Privacy Policy
Effective date: 2026-08-22
SvrGuard is designed around one principle: your data stays on your machine. This policy explains exactly what we collect — and what we don't.
0. Who controls your data
The data controller is XUHEI FUYUAN INFORMATION CO LTD (旭黑富源資訊有限公司), a limited company registered in Taiwan (R.O.C.), company number 66557794, registered office at 10F., No. 8, Sec. 1, Zhonghua Rd., Xinzhuang Dist., New Taipei City 242, Taiwan (R.O.C.), trading as SvrGuard.
Questions about this policy, or requests concerning your data: support@ofuyuan.com
1. This website
- This site is static and uses no tracking cookies and no third-party analytics.
- Browser localStorage stores only your language preference; it is sent to no one.
- Our web server keeps standard access logs (IP, time, request path) for security and debugging, deleted after 90 days.
2. The SvrGuard software (Free, standalone mode)
- Log analysis happens entirely on your host; your log contents and your visitors' data are never uploaded to us.
- Events and block records are stored in a local database on your host, fully under your control.
- The software works in fully offline environments and never requires a connection to our servers.
3. Fleet central mode (Pro)
When central reporting is enabled, the agent uploads only:
- Attack event summaries: attacking IP, rule code, severity, timestamp, GeoIP country/city, evidence summary;
- Host status: hostname, software version, time of last contact;
- Resource monitoring (CPU / memory / disk) is never uploaded — both the samples and the charts stay in the local database on your host;
- Machine identification: NIC MAC address and machine ID (used solely to tell one host from another, never as a security credential).
Never uploaded: whole log files, ordinary visitor traffic that triggered no rule, or the contents of any file on your host.
An “evidence summary” is the request lines that triggered the rule (time, method, path, status code and User-Agent), at most three, so you can see on the Hub what the block actually caught.
4. Accounts and payment
- Pro account data: username, email (for notifications), password (stored as a bcrypt hash — we cannot read it).
- Payments are processed by Paddle.com Market Ltd (Merchant of Record); card numbers never touch our systems. See paddle.com for their privacy policy.
5. Retention and your rights
- Event data on the central server is aggregated and pruned after 1 year; after account deletion, associated personal data is removed within 30 days.
- You may request access to, correction of, or deletion of your personal data at any time: support@ofuyuan.com.
6. Security
All external connections enforce HTTPS; passwords are always bcrypt-hashed; internal database identifiers are separated from public identifiers; management interfaces are access-restricted.
7. Updates to this policy
Material changes will be announced on this site with an updated effective date.