Legal / Privacy Notice

Privacy Notice

Last updated 3 October 2026.

Who we are

SafeGrd is provided by Kush Kumar Sharma, a sole proprietor trading as SafeGrd, of Bengaluru, India - 560048. We are the controller of the personal data we collect about users of our website and service. For personal data inside what you back up, you are the controller and we act as your processor under our Data Processing Agreement. For anything about your data, write to support@safegrd.dev.

Your backups and your key

Your database, file and mailbox backups are compressed and encrypted on your own machine before they leave it. They are written either to storage in your own cloud account or to compliance-locked object storage provided by SafeGrd, and kept there only as encrypted bytes. By default we never receive your database passwords, mailbox credentials or storage keys. With a customer-managed key, we never receive your private encryption key, so we cannot read your backups.

You can choose to have SafeGrd hold some of these instead: a database or mailbox credential for a surface, your storage bucket's secret key, or (with SafeGrd-managed key custody) your private encryption key. Each is a separate choice, and the console shows which ones you made. Whatever we hold is stored encrypted under per-organization envelope protection, released only to your enrolled machines when they run a backup or restore drill, and recorded on every release. It is never displayed in the console or readable through the API.

With SafeGrd-managed key custody you can also choose to run a surface’s restore drills on SafeGrd instead of on your own machines. This is the only case in which we decrypt a backup. Each drill runs on a virtual machine of its own, which downloads one snapshot from SafeGrd-hosted storage, decrypts it with your key, restores it into a temporary database or reads it in memory, checks it, and reports the result. The machine runs nothing for anyone else, and it is destroyed with everything restored on it when the drill ends or reaches its time limit. Your key access record shows each release to a drill. The restored data never reaches our control plane, which keeps only the drill’s result.

With SafeGrd-managed key custody you can also have SafeGrd take a database’s backups from a connection string you give us to hold. Each backup runs on a virtual machine of its own, which is given that connection string for that backup alone, connects to your database, dumps it, encrypts it to your key and writes it to SafeGrd-hosted storage. That machine is never given your key, and it is destroyed when the backup ends. Your key access record shows each release of the connection string. The dump never reaches our control plane, which keeps only the backup’s record.

What we collect, and why

We do not sell personal data, and we do not use it for advertising.

Who we share it with

A complete, up-to-date register of our third-party processors is published on our Sub-processors page.

International transfers

Our servers are in the United States. If you use SafeGrd from elsewhere, your account data is transferred there. Where the law you are under requires it, we rely on appropriate safeguards for those transfers, such as the standard contractual clauses approved for this purpose.

How long we keep it

Your rights

Depending on where you live, you can ask us to: give you a copy of your personal data; correct it; delete it; restrict or object to how we use it; and receive it in a portable form. Where we rely on your consent, you can withdraw it at any time. Write to support@safegrd.dev; we answer within one month (extendable where the law allows, and we will tell you if so). You can also complain to the data protection authority where you live — in the UK the Information Commissioner’s Office, in the EU your local supervisory authority, and in India the Data Protection Board.

Security, and if something goes wrong

We protect what we hold with encryption in transit (TLS) and at rest where supported, hashed passwords, access controls, rate limiting, and by keeping as little as we can. Your backups reach us readable only on the machine of a drill you chose to run on SafeGrd, and with a customer-managed key neither they nor their key reach us at all. If a breach affecting your personal data happens, we will tell you without undue delay, say what was affected and what we are doing, and notify the authorities where the law requires it.

If the business changes hands

If SafeGrd is sold, merged or transferred, the personal data we hold may pass to the new owner, who will be bound by this notice for it. We will tell you before that happens.

Other sites

Our site links to others (Paddle, GitHub, your storage provider’s documentation). Their own privacy notices apply there, not this one.

Cookies and local storage

We do not use cookies for advertising. What we set, and why:

You can change your answer at any time with the “Cookie settings” link at the foot of our public pages, or here: . Withdrawing removes the analytics cookies. When you pay through Paddle, Paddle’s checkout runs on our payment page and may set cookies of its own, which Paddle’s privacy notice describes.

Changes

If we change this notice we will post the new version here with its date, and tell you by email or in the console before a material change takes effect.