Skip to content

Privacy Policy

Last updated:

What personal data Ward handles, why, for how long, who receives it and how to exercise your rights.

1.Who is responsible

Ward (“Ward”) is the controller of the personal data described in this policy, except where it acts as a processor (see “When Ward acts as a processor”).

Controller
Ward
Privacy contact
onboarding@resend.dev

2.What Ward does, in plain terms

Ward looks at how a company appears from the internet and explains what someone who wanted to attack it could take advantage of. It does this with public and technical sources. It doesn’t attack anyone and it doesn’t need access to your systems.

Ward hasn’t opened yet. Today we only handle data from the website and the waitlist. The rest of this policy describes the service that will open, and its processing starts when it opens.

What it does:

  • Queries public sources about the domain: DNS records, certificate records, domain registration records and third-party databases (reputation lists, vulnerabilities, leaks).
  • Visits your home page once, the way a browser would, and requests three standard public files (robots.txt, sitemap.xml and security.txt). It doesn’t follow links or probe other paths.
  • Monitors the domains you subscribe to and emails you about changes.
  • Ward AI answers your questions about findings and about the company’s situation.
  • The Analyzer reads an email, a link or a file you send it from the inside, without running it or opening the link.

What it never does: scan ports, try passwords, send malicious payloads, or get into your devices.

3.Where the data goes

The diagram summarizes what comes in, what is looked up outside, and what is kept and for how long. The same content is written out below it.

In
  • What you see and fill in on the website (visits, forms and the waitlist).
  • Your email and, if you enter it, your domain.
  • Your account, what you do in the dashboard, and what you write to Ward AI.
  • The emails, links and files you send to the Analyzer.
Looked up outside
  • Public and technical sources about the domain (DNS, certificates, third-party lists), with only what each query needs.
  • Our providers for hosting, email, database, artificial intelligence and, if enabled, Google Web Risk.
Kept for
  • The waitlist, up to 12 months. The trial report, 30 days.
  • The session, 30 days. Ward AI conversations, 90 days.
  • The Analyzer: the email body and code excerpts, 7 days; the rest, about 13 months.

4.What data we handle and why

For each processing activity we state what we use the data for, the legal basis (Article 6 GDPR), what the data is, how long we keep it, who receives it and whether it leaves the European Economic Area (EEA).

ProcessingLegal basisHow long
WaitlistConsent (Art. 6.1.a)Up to 12 months, or until you unsubscribe
Website and securityLegitimate interests (Art. 6.1.f)Hosting logs; limits, up to one day
Trial reportLegitimate interests (Art. 6.1.f)30 days
Account and sign-inContract (Art. 6.1.b)While the account is active
DashboardContract (Art. 6.1.b)While the account is active; events, 365 days
Analyzer and Ward AIContract (Art. 6.1.b)Analyzer: 7 days and 13 months; Ward AI: 90 days

Waitlist (launch notice)

Purpose
Telling you once, when Ward opens. If you also enter a domain in the home page notice, we will scan it when we open and send the report to that email. We don’t use the email or the domain for anything else and we don’t sell or share them.
Legal basis
Your consent (Art. 6.1.a), given when you submit the form, which states what the email is used for. You can withdraw it at any time by emailing onboarding@resend.dev; this doesn’t affect what was processed before.
Data
Your email; the plan you were interested in (if you choose one); the domain (only if you enter it); the language, the form you signed up from, and the date. In our database, also a keyed hash (HMAC) of your IP address, only to prevent abuse.
Retention
Until the launch notice or until you unsubscribe, and at most 12 months after you signed up. With our own database, the daily cleanup deletes expired entries. Until we have one, contacts are kept in Resend, and we delete them by hand when the period ends.
Recipients
Our database or, until we have one, a Resend contact list (processor). Hosting is provided by Vercel.
Transfers
Yes, to the U.S. (Resend and Vercel), with the safeguards described in the section “Processors and sub-processors”. Bot protection: a hidden field, a minimum fill time and a limit on sends per IP. If the email was already on the list, the response is the same, so we don’t reveal who is on it.

Website visits and security

Purpose
Serving the website, keeping it secure and preventing abuse (for example, mass use of a form or of the trial report).
Legal basis
Legitimate interests (Art. 6.1.f) in the security and continuity of the service. You can object by writing to the contact address.
Data
IP address and technical details of each request (browser, date, page), which the hosting provider records in its logs. For usage limits we keep only a keyed hash (HMAC) of the IP, never the IP itself. A strictly necessary cookie remembers the language (see the Cookie Notice).
Retention
Hosting logs, for the period Vercel sets. Limit counters last as long as each limit’s window (from one hour to one day) and are deleted in the daily cleanup.
Recipients
Vercel (hosting).
Transfers
Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.

Trial report (free scan of one domain)

Purpose
Scanning the domain you give us and showing you the result: the score, how many problems there are and how you could be attacked. No account or email is needed.
Legal basis
Legitimate interests (Art. 6.1.f) in providing the scan you ask for and in preventing its use against third parties. The impact is minimal: only public technical information about companies is consulted. You can object by writing to the contact address.
Data
The domain; the technical results (DNS, certificates, web headers…); a random browser identifier (a strictly necessary cookie; in the database we only store its hash); and a keyed hash (HMAC) of the IP for limits.
Retention
30 days. If you create an account from the same browser within 7 days after the scan, the scan moves to your account.
Recipients
Vercel, the database, Inngest (background tasks, internal identifiers only), Google Web Risk if enabled, and the sources described in “External data sources.”
Transfers
Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.

Accounts and sign-in

Purpose
Creating and managing your account, signing in with a one-time link (no password), and telling people and organizations apart.
Legal basis
Performance of a contract or pre-contract steps at your request (Art. 6.1.b). Account security is based on legitimate interests (Art. 6.1.f).
Data
Email, name (optional), language, sign-up and last-sign-in dates, your role in the organization and the organization’s name. For sign-in links and sessions we store only a hash of the code, never the code itself.
Retention
While the account is active. Sign-in links are valid for 15 minutes and are deleted in the daily cleanup; the session lasts 30 days. If you ask us to close the account, we delete its data, except what the law requires us to keep, which is blocked while claims could still be made.
Recipients
The database, Resend (sends the sign-in link) and Vercel.
Transfers
Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.

Dashboard

Purpose
Providing the service you subscribe to: regularly monitoring domains, showing findings and their history, managing them with your team, alerting you by email (immediate alerts, a weekly summary and expiry notices) and receiving DMARC reports.
Legal basis
Performance of a contract (Art. 6.1.b).
Data
Domains and the organization; results and findings; how they are handled (status, notes, comments and the files you attach: images or PDFs); the event history; your alert preferences; integration keys you add (encrypted); and, in aggregated DMARC reports, the IP addresses of sending servers and sender domains.
Retention
While the account is active. Event history, 365 days; DMARC reports, 13 months by default. If a domain or an organization is deleted, everything connected to it is deleted too.
Recipients
Vercel, the database, Inngest (scheduled tasks), Resend (alerts) and external sources.
Transfers
Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.

Alert recipients named by a customer

Purpose
Sending alerts or the weekly summary to people the customer names (for example, its IT lead or its adviser).
Legal basis
Legitimate interests (Art. 6.1.f) of the customer and of Ward in the information reaching the person who must act. The person first receives a confirmation email and nothing is sent until they confirm; they can unsubscribe with one click in each message.
Data
Email, language, which alerts they receive and from what severity, the confirmation date and a hash of the unsubscribe code.
Retention
Until the person unsubscribes or the customer removes them.
Recipients
The database and Resend.
Transfers
Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.

Monitoring the team’s email accounts

Purpose
Alerting the customer if the company email accounts it names appear in data breaches or on devices infected with malware.
Legal basis
The customer is the controller and must have its own legal basis (usually its legitimate interest in protecting its systems); Ward acts as processor. The customer must inform the people concerned.
Data
Email addresses, name (optional), the result of the lookup (name and date of the breach, types of data affected) and what you do about it. Passwords found are never stored.
Retention
While the account is being monitored and the customer’s account is active.
Recipients
The breach sources we query receive the domain or the addresses to check (see “External data sources”), in addition to our infrastructure providers.
Transfers
Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.

Ward AI’s Analyzer (suspicious emails, links and files)

Purpose
Analyzing a suspicious email (an .eml file or pasted source), a link or a file to say whether it looks like fraud, showing the result in the dashboard, alerting administrators if it is dangerous, and grouping the analyses of the same campaign.
Legal basis
Performance of a contract (Art. 6.1.b). The customer is responsible for the content it uploads, which may include third parties’ personal data (for example, the sender), and Ward acts as processor. The team must be informed.
Data

Email: the subject and sender (trimmed), the sanitized body text stored encrypted, and the technical details of the analysis (authentication, domains, disabled links, and the name, type, size and fingerprint of attachments). The .eml you upload is not stored, and attachments are never stored or opened.

Link: the URL without query parameters or fragment, the registrable domain and the technical signals. The full URL with parameters is not stored.

File: never the file itself. Only the trimmed name, the real type detected, the size, the SHA-256 fingerprint and the signals from static analysis. If the file contains suspicious code, short excerpts (up to 1,500 characters) are stored encrypted, never the whole code.

In all three cases: who ran the analysis (only owners, administrators and that person can see it), the verdict, the reasons and, if marked, the answer to “Have you clicked yet?”.

Retention
The email body and code excerpts, 7 days. The rest of the analysis (verdict, signals and metadata), 395 days (about 13 months).
Recipients
OpenRouter and the AI model receive a summary of the signals and, if there is any, sanitized and delimited text (never the file, nor the URL with parameters, nor email addresses; for code, up to 2,000 characters). Link addresses without parameters are checked against Google Web Risk if that source is enabled. Ward reads files from the inside, code included, but never visits a link or runs a file.
Transfers
Yes, to the U.S. (OpenRouter, the model provider, Google and our infrastructure), with the safeguards described in the section “Processors and sub-processors”.

Ward AI (assistant)

Purpose
Helping you understand and fix a finding step by step (the finding chat) and answering questions about the company’s situation (general chat).
Legal basis
Performance of a contract (Art. 6.1.b): used only when the person opens the chat.
Data
Your messages and the context we send with them: the finding you ask about or, in the general chat, a summary of the company’s situation (domains, scores, titles of the most serious findings and counts; no secrets, technical evidence or third parties’ personal data). We also keep usage counters, without content. Don’t enter passwords or unnecessary personal data.
Retention
90 days for conversations and their messages.
Recipients
OpenRouter, which routes the request to Anthropic’s model (today, Claude Haiku 5.5). We ask that only providers that don’t collect the data be used (data_collection = deny), and OpenRouter says it doesn’t train on it. Ward AI also writes explanations of public vulnerabilities (CVEs) from public data, with no customer data.
Transfers
Yes, to the U.S. (OpenRouter and Anthropic), with the safeguards described in the section “Processors and sub-processors”.

Questions and requests you send us

Purpose
Answering what you ask us or request, including the exercise of your rights.
Legal basis
Legitimate interests (Art. 6.1.f) in replying to whoever writes to us and, for rights requests, legal obligation (Art. 6.1.c).
Data
Your email, your name if you give it, the content of the message and our reply.
Retention
The time needed to handle the request and, afterwards, blocked while claims could still be made.
Recipients
The company’s email provider, as processor.
Transfers
We don’t move them out of the EEA; if the email provider processes them outside it, it does so with safeguards equivalent to those in this section.

5.External data sources

To scan a domain, Ward queries public and technical sources (DNS, domain registries, certificates) and third-party databases (reputation lists, vulnerabilities, leaks). These sources only receive what each query needs: usually a domain name, an IP address or a web address. This is company data and, except in isolated cases (for example, a sole trader with a domain in their own name), it is not personal data. The customer’s website receives a single visit to its home page and three standard public files. The full list, with licenses, is on the Sources page.

When a source receives personal data (for example, the email addresses being monitored), we treat it as a sub-processor. These are the ones active today, with their country (the list is generated from our source registry, so it only names the ones switched on):

  • Cert Spotter (United States)
  • GitHub (United States)

Where the country says “to be confirmed,” we are confirming it. The safeguards for each transfer are described in the next section.

6.Processors and sub-processors

These are the providers that process data on our behalf. With each one we sign the data processing agreement required by Article 28 GDPR. Some only take part when the related feature is switched on, and we say so. The links go to the provider’s documents where we checked the safeguard (consulted on October 8, 2026).

Vercel

Company
Vercel Inc.
Location
United States (and other countries where Vercel or its providers run infrastructure)
What it does
Hosting and running the website and the service.
Data it receives
Everything that goes through the website: the IP address and technical details of each request, and what is sent in forms.
Transfer safeguard
Vercel states that it is certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of July 10, 2023), and its data processing agreement also includes the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914).

Inngest

Company
Inngest Inc.
Location
United States (its databases are located there)
What it does
Runs the scheduled and background jobs: periodic scans, alerts and the daily cleanup.
Data it receives
Internal identifiers (of domains, scans and submissions) and counts. We don't send it email addresses or the content of the analyses.
When it is involved
Only once there are accounts and scheduled jobs, that is, after launch.
Transfer safeguard
Standard contractual clauses of the European Commission or another appropriate safeguard under Article 46 of the GDPR.

Resend

Company
Plus Five Five, Inc. (Resend)
Location
United States
What it does
Sends our emails (sign-in links, alerts and summaries) and, while there is no database of our own, stores the waitlist as a contact list (the email and, if configured, the domain entered in the notice on the home page).
Data it receives
Recipient email addresses, the content of each message and, for the waitlist, only the email address (and the domain, if one was entered and we have set Resend to keep it).
Transfer safeguard
Resend states that it complies with the EU-U.S. Data Privacy Framework and its UK Extension, and its data processing agreement includes the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914).

OpenRouter

Company
OpenRouter, Inc.
Location
United States
What it does
Artificial intelligence gateway: receives what we send to Ward AI (chat and Analyzer) and routes it to the model.
Data it receives
Chat messages and the context we send with them, and the summary of signals from what is analyzed with Analyzer. See “Ward AI” and “Analyzer” above.
When it is involved
Only when Ward AI is on.
Transfer safeguard
OpenRouter says in its privacy policy that, to transfer data outside the European Economic Area, it relies on standard contractual clauses approved by the European Commission (Article 46 GDPR). We also ask, in every request, that it only use providers that don't collect the data (the “data_collection: deny” option), and OpenRouter says it doesn't use inputs or outputs to train models.

Anthropic

Company
Anthropic PBC
Location
United States
What it does
Provider of the language model we use today (Claude Haiku 5.5), the one that writes Ward AI's replies. Ward doesn't contract with Anthropic: it receives requests through OpenRouter.
Data it receives
The same that OpenRouter routes to the model.
When it is involved
Only when Ward AI is on.
Transfer safeguard
Standard contractual clauses of the European Commission or another appropriate safeguard under Article 46 of the GDPR.

Google (Web Risk)

Company
Google Cloud
Location
United States (and other countries where Google runs infrastructure)
What it does
Web Risk service: says whether a web address is flagged as dangerous (malware or phishing).
Data it receives
The web address being checked (your domain's or, in Analyzer, a link's without query parameters or fragment).
When it is involved
Only when this source is on.
Transfer safeguard
Google Cloud's data processing addendum applies the European Commission's standard contractual clauses to transfers outside the EEA, unless Google adopts another recognized transfer solution, in which case it informs us.

Base de datos

Location
To be defined (EU or United States, depending on the provider)
What it does
Managed Postgres where accounts, domains, scans and everything else described in this policy are stored. During the pre-launch there may not be one.
Data it receives
All account and service data.
When it is involved
Only once there is a database. Before using it, this section will name the provider.
Transfer safeguard
Standard contractual clauses of the European Commission or another appropriate safeguard under Article 46 of the GDPR.

If we turn on phishing-mailbox intake (which would use Cloudflare to receive messages) or payments (Stripe), we will add them to this list before using them. Changes of provider are reflected here with the update date.

7.International transfers

Some of our providers are in the U.S. or process data there. To make those transfers lawful, we rely on, depending on the provider:

  • the EU-U.S. Data Privacy Framework, which the European Commission found adequate on July 10, 2023 (Implementing Decision (EU) 2023/1795), for certified companies;
  • the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914); or
  • another appropriate safeguard under Article 46 of the GDPR.

Each processor entry says which one applies. You can ask for a copy of the safeguards by emailing onboarding@resend.dev. More information on the Data Privacy Framework is at dataprivacyframework.gov(opens in a new tab).

8.How long we keep data

Each processing activity’s period is in its entry above. In summary:

DataPeriod
WaitlistUntil the launch notice or unsubscribe, and at most 12 months
Account and service dataWhile the account is active
Sign-in link15 minutes, single use
Session30 days, or until you sign out
Trial report30 days (7 days to move it to an account)
Event history365 days
DMARC reports13 months by default
Ward AI conversations90 days
Analyzer: email body and code7 days
Analyzer: the rest of the analysisAbout 13 months
Hosting logsThe period set by the provider

After those periods we delete the data or anonymize it. What the law requires us to keep is blocked and used only to handle possible claims.

9.Security and breach notification

  • All communications are encrypted (HTTPS).
  • For access codes and sessions we store only an encrypted hash, and for IP addresses only a keyed hash (HMAC), never the value itself.
  • The body of analyzed emails, code excerpts and integration keys are stored encrypted.
  • Each organization’s data is separated in the database with row-level security: one organization cannot see another’s data.
  • Only people who need the data to provide the service can access it.

If a security breach affects personal data, we will notify the Spanish Data Protection Agency within 72 hours where required (Article 33 GDPR), and the people affected without undue delay where the risk is high (Article 34). For U.S. residents, we will notify them as their state’s laws require.

10.When Ward acts as a processor

When a customer entrusts us with other people’s data (the team emails being monitored, alert recipients, the content the Analyzer examines, notes and attachments), the customer is the controller of that processing and Ward acts as processor: it only handles that data to provide the service to the customer and on its instructions, with the security measures in this policy and with the sub-processors listed here. The customer must have a legal basis for it and inform the people concerned.

The data processing agreement (Article 28 GDPR) will be published before the paid plans launch and is accepted when you subscribe.

11.Your rights (GDPR)

You can exercise these rights at any time, free of charge:

  • access: to know what data we hold about you and receive a copy;
  • rectification: to correct inaccurate data;
  • erasure: to have your data deleted when it is no longer needed, you withdraw consent, or there is no other basis for processing it;
  • objection: to object to processing based on legitimate interests;
  • restriction: to ask us to stop using the data while a question is resolved;
  • portability: to receive the data you gave us in a common format;
  • withdrawal of consent, where processing is based on consent (for example, the waitlist).

To exercise them, email onboarding@resend.dev and tell us which right you want to use. We may ask you to verify your identity. We reply within one month at most (extendable by two more months if the request is very complex; we would tell you). If a customer of ours is the controller of the data, we will tell you whom to contact.

If you believe we don’t process your data lawfully, you can complain to the Spanish Data Protection Agency (www.aepd.es(opens in a new tab); electronic office: sedeagpd.gob.es(opens in a new tab)). We would rather you wrote to us first so we can try to resolve it. If you live in another EU country, you can also contact the data protection authority there.

12.Automated decisions and profiling

The Ward Score and the findings are calculated by an automated system from public technical signals about a domain, that is, about a company and its infrastructure, not about a person. They don’t produce legal effects for anyone and don’t affect anyone in a similar way (Article 22 GDPR): they help the company fix its problems, and nobody uses them to decide about a person. We also don’t build profiles of people for commercial purposes.

The same is true of the Analyzer’s verdict on an email, link or file and of Ward AI’s answers: they are automated guidance that a person reviews and applies. If you think a result is wrong, tell us. Usage limits automatically and temporarily block excessive requests, with no further consequences.

13.Children

Ward is a service for businesses and is not directed to anyone under 16. We don’t knowingly collect data from anyone under that age. If we find we have, we delete it. We also don’t knowingly collect personal information from children under 13, as the Children’s Online Privacy Protection Act (COPPA) requires.

14.California residents (CCPA and CPRA)

This section is the notice for California residents required by the California Consumer Privacy Act (CCPA), as amended by the CPRA. It explains which categories of information we collect, why, and to whom we disclose it.

Categories we collect

CategoryExamples at WardCollected?
IdentifiersEmail, name (optional) and an encrypted hash of your IP addressYes
Account dataRole in the organization, language and organization nameYes
Technical and usage dataLogs of each request to the hosting provider, access datesYes
Content you send usMessages to Ward AI; emails, links and files sent to the Analyzer; notes and attachmentsYes
Commercial informationPlan you subscribe to or are interested inYes
Sensitive personal informationWe don’t ask for it. An analyzed email or file may contain it, and it is handled only for the analysisWe don’t seek it
Inferences and profilesWe don’t build profiles of peopleNo

Where it comes from

From you (when you sign up, use the dashboard or write to us), from your browser and device (the website and its technical logs), and from public sources about companies.

Why we use it and to whom we disclose it

For the purposes of each processing activity in this policy, not for advertising. We disclose it only to our processors (hosting, email, database, artificial intelligence and, if enabled, Google Web Risk), and only to provide the service.

Sale and “sharing”

We don’t sell personal information or share it for cross-context behavioral advertising, and we don’t use advertising trackers. For that reason there is no “Do Not Sell or Share” link and we have nothing to opt out of. We don’t use sensitive personal information beyond what the service requires.

Your rights

  • To know what personal information we have about you, and to receive a copy.
  • To ask us to correct it or delete it, except what the law requires us to keep.
  • Not to be treated differently (in price or service quality) for exercising your rights.

To exercise them, email onboarding@resend.dev. We may ask for information to verify your identity, and an authorized agent may submit the request for you. We respond within 45 days at most; if we need more time, we may extend it by another 45 days and tell you. If we deny a request, you can ask us to review it. A Global Privacy Control (GPC) signal from your browser changes nothing, because we don’t sell or share personal information.

15.Other U.S. states

Several states have privacy laws similar to California’s (for example, Virginia, Colorado, Connecticut, Utah and Texas). Depending on the state and the thresholds each law sets, they give similar rights: to know what data we hold, to obtain a copy, to correct or delete it, and to opt out of targeted advertising, sale or certain profiling. We will handle those requests through the same address, onboarding@resend.dev, using a procedure similar to the one for California.

16.Commercial emails

The emails we send to tell you about the launch or the launch offer are commercial. We send them only to people who have consented (Article 21 of Spain’s LSSI-CE and the GDPR). We also comply with the U.S. CAN-SPAM Act: each email identifies Ward and the company, includes our postal address and a working unsubscribe link, and we process each unsubscribe within 10 business days.

17.Changes to this policy

We may update this policy, for example when we open a new feature or change providers. The current version is the one on this page, with the date of the last update at the top. If a change is significant and we have your email through an account, we will tell you before it takes effect.