Skip to content

Privacy Policy

Effective Date: 2026-09-15

Last updated: 2026-09-15

This Privacy Policy explains how Sminter & Sminter, LLC, a Delaware limited liability company, doing business as Appwarden (“Appwarden,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal data in connection with our websites, dashboard, APIs, documentation, edge middleware, monitoring, quarantine, and incident response services (collectively, the “Service”).

By using the Service, you acknowledge the practices described in this Policy. Our Terms of Service govern your use of the Service, and capitalized terms not defined here have the meanings given there.

  • Account and business data. For data about our own customers and users (account registration, billing status, support communications), Appwarden is the controller (a “business” under California law).
  • Customer site and visitor data. For data our customers instruct us to process about visitors to websites and applications they protect with the Service (“Visitor Data”), the customer is the controller and Appwarden acts as a processor (or “service provider”/“contractor” under U.S. state law) under Section 8 of the Terms of Service. If you are a visitor of a website protected by Appwarden, the site operator’s privacy policy governs that data, and you should contact the operator to exercise your rights.
  • Account data. When you sign in with a third-party identity provider (such as Discord or Slack), we receive the profile information that provider shares with us, such as your username, display name, email address, avatar, and provider account IDs.
  • Organization data. Organization name and profile, membership and roles, invitations (invitee email addresses), and your Service configuration, including domains, monitoring targets, quarantine settings, and connected integrations.
  • Support and communications. Messages you send us (for example to support@appwarden.io) and your contact preferences.

Purchases are processed by our merchant of record (Paddle). We receive and store subscription status, plan, billing interval, currency, pre-tax amounts, and transaction identifiers. We do not receive or store your full payment card number; payment details are collected directly by Paddle under its own privacy policy.

When you or your systems interact with the Service, we automatically collect log and diagnostic data such as IP addresses, user agents, request paths and timestamps, API token identifiers, error reports, and feature-usage metadata.

When providing monitoring and quarantine features for a customer’s website, we process data on that customer’s instructions, which may include: visitor IP addresses (for example, for rate limiting), request headers and metadata, page content and content diffs used for change detection, incident records, and notification content routed to collaboration platforms the customer connects (such as Discord, Slack, or PagerDuty). Our monitoring systems fetch and analyze customer-configured pages to detect changes and serve lock pages when a quarantine is active.

We receive data from the third-party services you connect, limited to what is needed to operate the integration (for example, workspace or server identifiers, channel identifiers, and bot installation metadata).

The Service uses only strictly necessary cookies, such as authentication and session cookies that keep you signed in and security cookies that protect requests. We do not use analytics, advertising, or cross-site tracking cookies, and we do not use third-party advertising trackers on our marketing site or dashboard. Because there is no tracking to opt out of, the Service does not respond to “Do Not Track” signals; where required, we treat Global Privacy Control signals as an opt-out of any sale or sharing of personal data (which we do not conduct in any case).

We use personal data to:

  1. Provide and operate the Service — authenticate you, run monitoring and quarantine features, deliver incident notifications, and operate the dashboard and APIs.
  2. Process transactions — manage trials, subscriptions, billing status, and account access through our merchant of record.
  3. Communicate with you — respond to support requests, send service and security notices, and notify you of material changes to our terms or this Policy.
  4. Secure and improve the Service — prevent abuse, enforce rate limits, debug errors, monitor performance, and maintain the integrity of the Service.
  5. Comply with law — satisfy legal, tax, accounting, and regulatory obligations, and establish or defend legal claims.

Legal bases (EEA/UK/Swiss users). We process personal data as necessary: to perform our contract with you (providing the Service); for our legitimate interests (securing, maintaining, and improving the Service, and communicating with customers), balanced against your rights; to comply with legal obligations; and, where required, based on your consent (which you may withdraw at any time).

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.

We disclose personal data only to:

  • Service providers (subprocessors) acting on our behalf under contractual confidentiality and data-protection obligations, in the following categories: cloud hosting and content delivery; database and authentication; payment processing and merchant-of-record services; transactional email delivery; error and performance monitoring; collaboration and incident-management platforms; and code hosting. A current list of named subprocessors is available at Subprocessors. We will notify customers of material changes to these categories by email or in-product notice, and you may object via support@appwarden.io.
  • Third-Party Services you connect — for example, when incident content is posted to the chat or paging platforms you configure. Data sent to these platforms is governed by their own privacy policies.
  • Legal, safety, and compliance recipients — where required by law, legal process, or to protect the rights, property, or safety of Appwarden, our customers, or others.
  • Business transferees — in connection with a merger, acquisition, reorganization, or sale of assets, subject to this Policy.
  • Operational logs and diagnostics: retained for approximately 90 days, then deleted or de-identified.
  • Account and organization data: retained while your account is active; after a verified deletion request, deleted or de-identified within 30 days, subject to the exceptions below.
  • Monitoring content and content diffs: retained while the related monitoring configuration is active; deleted or de-identified within 90 days after the configuration is removed.
  • Incident records: retained while the incident is open and for 12 months after closure, then deleted or de-identified.
  • Billing and transaction records: retained as required by tax, accounting, and other legal obligations.
  • Backups: residual copies in encrypted backups are deleted on the backup rotation schedule.

We may retain data longer where required by law, to resolve disputes, or to enforce our agreements.

We are based in the United States and process data there and in other countries where our service providers operate. When we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or another lawful transfer mechanism. For these transfers, the applicable Standard Contractual Clauses or UK Addendum are incorporated into and executed under Section 8.6 of our Terms of Service. You may request a copy of the applicable safeguards via support@appwarden.io.

We implement technical and organizational measures designed to protect personal data, including encryption in transit, access controls, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We will notify affected parties and regulators of personal data breaches where required by law.

9.1 EEA, UK, and Swiss users (GDPR/UK GDPR)

Section titled “9.1 EEA, UK, and Swiss users (GDPR/UK GDPR)”

Subject to legal conditions, you have the right to: access your personal data; rectify inaccurate data; erase your data; restrict or object to processing; data portability; withdraw consent at any time (without affecting prior processing); and lodge a complaint with your supervisory authority.

EU/UK representative (Article 27). We are evaluating the applicability of Article 27 of the GDPR and UK GDPR (local representative requirements) to our processing activities and will publish the contact details of any appointed EU/UK representative in this Policy when appointed.

9.2 U.S. state privacy rights (including California, CCPA/CPRA)

Section titled “9.2 U.S. state privacy rights (including California, CCPA/CPRA)”

Depending on your state of residence, you may have the right to: know/access the personal data we hold about you; correct inaccurate data; delete your data; opt out of the sale or sharing of personal data or targeted advertising (we do not sell or share personal data for those purposes); limit the use of sensitive personal data (we do not use or disclose sensitive personal data outside permitted purposes); and not be discriminated against for exercising your rights. California residents may also request information about our disclosure practices under California’s “Shine the Light” law. If we deny your request, you may appeal by replying to our decision email; if the appeal is denied, you may contact your state attorney general. Nevada residents: we do not sell covered information as defined by Nevada SB 220; you may register a request under that law by emailing support@appwarden.io.

Email support@appwarden.io with your request. We will verify your identity (for account holders, typically via the email on the account) before acting, and will respond within the timeframes required by applicable law. You may use an authorized agent where permitted; we may require proof of authorization. Visitors of customer websites: Appwarden processes Visitor Data on behalf of the site operator; please direct your request to the operator of the site in question. If you contact us about Visitor Data, we will refer your request to the relevant customer where feasible.

To delete your account and associated personal data, email support@appwarden.io. Deletion removes your profile and organization membership data subject to the retention rules in Section 6. Cancellation of billing alone does not delete account data.

The Service is not directed to children, and you must be at least 18 years old to use it. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact support@appwarden.io and we will delete it.

We may update this Policy from time to time. For material changes, we will provide at least 30 days’ advance notice by email or prominent dashboard notice and will update the Effective Date. Your continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.

Privacy questions, rights requests, and notices:

Sminter & Sminter, LLC, d/b/a Appwarden Email: support@appwarden.io Mail: Sminter & Sminter, LLC, c/o Harvard Business Services, Inc., 16192 Coastal Highway, Lewes, Delaware 19958, USA