1. Who we are and what this policy covers
This Privacy Policy explains how the independent developer of OpenWithGuard (“OpenWithGuard,” “we,” “us,” or “our”) processes information when you use the OpenWithGuard Windows application, visit https://www.openwithguard.com, sign in with Google, contact support, or use related update and account services.
For privacy questions or requests, contact [email protected].
2. Information we process
Information stored on your device
The application stores settings needed to operate locally, including protected file extensions, chosen executable paths and application metadata, browser-protection choices, general preferences, a bounded activity history, update state, an anonymous analytics installation identifier, and—if you sign in—a PocketBase authentication session plus the account profile described below.
Protection rules and activity history may reveal which applications you use and the names or extensions of files opened through protected rules. These records are used by the product on your device and are not included in PostHog product analytics.
Account information
When you create or use an account, we process a stable account identifier, email address, display name, profile image, authentication provider, session token, and account timestamps. PocketBase stores the server-side account record. The application stores a local session so it can restore your signed-in state.
Support communications
If you contact us, we process the information you choose to provide, such as your email address, account identifier, purchase receipt, diagnostic details, and the content of your request. Please do not send passwords, Google access tokens, or unrelated sensitive files.
Website and service logs
Our website host, reverse proxy, account service, and update service may process standard network information such as IP address, request time, requested URL, response status, user agent, and security logs. This information is used to deliver the service, investigate failures, prevent abuse, and maintain security.
3. Google Sign-In and Google user data
OpenWithGuard uses Google Sign-In only to authenticate you and create or display your OpenWithGuard account. Through the Google authentication flow and PocketBase, we receive and use:
- a stable Google-linked account identifier;
- your email address;
- your display name; and
- your profile image, when available.
We use this data to sign you in, display your account profile, associate future license or subscription records with your account, prevent duplicate accounts, provide support, and protect account security. OpenWithGuard does not request access to Google Drive, Gmail, contacts, calendars, or other Google product content.
We do not use Google user data for advertising, sell it, or transfer it to data brokers. We share it only with service providers acting on our behalf, when necessary to provide a user-requested feature, when you direct us to do so, or when required by law.
4. Product analytics
Analytics are disabled in debug builds. Configured release builds use PostHog to understand basic installation and daily activity. The application creates a random installation UUID that is not derived from your Google account, Windows account, hardware serial number, email address, or protected files.
The application currently sends only these product events:
app_installed— emitted when the local anonymous installation identity is first created after a successful application start.app_shown— emitted when the main window is successfully shown.
Event properties may include the random installation ID, application version, distribution language, operating system, processor architecture, the way the window was shown (initial, tray, or second_instance), and a Boolean value indicating whether a local account session exists. The Boolean does not include your account identifier or email address.
PostHog person profiles and analytics geolocation are disabled by the application. However, network providers may temporarily process your IP address to receive and route the request. We do not send file contents, file names, protected extensions, executable paths, rule choices, activity entries, Google profile data, PocketBase tokens, or support messages to PostHog.
5. Why we process information
Depending on where you live, our legal bases may include performing our contract with you, our legitimate interests in operating and securing the service, your consent where required, and compliance with legal obligations. We use information to:
- provide file-association, browser-protection, account, update, and support features;
- authenticate users and maintain sessions;
- measure anonymous installs and active installations;
- diagnose failures, prevent abuse, and secure our infrastructure;
- communicate about support, material service changes, and legal notices; and
- comply with applicable law and enforce our Terms of Service.
6. Service providers and disclosures
We may disclose information to the following categories of recipients, only as needed for the purposes described above:
- Google, which operates the Google Sign-In flow under Google’s own privacy terms;
- PocketBase and our infrastructure host, which provide account, update, database, and network services under our control;
- PostHog, which processes the limited product analytics described above;
- support and security providers, if we engage them to help answer requests or protect the service;
- professional advisers and authorities, where reasonably necessary to comply with law or protect rights and safety; and
- a successor organization, if the product or business is involved in a merger, acquisition, financing, or asset transfer, subject to appropriate safeguards.
We do not sell or rent personal information. We do not share personal information for cross-context behavioral advertising.
7. Data retention
Local rules, preferences, activity, analytics identity, and account sessions remain on your device until removed by the product, deleted by you, or removed during applicable application-data cleanup. Bounded activity history automatically discards older entries as new entries are recorded.
Server account records, operational logs, analytics events, and support communications are retained for [RETENTION PERIOD], unless a longer period is needed for security, dispute resolution, legal compliance, or an active account relationship. We delete or anonymize information when it is no longer reasonably needed.
8. International data transfers
Our service providers may process information outside your country. Where required, we use recognized safeguards for international transfers, such as contractual protections, adequacy decisions, or another lawful transfer mechanism.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of personal information, receive a portable copy, or withdraw consent. You may also:
- sign out to remove the active account session from the application;
- delete or pause local protection rules;
- clear local activity through the product when that control is available;
- uninstall the application and remove its application-data directory; and
- request account deletion or a privacy export by contacting [email protected].
You can revoke OpenWithGuard’s Google access from your Google Account’s third-party connections page. Revoking Google access does not automatically delete an OpenWithGuard account already created; contact us if you also want the OpenWithGuard account deleted.
10. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. No storage or transmission method is completely secure, and we cannot guarantee absolute security. Keep your Windows account protected and do not share application session files or authentication tokens.
11. Children
OpenWithGuard is not directed to children under 13, or the minimum age required by local law. We do not knowingly collect personal information from children in violation of applicable law. Contact us if you believe a child has provided personal information.
12. Changes to this policy
We may update this policy as the product, providers, or legal requirements change. We will post the revised policy at this URL and update its effective date. If a change materially affects how we use Google user data, we will provide additional notice where required.
13. Contact us
Privacy questions and requests may be sent to [email protected].
OpenWithGuard
Independent developer
[email protected]