SwearGuard

SwearGuard privacy policy

Last updated: 1 October 2026

SwearGuard is a parental-control app for Windows, with an optional phone app for parents, SwearGuard Parent. A parent installs it on a PC their child uses. This policy explains what it does with information.

In short:

What SwearGuard looks at, and where it goes

WhatWhyStored?Leaves the PC?
Microphone soundTo notice swear words and shoutingNo. Sound is analysed as it comes in and discarded.No
The words spoken in a sentence that contained a swear wordSo the parent can see what was said in the activity logYes, in the activity log on the PCNo
Webcam picture (only if the parent turns on a camera feature)To notice wild movement, a phone held up, a covered camera, or nobody at the PCNo. Pictures are analysed as they come in and discarded.No
The address of the browser tab in frontTo apply the parent's YouTube and Shorts rulesNo. Only minutes of YouTube and Shorts used today are kept.No
The name of each new website in the browser (for example example.com, never the full address)To close adult websites (on by default, can be switched off)Answers are remembered in memory for an hourYes: the name is looked up with Cloudflare's family DNS (family.cloudflare-dns.com), like any DNS lookup
Adult websites the child triedSo the parent knowsYes, in the activity logOnly end-to-end encrypted to the parent's phone, if one is connected
Settings, parent PIN (as a salted hash), strikes and activity logSo SwearGuard works and the parent can review what happenedYes. Protected settings, PIN and counters are in %ProgramData%\SwearGuardPrivate on an installed PC; the ordinary activity log is in %ProgramData%\SwearGuardThe PIN never. Status, activity (swear words masked) and some settings are sent end-to-end encrypted to paired phones
Screen-time and app-use totals (including app names), YouTube and Shorts minutesTo enforce the parent's time limits and show useYes, in usage files on the PCTotals and app names are included in the encrypted status sent to paired phones
Phone-pairing key and access tokenTo connect the PC to the parent's phonesYes, in protected state on an installed PCThe key is shared with a phone in the pairing QR code, not sent to the relay; the relay receives the PC's access token and stores its hash
License key, purchased device count, random installation ID and verification dates, when licensing is enabledTo activate and recheck a monthly membership and enforce its PC allowanceYes, in protected state on an installed PCThe key, product ID and random installation ID are sent to the SwearGuard licensing relay on activation and normally once a day. The relay forwards the key and product ID to Gumroad (api.gumroad.com) and stores hashes of the key and installation ID for the device allowance; it does not store the raw key. The PC stops guarding after three days without successful verification

SwearGuard has no user accounts, app analytics, advertising or tracking. It never uploads audio, pictures or browsing history. Its local activity log can include a swear-word sentence and the name of an adult site the child tried to open.

The SwearGuard Parent phone app (optional)

When a parent connects a phone, the PC sends it:

The swear word is masked and the sentence around it is not sent.

All of this is encrypted on the PC with a key shared only by that PC and the paired phones. The key is inside the QR code the parent scans, and it is not sent to our server. Our server (a Cloudflare Worker) cannot read message content. It can see connection and event times, whether the PC is online, and which events request a push notification. It keeps:

WhatWhyHow long
Encrypted latest status, the last 200 encrypted events, and up to 20 waiting commandsSo the phone can catch up when it opensStatus remains until replaced or successfully deleted. Older events are replaced by newer ones. Waiting commands are cleared when the PC reconnects or newer commands replace them
Encrypted names of the PC and phones; hashes of their access tokensTo show paired devices and check accessUntil the phone is successfully removed or all phones are successfully disconnected
A phone's push-service addressTo make the phone buzzUntil that phone is successfully removed, all phones are successfully disconnected, or the push service reports the address invalid
Event and pairing times, push flags, and whether and when the PC went offlineTo show activity and connection state and send alertsEvent times roll off with the oldest of the last 200 events. Pairing and offline times remain until the relevant entry is removed or the family data is successfully deleted

Push notifications carry no content. They only wake the app, which then fetches and decrypts the news itself. Standard web requests to the parent app also pass through Cloudflare, which receives connection details such as IP addresses and request times.

The parent app keeps each pairing's encryption key and access token in the phone's IndexedDB storage. It also caches the latest decrypted status and up to 60 activity events in the phone's local storage, so they remain visible when it is offline. Removing a PC from the phone removes that local pairing and cache and tries to delete the phone's entry on the relay.

When the relay confirms a Disconnect all phones request from the PC, it deletes the family's data on the relay. If that request fails, if a phone is removed while offline, or if SwearGuard is uninstalled without a successful disconnect, server data can remain. There is currently no automatic expiry for an inactive family's stored data. Disconnect all phones while the PC is online before uninstalling.

Safe internet (optional)

When a parent turns on safe internet, SwearGuard changes Windows' own settings on the PC:

From then on, the PC's web addresses are looked up with Cloudflare's family DNS instead of the internet provider's. Cloudflare's privacy policy for its public DNS applies.

Turning safe internet off, or uninstalling SwearGuard, puts the previous settings back.

SwearGuard DNS (separate, optional service)

Families may choose a separate DNS service hosted on our own servers in the United States and South Africa, including devices without the SwearGuard Windows app. Setup suggests the server that answers the family's network fastest. Accounts and query history are stored on the main server in the United States; each server keeps a copy of the profile rules, linked IP addresses and device address hashes so it can filter. Query history recorded by the South African server is sent to the main server over an encrypted connection, then deleted from the South African server. Invite-only signup stores the parent's email address, a salted password hash, a login session, profile rules, and any linked public IP address or DDNS hostname. The DDNS hostname is rechecked periodically so a changing home IP can stay linked. DNS questions sent to our servers are checked against public blocklists and the profile's custom allow/block rules. Allowed questions are resolved by our local recursive resolver. Query history is off by default. If a customer turns it on, the main server stores each queried domain, time, DNS type, result and public network IP for up to seven days or 100,000 total records, whichever limit comes first. Customers can clear their own history or turn it off, which deletes their records. The DNS portal also displays this notice at dns.swearguard.com/privacy. Ordinary DNS between the device and our servers is unencrypted. The hosting providers can process connection information. The public blocklists are downloaded from StevenBlack/hosts; the DNS service does not send queries to Cloudflare. Email support@swearguard.com to request removal of a DNS account and its linked information.

Children

SwearGuard is used by parents to supervise their own children. Nothing about the child leaves the PC except:

We can't read those encrypted updates. When paid licensing is enabled, the parent's license key goes through our licensing relay to Gumroad, which issued it with the purchase.

Your control

Purchases

When paid licensing is enabled, monthly memberships are handled by Gumroad and Gumroad's privacy policy applies to them. Builds without a Gumroad product ID do not contact the licensing relay or Gumroad to activate or recheck keys.

Contact

Questions or privacy requests: email support@swearguard.com.