inquiry" as the subject.
Privacy Guarantee: IronGuard is private by design. Threat detection runs entirely on your device—your browsing never leaves your browser. No tracking, no ad networks, no data selling. We process personal data only for the optional account and billing you explicitly choose.