Privacy at Ward
This notice explains what personal information Ward uses, why it is needed, how long it is kept and the choices available to you.
The data controller is Ward, operating Ward. Contact Ward at support@wardprotection.com. A public postal contact must be configured before Ward's public launch.
Ward uses your account name, email address, authentication identifier and essential session data to create and secure your account and deliver the service. It uses subscription and Stripe identifiers to provide paid access, manage renewal and prevent duplicate billing. Family membership, invitation addresses, safety-plan choices and deliberately general activity records are used only to provide the Family features. Security, rate-limit and token-count records help prevent abuse, control provider cost and keep Ward reliable; they do not contain the original message. These uses are necessary to perform Ward's contract with you or for Ward's legitimate interests in securing and operating the service. Payment records may also be processed where the law requires them.
Ward processes the text, image, recording, link, phone number or email address you deliberately submit to produce the result. Message text, uploaded images and recordings are not stored in Ward's ordinary history after processing, and voice transcripts are not kept. Your check history — the result and, for link, contact and breach checks, the address you chose to check — is saved to your account so the same list appears on all your devices; it is encrypted at rest, limited to your most recent checks, and a copy is cached in this browser for offline viewing. When you look up a phone number or email address, Ward also updates an anonymous search counter for that contact — a non-reversible fingerprint and a running total, with no record of who searched — so every member can see how often it has been looked up. If you choose to leave a review of a contact, the contact is stored encrypted and the review is linked privately to your account to prevent duplicate ratings; other members see the review without your identity. Ward does not sell submissions or put originals in the public Radar database. Never submit information you are not permitted to use.
A one-off breach check keeps nothing: the address is sent to the breach-data provider for that lookup only. If you separately turn on weekly monitoring, Ward must keep something in order to notice a change, so it stores the email address on your own Ward account together with the names of the breaches it has already seen, held as a single encrypted record and readable only while a check is running. Monitoring covers your own account address only, not an address belonging to someone else. Ward re-checks it about once a week and emails you only when a breach appears that it has not seen before; that email never contains a link to click and never asks for a password, payment or verification code. Turning monitoring off deletes the stored record, as does deleting your account.
Vercel hosts the website and API; Neon provides the database and sign-in service; Anthropic provides language and image analysis; Stripe processes subscriptions; and Vercel Web Analytics provides aggregate site-usage information. Depending on the feature and configuration, a check can also use Modulate or Hugging Face for audio, Google Web Risk and other reputation or domain-information services for links, contact or breach-data providers, and Cloudflare plus Resend for forwarded email. A link probe sends the submitted public web address to its destination using a non-body HEAD request. These organisations process information under their own service terms and may retain limited operational or security records.
Some providers operate in the United Kingdom, European Economic Area, United States or other countries. Where UK personal data is transferred internationally, Ward relies on the provider's applicable contractual safeguards, adequacy arrangements or another lawful transfer mechanism. Contact Ward for the current provider and safeguard details relevant to a particular feature.
Your check history is saved to your account and encrypted at rest, keeping only your most recent checks; it stays until you clear it or delete the account, and a copy is cached in your browser for offline viewing. Forwarded-email results — the subject line and what the analysis found, including any suspicious links or contact details from the email, but never the email's full text and always with your own email address removed — are kept on Ward's server for up to 30 days; replay-protection records are kept for 7 days. Finished email-delivery records and Family invitations are removed after 30 days, and Family alerts after 365 days. Optional redacted Ward Network observations are removed when you withdraw consent or delete the account. Account, Family and subscription records remain while the account is active and are erased or anonymised when you delete it, subject to records that Stripe or another provider must retain by law. Ward keeps a one-way deletion-suppression key, without your email or content, only to stop a deleted identity silently creating a fresh account; it is reviewed as that need changes.
Ward Network contributions happen only after you opt in. Ward contributes a pseudonymous keyed pattern, controlled tactic categories, and structured scam indicators — the destination website’s domain (never the full, personalised link), the scam’s own phone numbers and email addresses, and a fixed impersonation category — rather than your original submission. Your own email address is removed, and Ward never contributes or publishes the message text, an AI-written summary, or anyone’s name. So that no detail unique to you is ever shown, Ward publishes a scam indicator only once two or more members have independently reported the same one; anything a single person reported stays hidden. To recognise repeat scam operations over time, Ward also keeps an anonymous running total for each reported scam domain, phone number and email address — the value, a count and first/last seen dates, with no record of who reported it. Consent can be withdrawn in Settings without losing access to the checker; withdrawal removes observations linked to your contributor key (the anonymous totals contain nothing linked to you).
Family accounts remain independent. Another family member sees only the general warning category or review request that the feature deliberately shares, not the original message, screenshot or recording. An invitation email address is used to deliver and match the invitation and is removed under the retention rules above.
Ward uses rules and AI to produce a safety assessment, but it can be wrong and does not make a legal or similarly significant decision about you. You decide what action to take. For important financial or safety decisions, contact the organisation through independently verified details.
In Settings you can download server-held account data, clear your history, turn optional Ward Network sharing off, or permanently delete the account. Depending on UK data-protection law, you may also ask for access, correction, deletion, restriction, portability or object to a use based on legitimate interests. Email support@wardprotection.com. Ward may need to verify your identity. You can complain to the UK Information Commissioner at ico.org.uk.
Last updated 18 July 2026.