Privacy Notice
Last updated 3 October 2026.
Who we are
SafeGrd is provided by Kush Kumar Sharma, a sole proprietor trading as SafeGrd, of Bengaluru, India - 560048. We are the controller of the personal data we collect about users of our website and service. For personal data inside what you back up, you are the controller and we act as your processor under our Data Processing Agreement. For anything about your data, write to support@safegrd.dev.
Your backups and your key
Your database, file and mailbox backups are compressed and encrypted on your own machine before they leave it. They are written either to storage in your own cloud account or to compliance-locked object storage provided by SafeGrd, and kept there only as encrypted bytes. By default we never receive your database passwords, mailbox credentials or storage keys. With a customer-managed key, we never receive your private encryption key, so we cannot read your backups.
You can choose to have SafeGrd hold some of these instead: a database or mailbox credential for a surface, your storage bucket's secret key, or (with SafeGrd-managed key custody) your private encryption key. Each is a separate choice, and the console shows which ones you made. Whatever we hold is stored encrypted under per-organization envelope protection, released only to your enrolled machines when they run a backup or restore drill, and recorded on every release. It is never displayed in the console or readable through the API.
With SafeGrd-managed key custody you can also choose to run a surface’s restore drills on SafeGrd instead of on your own machines. This is the only case in which we decrypt a backup. Each drill runs on a virtual machine of its own, which downloads one snapshot from SafeGrd-hosted storage, decrypts it with your key, restores it into a temporary database or reads it in memory, checks it, and reports the result. The machine runs nothing for anyone else, and it is destroyed with everything restored on it when the drill ends or reaches its time limit. Your key access record shows each release to a drill. The restored data never reaches our control plane, which keeps only the drill’s result.
With SafeGrd-managed key custody you can also have SafeGrd take a database’s backups from a connection string you give us to hold. Each backup runs on a virtual machine of its own, which is given that connection string for that backup alone, connects to your database, dumps it, encrypts it to your key and writes it to SafeGrd-hosted storage. That machine is never given your key, and it is destroyed when the backup ends. Your key access record shows each release of the connection string. The dump never reaches our control plane, which keeps only the backup’s record.
What we collect, and why
- Account details — your name, email address and a one-way hash of your password (never the password itself). Why: to create and secure your account, sign you in, and send account and security email. Legal basis: performance of our contract with you.
- Organization and team details — organization and project names, and the email addresses of people you invite. Why: to run the workspaces you create and let you invite your team. Legal basis: contract.
- Backup metadata and evidence — the names you give to protected surfaces and hosts, schedules, and for each backup and restore drill: timestamps, sizes, item counts, checksums and pass/fail results. No backup contents. Why: this is the evidence the product sells — that your backups exist and restore. Legal basis: contract.
- Technical and security data — IP addresses, browser and client versions, and request logs. Why: to keep the service secure, stop abuse (for example rate-limiting sign-in attempts), and fix faults. Legal basis: our legitimate interest in running a secure, reliable service.
- Billing status — which plan you are on and whether your subscription is active, as reported by the Merchant of Record that took your order. We never see or store your card details. Why: to give you the plan you pay for. Legal basis: contract.
- Hosted backups, only if you choose SafeGrd-hosted storage — your backups as encrypted bytes, which we store and cannot read, with the size and lock date of each. Why: to keep them for you. Legal basis: contract.
- Drills run on SafeGrd, only if you choose them: the contents of one snapshot, decrypted on that drill’s machine for the length of the drill and then destroyed with it. Why: to prove the backup restores. Legal basis: contract.
- Support messages — what you write to us. Why: to help you. Legal basis: contract, or our legitimate interest in answering you.
We do not sell personal data, and we do not use it for advertising.
Who we share it with
- Paddle.com, our Merchant of Record and reseller. It sells the subscription to you, takes payment, manages the subscription, and handles tax and invoicing. It collects your payment details itself, as an independent controller, under its own privacy notice: Paddle’s. We share your email address and organization with it to open the order.
- Service providers who run parts of the service for us under contract: our cloud hosting and database infrastructure provider; our email delivery provider, which sends account and security email; for SafeGrd-hosted storage only, our object storage provider, which stores those backups as encrypted bytes; and, for drills you run on SafeGrd only, our compute provider, which runs each drill’s machine. See our Sub-processors page for the current list and locations.
- Google Analytics (Google LLC), only if you allow it, and on our public pages only — the home page, the documentation and these legal pages — to count visits and see which pages are read. It is never loaded in the console or on the sign-in, sign-up, password-reset or verification pages. See Google’s privacy policy.
- Destinations you configure: if you connect a Slack or Discord webhook, alerts about your backups are sent there.
- Professional advisers (legal, accounting) where needed, and authorities where the law requires it or to protect the rights and safety of our users or others.
A complete, up-to-date register of our third-party processors is published on our Sub-processors page.
International transfers
Our servers are in the United States. If you use SafeGrd from elsewhere, your account data is transferred there. Where the law you are under requires it, we rely on appropriate safeguards for those transfers, such as the standard contractual clauses approved for this purpose.
How long we keep it
- Account, organization and backup-evidence records: while your account is open. When you ask us to close your account, by email, we delete or anonymize them within 30 days.
- A deleted organization: deleting it in the console takes it out of the service at once, and we keep its records for 12 months so we can restore it if you ask, then erase them. Write to support@safegrd.dev to have them erased sooner, and we do so within 30 days.
- Server logs, including IP addresses: 30 days.
- Hosted backups: until the lock you chose for each one ends, then deleted within a day. A locked backup cannot be deleted sooner by anyone, including us, so closing your account does not remove it early; download what you want to keep before its lock ends.
- A snapshot restored for a drill run on SafeGrd: destroyed with the drill’s machine when the drill ends or reaches its time limit. The drill’s result is kept with your backup evidence.
- Google Analytics data: no longer than 14 months, the retention set in our Google Analytics account.
- Our own backups of our database: kept for 14 days, then overwritten, so deleted data leaves them within that time.
- Billing records held by Paddle are kept by it as the law requires of it.
Your rights
Depending on where you live, you can ask us to: give you a copy of your personal data; correct it; delete it; restrict or object to how we use it; and receive it in a portable form. Where we rely on your consent, you can withdraw it at any time. Write to support@safegrd.dev; we answer within one month (extendable where the law allows, and we will tell you if so). You can also complain to the data protection authority where you live — in the UK the Information Commissioner’s Office, in the EU your local supervisory authority, and in India the Data Protection Board.
Security, and if something goes wrong
We protect what we hold with encryption in transit (TLS) and at rest where supported, hashed passwords, access controls, rate limiting, and by keeping as little as we can. Your backups reach us readable only on the machine of a drill you chose to run on SafeGrd, and with a customer-managed key neither they nor their key reach us at all. If a breach affecting your personal data happens, we will tell you without undue delay, say what was affected and what we are doing, and notify the authorities where the law requires it.
If the business changes hands
If SafeGrd is sold, merged or transferred, the personal data we hold may pass to the new owner, who will be bound by this notice for it. We will tell you before that happens.
Other sites
Our site links to others (Paddle, GitHub, your storage provider’s documentation). Their own privacy notices apply there, not this one.
Cookies and local storage
We do not use cookies for advertising. What we set, and why:
- Strictly necessary, set without asking because the service cannot work without them: when you sign in, the console sets __Host-safegrd_session (your session, which scripts cannot read) and __Host-safegrd_csrf (protection against forged requests). Signing out removes both. If you tick “Remember this browser” when you enter a two-factor code, the console also sets safegrd_mfa_remember (scripts cannot read it), so this browser is not asked for the code again for 30 days. It stays when you sign out, and stops working when you reset your password, sign out everywhere or turn two-factor off. The console also keeps your name and email in your browser’s local storage, to show them, and signing out removes that too. Your answer to the analytics question below is kept in local storage as safegrd_analytics, so we do not ask again.
- Analytics, only with your consent. On our public pages — the home page, the documentation and these legal pages — we ask whether we may use Google Analytics. Until you say yes, nothing is loaded from Google and no analytics cookie is set. If you agree, Google Analytics sets first-party cookies (_ga and _ga_…) to tell visits apart, and sends Google the page address, your browser and device type, an approximate location derived from your IP address, and how you arrived. Why: to learn which pages people read. Legal basis: your consent. If your browser sends a Global Privacy Control signal, we treat it as a no and do not ask. The console, and the pages where you sign in, sign up, reset a password or verify your email, never load analytics.
You can change your answer at any time with the “Cookie settings” link at the foot of our public pages, or here: . Withdrawing removes the analytics cookies. When you pay through Paddle, Paddle’s checkout runs on our payment page and may set cookies of its own, which Paddle’s privacy notice describes.
Changes
If we change this notice we will post the new version here with its date, and tell you by email or in the console before a material change takes effect.