Legal
Privacy Policy
Version 2026-08-22 · in effect from 22 August 2026
This policy explains what we collect, what we do not, and what you can ask us to do about it.
Ward is a local-first application. Most of what a tool like this would normally hold about you never leaves your computer, and the shortest honest summary of this document is: we hold your account, your plan, and — only if you use team sharing — a description of the profiles you chose to share. Nothing else.
Who we are
Ward is operated by Digital Heroes ("we", "us"). You can reach us at privacy@digitalheroes.co.in.
For data-protection purposes we are the controller of the account information described below. For anything Ward stores on your own computer, we are neither controller nor processor, because we have no access to it.
What stays on your computer, always
None of the following is transmitted to us, and we have no ability to read it:
- Your browser profiles: their cookies, local storage, saved sessions, browsing history, cache, and every file inside a profile directory.
- Proxy hostnames, usernames and passwords. Proxy passwords are encrypted on your disk with AES-256-GCM under a key held in your own user account.
- Generated device identities and the per-surface policy you set for them.
- Recorded scripts and their run history.
- Local team accounts, their password hashes, their TOTP secrets and their recovery codes.
- Your launch history and how long each profile was open.
These live in a SQLite database and a set of directories under your own user profile. You can copy them, back them up, or delete them, and we are not involved in any of that.
What we collect
Account information. Your email address and a password hash, held by our authentication provider. We use it to sign you in and to tell you about your account. We never see your password.
Plan and entitlement. Which plan you are on, when it renews, and counts of how many profiles, mobile profiles and seats your installation is using — as numbers, not as a list. We use this to apply the plan you are paying for.
Device registration. A random identifier for each installation, its operating system family, and the Ward version, so that a plan can be applied per installation and so you can see and remove installations you no longer use.
Team sharing, only if you use it. If you share a profile with a teammate we store a description of it: the name, the engine, the notes and tags you wrote, the generated device identity, and which proxy to point at. The proxy username and password are never uploaded. That is enforced by a constraint in the database, not by a promise in a document.
Support correspondence. If you write to us, we keep the message.
Payment information. Handled by our payment processor. We receive a confirmation that a subscription is active and the last four digits and brand of the card. We never receive or store your full card number.
What we do not collect
- We do not use analytics or telemetry in the desktop application.
- We do not track which sites you visit, in any profile.
- We do not sell personal data, and we do not share it for advertising.
- We do not read, index, or scan the contents of any browser profile.
Cookies on our website
Our website uses only what is necessary to keep you signed in and to remember your consent choices. We do not run advertising or third-party analytics cookies. There is no consent banner because there is nothing non-essential to consent to.
Who else sees it
We use a small number of processors, each for one job:
| Processor | What for | Where |
|---|---|---|
| Supabase | Account identity, plan records, team sharing metadata | European Union |
| Cloudflare | Website hosting and delivery | Global edge |
| Our payment processor | Subscription billing | As disclosed at checkout |
We do not transfer your information to anybody else except where we are legally required to, and we will tell you if that happens unless we are prohibited from doing so.
How long we keep it
- Account and plan records: while your account is open, and for up to 12 months after you close it, so that billing and tax records reconcile.
- Team sharing metadata: until you unshare the profile or leave the team.
- Support correspondence: 24 months.
- Payment records: as long as tax law requires, currently 7 years.
Your rights
Depending on where you live you may have the right to access, correct, delete, export, or restrict our use of your information, and to object to it. Write to privacy@digitalheroes.co.in and we will respond within 30 days.
Because most of your data is on your own computer, an access or deletion request to us covers only what is listed under "What we collect". You already have complete access to the rest, and you can delete it without asking us.
If you are in the EEA or the UK you may also complain to your supervisory authority. If you are in India, you may complain to the Data Protection Board.
Security
Proxy passwords are encrypted at rest on your machine with AES-256-GCM, with the key held in a file readable only by your user account and each record bound to the row it belongs to so that a ciphertext moved between rows fails to decrypt rather than decrypting into the wrong place.
Traffic between Ward and our systems uses TLS. Our database enforces row-level security so that one account cannot read another's rows, and the service key that would bypass those rules is not present in the desktop application.
No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal data we will notify you and the relevant authority within the periods the law requires.
Children
Ward is not for anybody under 18, and we do not knowingly collect information from children.
Changes
We will post any change here with a new version date, and where a change materially affects you we will tell you in the application and by email before it takes effect.