// Privacy Policy

Privacy Policy

Version 2026-09-08.draft-1 · effective 2026-09-08

Draft. This document has not had a legal review and will change before launch.

In short

  • Your messages stay on your phone. Our servers receive pattern, severity and confidence with the personal detail stripped.
  • Content leaves only inside an evidence package you build with consent, readable by the people it names and by us, with a receipt every time it is opened.
  • You can see, export and delete what we hold, and withdraw at any time.

1. What this policy covers

This policy describes what the Guardii apps and services do with information about you, about the people you message, and about the guardiians you choose. It applies to the iOS and Android apps, the guardii.ai website and the services behind them.

This version is a draft pending legal review. The version identifier at the bottom is what your account records when you accept it.

2. What stays on your phone

Guardii analyses the supported apps you connect on the phone itself. The messages it reads, the analysis of them and the results are held on the device, encrypted with a key that belongs to you.

The phone keeps a bounded window of what it has analysed so that an evidence package can be built later if you decide to build one. The window is currently around 90 days and is under review. When something is scored, a fingerprint of it is recorded at that moment so that anything later included in a package can be shown to match what was scored.

Nothing in this section reaches our servers in a form that can be read.

3. What reaches Guardii

Account information: your email address (or the relay address Apple gives us when you hide it), your name if you give it or your sign-in provider does, the age band you declare, your language, and the documents and versions you accepted. If you are a guardiian, the pairing that links you to the person who chose you.

Signal: when analysis finds something, the phone sends the pattern, its severity and its confidence, with the model version and rules that produced it. It sends no message text, no names and no handles. Our cloud models see this signal; they never see a message.

Product analytics: which screens and steps you used, and whether they succeeded, so we can see where the app fails people. No content and no free text.

Diagnostics: crash reports and performance data, with anything that could identify a message removed before it leaves the phone.

4. Evidence packages

An evidence package is the one route by which message content leaves your phone. You build it, on the device, under the consent ceremony for your age band, and you review its contents before it goes anywhere.

A package may carry your name and your handles on the platforms it covers, the handles of the people you were messaging on those platforms, and the messages themselves for the window it covers. It is encrypted to the recipients the consent names.

Those recipients can read it, and so can Guardii, because a sealed file nobody can open is not evidence. We hold it encrypted, every opening is receipted back to you (what was shared, with whom, who opened it and when), and it is destroyed on the schedule the consent set. Delivery is through an authenticated portal; we never send content through an unauthenticated link.

A queued package is checked again at the moment of sending. If you have withdrawn, or the request has been contested, it does not go.

5. Guardiians

A guardiian sees pattern summaries and coverage. There is no screen in Guardii that shows a guardiian message content, and identifiers from an evidence package never appear in a guardiian's view.

You see everything a guardiian sees, first or at the same moment. A guardiian who becomes involved in a concern is routed around automatically. When you remove a guardiian, their view goes idle without saying why.

6. Research data

Separately from protection, the app sends an anonymous count of which categories of harm were detected, for research and for measuring how well protection works. The Research Data Agreement describes exactly what a count contains and never contains, how counts are aggregated so that no one can be picked out, and how to stop. Aggregates are anonymous and may be kept indefinitely.

7. Who we share with

Evidence packages go to the recipients the consent names, and nobody else. A guardiian is the usual recipient; an institution such as a police force, a school or a support service is the exception, and only when the consent names it.

Service providers process data on our behalf under contract: cloud hosting (Amazon Web Services), error and performance monitoring, product analytics, and email delivery. They act on our instructions and do not receive message content.

Today the only lawful basis on which content leaves your phone is your consent. We do not disclose content in response to a request from an authority without a consent basis; how we handle a warrant is deferred and will be described here before it applies. Signal that carries no personal detail may be used in aggregate to understand harm patterns.

8. Where data is held

Guardii runs in a cloud region inside the jurisdiction it serves. For accounts created in the United Arab Emirates the services run in a region chosen to meet UAE residency requirements; the specific region is to be confirmed in the reviewed version. Analysis of your messages never leaves the phone.

9. How long we keep things

Account information is kept while the account exists and deleted when you delete it, except for records we must keep to show that consent existed and what it covered.

Signal is kept for as long as it is needed to show a pattern over time, and is pinned to the model and rules that produced it. Evidence packages are destroyed on the schedule the consent set. Anonymous aggregates may be kept indefinitely.

10. Your rights

You can see what we hold about you, correct your name and language, export your data, withdraw consent, remove a guardiian, and delete your account, all from the app. You receive a receipt for every evidence package that is opened. If something here is not working, write to us and we will answer within the time the law allows.

11. Children and young people

An account for someone under 13 is set up with an adult guardiian's agreement and the child's own assent. Between 13 and 17, the young person signs and an adult guardiian co-signs. Guardii asks for an age band only, never a birthday, and the band is what the person declares.

A child asking for help or showing distress is never treated as evidence that they have done something wrong.

12. Security

Data on the phone is encrypted with your key. Data we hold is encrypted at rest and in transit, access to it is logged, and evidence packages are readable only by the recipients named in the consent and by Guardii. We tell you and, where required, the regulator if a breach affects you.

13. Changes to this policy

Each version carries an identifier and an effective date. When a change affects what you agreed to, the app asks you to accept the new version before you continue.

14. Contact

Privacy questions and requests go to privacy@guardii.ai. The name and contact details of the data protection officer are to be confirmed in the reviewed version.