Privacy Policy
Last updated: August 31, 2026
Introduction
Guardway AI, Inc. ("Guardway", "we", "us", or "our") provides endpoint scanning, AI gateway, guardrail, and governance services for organisations that deploy AI agents, MCP servers, and related tooling. This Privacy Policy describes how we collect, use, store, and share information when you use our website (guardway.ai), our application (app.guardway.ai), and any associated APIs or services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you are using the Service on behalf of an organisation, you represent that you are authorised to accept this policy on its behalf.
Information We Collect
Account information: when you create an account, we collect your name, email address, organisation name, role, and billing details. If you sign in through a third-party identity provider, we receive the profile information that provider shares.
AI traffic data: when AI requests are routed through the Guardway gateway, the Service processes prompts, model responses, tool calls, and associated metadata (model name, provider, token counts, latency, cost) in order to apply guardrails, enforce policies, and generate analytics. We do not use your AI traffic data to train machine learning models. Prompts and responses are logged only for the guardrail and audit features you enable; self-hosted deployments keep all traffic data within your own infrastructure.
Endpoint scan data: the AI Endpoint Scan reads agent configurations, MCP server manifests, hooks, plugins, and related files on enrolled devices. Scans are read-only; the Service never executes discovered agents. Scan results are transmitted to the Service for inventory and risk scoring.
Usage and analytics data: we automatically collect information about how you interact with the Service, including pages visited, features used, timestamps, IP address, browser type, operating system, and referring URL.
Support and communications: when you contact us, we collect the content of your messages, along with any attachments you provide.
How We Use Your Information
To deliver and operate the Service, including endpoint scanning, gateway routing, guardrail enforcement, cost attribution, and dashboard analytics.
To manage your account, process billing, and communicate with you about the Service, including security advisories and feature updates.
To monitor and improve the reliability, performance, and security of the Service.
To detect and prevent fraud, abuse, and violations of our Terms of Use.
To comply with applicable legal obligations, respond to lawful requests, and protect our rights.
We do not use your personal information or AI traffic data for advertising. We do not sell personal information.
AI Traffic and Model Data
Guardway acts as a data processor for AI traffic that flows through the gateway. Prompts, responses, and tool calls are processed solely to deliver the features you configure: guardrail evaluation, policy enforcement, spend tracking, and audit logging.
We do not train, fine-tune, or otherwise use your AI traffic data to develop or improve our own models or any third-party models.
When you use the self-hosted deployment option, all AI traffic data remains within your own network and is never transmitted to Guardway-operated infrastructure. The SaaS deployment encrypts traffic data at rest and in transit and isolates it per tenant.
Data Sharing and Sub-processors
We share information only in the following circumstances:
Service providers: we use third-party providers for infrastructure hosting, email delivery, payment processing, and analytics. Each provider is bound by a data processing agreement and may access data only to the extent necessary to perform their function.
AI model providers: when the gateway routes requests to upstream AI providers (such as OpenAI, Anthropic, Google, AWS Bedrock, or Azure OpenAI), the prompt and associated metadata are transmitted to the provider you selected. Each provider's own privacy policy governs its handling of that data.
Legal requirements: we may disclose information when required by law, regulation, or valid legal process, or when we believe disclosure is necessary to protect the safety or rights of any person.
Business transfers: if Guardway is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
A list of current sub-processors is available upon request by emailing security@guardway.ai.
Cookies and Tracking Technologies
Our website uses essential cookies for authentication and session management. We also use analytics services (Vercel Analytics and PostHog) to understand how visitors use the site. Both are configured to respect Do Not Track signals.
We do not use advertising cookies or third-party tracking pixels. You can manage your cookie preferences through the Cookie Settings control in the site footer.
Data Retention
Account data is retained for as long as your account is active and for up to 90 days after closure to allow for reactivation or to resolve pending matters.
AI traffic logs (prompts, responses, guardrail decisions) are retained according to the retention period configured in your workspace settings. The default is 30 days; you may set a shorter or longer period depending on your plan.
Endpoint scan results are retained for up to 12 months to support drift detection and historical comparison.
Usage and analytics data is retained in aggregate form and is not linked to identifiable individuals after 12 months.
When data reaches the end of its retention period, it is deleted or anonymised within 30 days.
Data Security
We implement technical and organisational measures designed to protect your data. These include encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, audit logging, network segmentation, and regular security assessments.
Self-hosted deployments inherit the security controls of your own infrastructure. We provide hardening guidance and container image signing to support your security posture.
No method of transmission or storage is completely secure. If we become aware of a security breach that affects your personal data, we will notify you and any applicable regulatory authority in accordance with applicable law.
International Data Transfers
Guardway processes data in the United States and in the regions where our infrastructure providers operate. If you are located outside the United States, your information may be transferred to and processed in the United States or other jurisdictions.
For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission, supplemented by additional technical safeguards where appropriate.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access: request a copy of the personal data we hold about you. Correction: request that we correct inaccurate or incomplete data. Deletion: request that we delete your personal data, subject to legal retention requirements. Portability: request a machine-readable export of your data. Restriction: request that we limit certain processing of your data. Objection: object to processing based on legitimate interests.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what categories of personal information we collect and the right to opt out of the sale of personal information. We do not sell personal information.
To exercise any of these rights, contact us at security@guardway.ai. We will respond within 30 days (or within the period required by applicable law). We may ask you to verify your identity before fulfilling your request.
Children's Privacy
The Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child, we will take steps to delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a notice in the application at least 30 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
Contact
For privacy-related questions, data requests, or concerns, contact us at security@guardway.ai.