Privacy Policy

Effective May 9, 2026

This Privacy Policy explains how Weard (“Weard”, “we”, “us”, “our”) collects, uses, shares, and retains personal data when you use our brand-protection platform (the “Service”). It is part of our Terms of Service. We comply with the EU General Data Protection Regulation (Regulation 2016/679, “GDPR”) and equivalent national laws.

1. Who we are

Weard is the controller of the personal data we process about you when you use the Service. You can contact us at:

2. What data we collect

We collect only what we need to operate the Service:

  • Account data — email address, full name, organization name, hashed password (bcrypt), Google OAuth identifier (only if you sign in with Google), and the timestamp at which you accepted these Terms.
  • Configuration data — keywords / brand names you ask us to monitor, whitelist entries, notification settings (email addresses, Slack/webhook URLs, Telegram bot tokens), and your billing tier.
  • Operational data — alerts produced for your account, audit logs of mutations against your account (who changed what, when, from which IP), and metadata about your dashboard usage.
  • Public domain data — domains and TLS certificates we ingest from public Certificate Transparency logs and similar public sources. This is not personal data about you; it is the corpus we monitor.
  • Payment data — handled directly by Stripe (our payment processor). We receive a billing identifier and subscription status; we do not store card numbers or full payment-instrument data.
  • Communications — emails or messages you send to support, abuse, or sales addresses.

3. Why we process your data and on what legal basis

Under the GDPR, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — to provide the Service you have signed up for: detect lookalike domains, send alerts, render the dashboard, manage your subscription.
  • Legitimate interests (Art. 6(1)(f)) — to keep the Service secure (rate limiting, fraud prevention, abuse detection), to maintain audit logs, and to improve the Service through aggregated and de-identified usage statistics. We only rely on this basis where our interests are not overridden by your fundamental rights.
  • Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, and legal-request obligations.
  • Consent (Art. 6(1)(a)) — for any optional processing where we ask for it explicitly. You can withdraw consent at any time without affecting prior processing.

We do not sell your personal data. We do not use your data to train third-party AI models. We do not engage in profiling or automated decision-making with legal or similarly significant effects on you.

4. Sub-processors

We use a small number of vetted vendors to operate the Service. Each is bound by a data-processing agreement and processes data only on our instructions.

  • Stripe, Inc. — payment processing and subscription billing.
  • Resend, Inc. — transactional email delivery (verification, password reset, alert notifications).
  • Google LLC — Google OAuth, only if you choose to sign in with Google.
  • EU-based infrastructure providers — for hosting, database, and managed services. The current list is available on request at privacy@weard.io; we will give 30 days’ notice before adding a new sub-processor that materially changes the processing.

5. Data retention

We retain personal data only as long as we have a lawful reason to:

  • Account data — kept while your account is active. After deletion, retained for up to 30 days in operational backups, then purged.
  • Alerts and configuration — kept while your account is active; deleted with the account.
  • Audit logs — retained for 18 months for security, abuse-investigation, and compliance purposes.
  • Billing records — retained for up to 7 years to meet tax and accounting obligations under applicable law.
  • Email correspondence — retained for up to 24 months unless required for ongoing matters.
  • Public domain data — retained as part of the operational corpus and is not tied to your account after the alert lifecycle closes.

6. Your rights

Subject to applicable law, you have the right to:

  • Access a copy of your personal data — available self-service via Settings → Data & Privacy → Download my data.
  • Rectify inaccurate or incomplete data — directly editable in Settings or by emailing privacy@weard.io.
  • Erase (“right to be forgotten”) your account and associated personal data. Submit a request via support@weard.io; you must first cancel any active paid subscription.
  • Restrict or object to processing in the cases set out in Articles 18 and 21 GDPR.
  • Data portability — the data export endpoint provides your data in machine-readable JSON.
  • Withdraw consent at any time where processing is based on consent (without affecting the lawfulness of processing carried out before withdrawal).
  • Lodge a complaint with a data-protection supervisory authority — for users in Spain, the Agencia Española de Protección de Datos (AEPD, aepd.es); for users elsewhere in the EU, your local supervisory authority.

We will respond to verified rights requests within 30 days. We may extend that period by up to 60 days for complex requests, in which case we will inform you of the extension and the reason.

7. International transfers

We process and store personal data primarily within the European Economic Area. Some sub-processors (notably Stripe and Google) operate from the United States. Where personal data leaves the EEA, the transfer is governed by the European Commission’s Standard Contractual Clauses (Decision 2021/914) or, where available, an applicable adequacy decision. Copies of the relevant safeguards are available on request at privacy@weard.io.

8. Security

We apply technical and organizational measures appropriate to the risk, including: TLS encryption in transit; encryption at rest for backups and credentials; bcrypt for stored passwords; least-privilege access for engineers, with audit logging of administrative actions; per-organization isolation of customer data; rate limiting and abuse detection; and regular dependency and security review. No system is perfectly secure; if we discover a personal-data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and notify affected customers without undue delay, in line with Articles 33 and 34 GDPR.

9. Cookies and similar technologies

We use a small number of strictly necessary cookies for authentication, session management, and CSRF protection. We do not use third-party advertising, tracking, or analytics cookies. Because these cookies are strictly necessary for the Service to function, we do not require consent for them under Art. 5(3) of the ePrivacy Directive.

10. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact privacy@weard.io and we will delete it.

11. Data Processing Agreement

If you are a business customer subject to the GDPR, a Data Processing Agreement (DPA) implementing Article 28 GDPR is available. Email privacy@weard.io to request a copy.

12. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to your account address or by in-product notice at least 14 days before they take effect. The latest version is always available at weard.io/privacy.

13. Contact

For privacy questions, data subject rights requests, or any other matter under this Policy: privacy@weard.io.