Privacy policy

How SpamGuard handles personal data. Last updated 2026-08-11. If anything here is unclear, write to {{PRIVACY_CONTACT_EMAIL}} and we will answer plainly.

Who is responsible

{{LEGAL_ENTITY_NAME}}, {{REGISTERED_ADDRESS}}, tax identifier {{VAT_OR_TAX_ID}}.

For anything concerning personal data: {{PRIVACY_CONTACT_EMAIL}}.

Two different relationships

If you run a website using SpamGuard, we are a processor acting on your instructions for the submissions your visitors make. You are the controller of that data, and the Data Processing Agreement governs it.

If you visit this website, or write to us, we are the controller of that small amount of data.

What we receive from a protected site

When a visitor submits a comment, registration or contact form on a site running SpamGuard, that site sends us: the submission text, the name and email address entered, the visitor’s IP address, the browser identification string, and the referring page.

If the visitor has JavaScript enabled, a small set of measurements about how the form was filled in is sent too: elapsed time, keystroke count, correction count, paste count, a sample count of pointer movement, and two statistics describing typing rhythm. This set contains no text, no key identities and no pointer coordinates. It cannot be used to reconstruct anything that was typed.

What we keep, and for how long

We store a one-way cryptographic fingerprint of the submission and a set of derived numbers — link counts, character ratios, language-independent structural measurements. We do not store the submission text.

The one exception is when the site owner has explicitly switched on “help improve detection”, which is off by default. In that case, submissions the owner personally corrects are stored in full so the model can learn from them.

Records are deleted automatically: 30 days on the free plan, one year on Pro, two years on Business. Corrections used for training are kept longer, because deleting them would degrade detection for everyone.

Where it is processed

On servers in the European Union. Our database is hosted in Frankfurt and our application in the EU.

No submission content is sent to any third-party artificial intelligence provider. Detection runs on models we operate ourselves. This is an architectural fact, not a policy commitment we could quietly change: sending content elsewhere would require rebuilding how the service works.

Legal basis

For the site owner: performance of the contract between us.

For a visitor to a protected site: the legitimate interest of the site owner in keeping their forms usable, balanced against the visitor’s interests. We designed the data minimisation described above specifically so that balance comes out favourably — we take what is needed to judge a submission and no more.

Who else sees it

Our infrastructure providers, acting as sub-processors under contract: Railway (application hosting, EU) and Supabase (database, Frankfurt).

Nobody else. We do not sell data, we do not share it for advertising, and there is no analytics or tracking on this website.

Your rights

Access, rectification, erasure, restriction, portability and objection, under the GDPR.

If you commented on a site using SpamGuard, address your request to that site first — they are the controller and their WordPress installation can export and erase what we recorded, using the plugin’s built-in integration with WordPress privacy tools.

You can also write to {{PRIVACY_CONTACT_EMAIL}} directly. You have the right to complain to your national supervisory authority.

Cookies

This website sets no cookies and runs no analytics.

The plugin sets no cookies on the sites that use it.

← SpamGuard