Privacy Policy
Effective date: 2026-07-25
SvrGuard is designed around one principle: your data stays on your machine. This policy explains exactly what we collect — and what we don't.
1. This website
- This site is static and uses no tracking cookies and no third-party analytics.
- Browser localStorage stores only your language preference; it is sent to no one.
- Our web server keeps standard access logs (IP, time, request path) for security and debugging, deleted after 90 days.
2. The SvrGuard software (Free, standalone mode)
- Log analysis happens entirely on your host; your log contents and your visitors' data are never uploaded to us.
- Events and block records are stored in a local database on your host, fully under your control.
- The software works in fully offline environments and never requires a connection to our servers.
3. Fleet central mode (Pro)
When central reporting is enabled, the agent uploads only:
- Attack event summaries: attacking IP, rule code, severity, timestamp, GeoIP country/city, evidence summary;
- Host status: hostname, software version, heartbeat time, resource metrics (CPU / memory / disk usage);
- Seat identification: NIC MAC address and machine ID (used solely for seat accounting, never as a security credential).
Never uploaded: raw log lines, your website visitors' personal data, or the contents of any file on your host.
4. Accounts and payment
- Pro account data: username, email (for notifications), password (stored as a bcrypt hash — we cannot read it).
- Payments are processed by Lemon Squeezy (Merchant of Record); card numbers never touch our systems. See lemonsqueezy.com for their privacy policy.
5. Retention and your rights
- Event data on the central server is aggregated and pruned after 1 year; after account deletion, associated personal data is removed within 30 days.
- You may request access to, correction of, or deletion of your personal data at any time: support@ofuyuan.com.
6. Security
All external connections enforce HTTPS; passwords are always bcrypt-hashed; internal database identifiers are separated from public identifiers; management interfaces are access-restricted.
7. Updates to this policy
Material changes will be announced on this site with an updated effective date.