1. Scope and operator
This Privacy Policy explains how the independent developer of OpenWithGuard (“we,” “us,” or “our”) handles information when you use the OpenWithGuard Windows application, visit https://www.openwithguard.com, sign in, check for updates, or contact support.
2. Information we handle
Data kept on your device
OpenWithGuard stores protection rules, selected applications, browser choices, preferences, a bounded local activity history, update state, an anonymous installation identifier, and—if you sign in—a local account session. File contents are not uploaded to provide file-association protection.
Account and support data
Your account may contain an account ID, email address, display name, profile image, sign-in method, verification status, session token, and account timestamps. PocketBase stores the server-side account record. If you contact support, we also handle the information you choose to include in your message.
Website and update requests
Our website, account service, update service, hosting provider, and security proxy may process standard request data such as IP address, date and time, requested URL, response status, and user agent. We use it to deliver and secure these services and diagnose failures.
3. Google Sign-In
OpenWithGuard uses Google Sign-In only to authenticate you and create or display your OpenWithGuard account. Through Google Sign-In and PocketBase, we receive:
- a stable Google-linked account identifier;
- your email address;
- your display name; and
- your profile image, when available.
We use this data to sign you in, show your profile, maintain your account, provide support, and protect account security. OpenWithGuard does not request access to Google Drive, Gmail, contacts, calendars, or other Google product content.
We do not use Google user data for advertising, analytics, credit decisions, or AI training. We do not sell it or disclose it to data brokers. It is shared only with Google, PocketBase and the infrastructure needed to provide sign-in and account features, when you direct us to share it, or when legally required.
4. Product analytics
Configured release builds use PostHog with a random installation ID that is not derived from your Google account, Windows account, hardware serial number, email address, or protected files. Debug builds and release builds without an analytics token do not send these events.
OpenWithGuard currently sends:
app_installed, when the anonymous installation identity is first created after a successful start; andapp_shown, when the main window is shown.
Properties may include the random installation ID, app version, distribution language, operating system, processor architecture, how the window was shown, and whether a local account session exists. PostHog person profiles and geolocation are disabled. We do not send file contents, file names, protected extensions, executable paths, rules, activity entries, Google profile data, PocketBase tokens, or support messages to PostHog.
5. How we use and share information
We use information only to operate file-association protection, sign-in, updates, support and security; measure limited product usage; comply with law; and enforce our Terms of Service. We do not sell or rent personal information or use it for behavioral advertising.
Information may be handled by:
- Google for the Google Sign-In flow;
- PocketBase and our hosting infrastructure for accounts, updates and service delivery;
- PostHog for the limited product analytics described above; and
- authorities or advisers when reasonably necessary to comply with law or protect users, the service, or legal rights.
6. Retention and security
Local information remains until you remove it, the application removes it, or you remove the application data. Account records are kept while your account is active and as long as reasonably necessary to provide the service, resolve support or security issues, and meet legal obligations. Other records are deleted or anonymized when they are no longer reasonably needed.
We use reasonable safeguards, including HTTPS for data in transit and restricted administrative access. No system is completely secure, so protect your Windows account and do not share session files or authentication tokens.
7. Your choices
You may:
- sign out, change or remove local rules, clear local activity, or uninstall OpenWithGuard;
- revoke OpenWithGuard from your Google Account’s third-party connections; and
- request account deletion, correction, or a copy of your account data by emailing [email protected].
Revoking Google access does not by itself delete the OpenWithGuard account already created. Depending on where you live, additional privacy rights may apply.
8. Changes
We may update this policy as the product, providers, or legal requirements change. We will post the revised policy at this URL and update its effective date. If a change materially affects how we use Google user data, we will provide additional notice where required.
9. Contact
For privacy questions or requests, contact the OpenWithGuard independent developer at [email protected].