Legal

Privacy policy.

Effective 2026-06-13

This Privacy Policy explains how Guardino Technologies LLC, a limited liability company registered in the State of Wyoming, United States of America (file no. 2026-001882554), operating from Istanbul, Türkiye ("Guardino", "we", "us") collects and processes personal data when you use the guardino.ai DNS-filtering service, including its dashboard, marketing pages and APIs (together, the "Service").

Our corporate website at guardinotechnologies.com is governed by a separate, site-specific privacy policy; this policy covers the product.

Who we are (data controller)

Guardino Technologies LLC is a Wyoming-registered company (file no. 2026-001882554) providing DNS-level filtering and digital-wellness services at guardino.ai. The data controller for the Service is Guardino Technologies LLC, operating from Istanbul, Türkiye.

For privacy matters contact support@guardino.ai. Our registered mailing address is 30 N Gould St, STE R, Sheridan, WY 82801, United States; full entity details are in our Legal Notice.

What we collect

Account data: your email address and a hashed password, or — if you sign in with Google — your Google OAuth identifier; your name; and your plan tier. Authentication is handled by better-auth.

Billing data: subscription and payment identifiers from Stripe, our payment processor. We do not store your full card number; Stripe processes payments in USD.

DNS query metadata: the domain queried, the response status (allowed / blocked / cached), the category, and a timestamp. We do NOT store the IP address of the device making the query in long-term storage.

Service usage: the device label you assign, the profile attached to it, and aggregate counters (queries today, blocked today).

Operational logs: short-lived server logs for debugging and abuse prevention, retained for 14 days then deleted automatically.

Marketing-site analytics: on our marketing pages we use Microsoft Clarity (see the dedicated section below), which may record interaction events and set cookies.

What we do not collect

We do not log full browsing history. DNS gives us domain names, not URLs or page contents.

We do not sell, rent or share your DNS data with advertisers or third-party data brokers — ever.

We do not require your real name. Pseudonyms are welcome.

We do not run advertising trackers, ad cookies or session-recording tools inside the signed-in dashboard.

Why we process this data and our legal bases (GDPR Art. 6)

To run the DNS filtering service you signed up for — legal basis: performance of a contract (Art. 6(1)(b) GDPR).

To bill your subscription via Stripe — legal basis: performance of a contract (Art. 6(1)(b) GDPR).

To detect abuse, prevent attacks on the service and meet plan quotas — legal basis: our legitimate interests in running a secure, available service (Art. 6(1)(f) GDPR).

To send security alerts and product updates you have explicitly opted in to — legal basis: your consent (Art. 6(1)(a) GDPR), revocable any time in Settings → Notifications.

To understand and improve our marketing pages via Microsoft Clarity — legal basis: our legitimate interest in measuring and improving those pages (Art. 6(1)(f) GDPR). We do not run Clarity for visitors in jurisdictions that require prior opt-in consent (see the Microsoft Clarity section).

Microsoft Clarity (marketing-site analytics)

Our public marketing pages use Microsoft Clarity, an analytics product provided by Microsoft Corporation (tag id wheayvsjkj). Clarity captures how visitors interact with our marketing pages — including session recordings (anonymised cursor movement, clicks, scrolling and page navigation) and aggregated heatmaps — to help us understand usage and improve the pages.

Clarity may set cookies and use similar storage on your browser, and it may combine the behavioural data it collects with information Microsoft holds, as described in Microsoft's own terms. Clarity runs on the marketing site only; it is not loaded inside the authenticated dashboard.

We do not load Clarity for visitors in the EU/EEA, the United Kingdom, Switzerland or Türkiye, where prior opt-in consent would be required and we show no consent banner; everywhere else, Clarity loads only when your browser does not signal Global Privacy Control (GPC) or Do Not Track (DNT), both of which we honour. You can additionally opt out at any time using Microsoft's opt-out at clarity.microsoft.com, or by blocking cookies and scripts for this site in your browser. Microsoft's privacy practices are described at privacy.microsoft.com/privacystatement and the Clarity terms at clarity.microsoft.com/terms.

Cookies and similar storage

Strictly necessary — "better-auth.session_token": the session cookie that keeps you signed in. It is HTTP-only, Secure, SameSite=Lax, and scoped to .guardino.ai so it works across our subdomains. No consent is required for this strictly necessary cookie.

Preference — "NEXT_LOCALE": stores your chosen interface language so we can serve the right localisation.

Analytics — Microsoft Clarity cookies are set on the marketing pages only, under consent where applicable, as described above.

Full details are in our Cookie Policy.

Who we share data with (sub-processors)

Stripe — payment processing (Stripe, Inc.; privacy at stripe.com/privacy).

Cloudflare — content delivery and DDoS protection (Cloudflare, Inc.).

Hostinger — managed VPS hosting and DNS infrastructure (Hostinger International Ltd.).

Microsoft Clarity — marketing-site analytics (Microsoft Corporation).

Vercel — application hosting (Vercel, Inc.).

We update this list whenever a sub-processor changes; a current description is in our Sub-processors page. Material changes trigger an email notice.

International transfers

Because Guardino is a United States entity operating from Türkiye, your personal data is processed in the United States and may be processed in the European Union and Türkiye by us and our sub-processors, some of whom operate global infrastructure in the United States.

Where data leaves the EEA, the UK or Türkiye, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or your explicit consent where applicable.

Retention

Query logs: stored for 30 days by default so you can review activity (90 days on Pro, 1 year on Team). You can request immediate deletion at any time — delete your account from Settings or write to support@guardino.ai.

Aggregate counters: kept for the lifetime of the account so monthly stats and trends stay accurate.

Account data: kept for as long as your account exists, plus 30 days after deletion to handle billing reversals, then permanently erased.

Operational logs: 14 days, then deleted.

Your rights (GDPR / UK GDPR)

Access — request a copy of all data we hold about you, in machine-readable JSON.

Correction — fix anything inaccurate from the Settings page or by writing to us.

Deletion — request permanent erasure of your account and all linked data.

Portability — export your custom rules, profiles and notification preferences.

Restriction & objection — restrict or object to processing, and opt out of marketing emails at any time, instantly.

Where processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise any right, write to support@guardino.ai; we respond within one month. You also have the right to lodge a complaint with a supervisory authority.

EU/EEA representative (GDPR Art. 27)

Where required under Article 27 of the EU General Data Protection Regulation, our EU representative will be designated here — to be designated. Until a representative is formally appointed, data-protection enquiries from the EU/EEA may be directed to support@guardino.ai and will be handled directly by the controller.

California residents (CCPA/CPRA)

We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act, as amended by the CPRA.

California residents have the right to know, delete, correct, and to non-discrimination for exercising their rights. We honour the Global Privacy Control (GPC) browser signal as a valid opt-out of sale/share.

To exercise these rights, contact support@guardino.ai.

Turkish users (KVKK)

If you reside in Türkiye, the Turkish Personal Data Protection Law No. 6698 ("KVKK") applies. Guardino Technologies LLC acts as the data controller (veri sorumlusu) and processes your data on the legal grounds of contract performance and legitimate interest defined in KVKK Articles 5 and 6.

Your KVKK Article 11 rights — to learn whether your data is processed, request information, learn the purpose of processing, request correction, deletion or destruction, and object to automated decisions — apply identically to the rights listed above. To exercise them, write to support@guardino.ai in Turkish or English; we respond within 30 days.

Cross-border transfer: by signing up you acknowledge that your data is transferred to and processed in the United States by Guardino Technologies LLC (Wyoming), and by our sub-processors Stripe, Cloudflare, Hostinger, Microsoft Clarity and Vercel. We rely on KVKK Article 9 explicit consent for this transfer.

Children

Guardino is intended for adults who manage their own and their family's protection. We do not knowingly collect data from children under 16 (or under 13 where COPPA applies). If you believe a child has created an account, write to us and we will delete it.

Changes

When we change this policy materially, we email everyone with an active account at least 14 days in advance, and the "Effective" date above always shows the current version.

Contact

Privacy & data protection: support@guardino.ai

Data Protection Officer / KVKK: support@guardino.ai

Security: support@guardino.ai

General: support@guardino.ai

Mailing address: Guardino Technologies LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States.