AgentWarden Antivirus for AI

Privacy Policy

Last updated 18 September 2026 · version 1.0

The short version. AgentWarden is built so that we learn as little about you as possible. Everything it watches (your code, prompts, agent transcripts, commands, file names and findings) is analysed on your own device and never sent to us. We receive only what we need to run licences and payments (your email, a one-way device fingerprint, payment records via Stripe), plus sealed alerts to your paired iPhone if you use that, which we cannot read and which expire after at most 7 days. Our website uses no cookies, analytics or trackers. We never sell or share your data for advertising.

1. Who is responsible

The controller of your personal data is PRAESI TECHNOLOGIES LTD, registered in Cyprus under number HE 483138, Aftokratora Ioustinianou 10, Block B, 1st floor, Office 101, Nicosia, Cyprus. For anything about privacy, write to operations@praesi.ai (or operations@praesi.ai). We are not required to appoint a Data Protection Officer; the person above answers privacy requests directly.

2. What stays on your device

To protect you, the Software reads, locally only, the session logs of AI agents on your device, the commands and processes they start, their network connections and startup items, installed skills, plugins and MCP server configurations, and your computer’s security settings. It keeps an event log of findings in your user folder. None of this is sent to us or to anyone else, except as you direct in sections 3.4 and 3.5. You can delete the log at any time from the app (or by deleting the AgentWarden folder in your user data).

Because this data never reaches us, we cannot see it, recover it, or produce it in response to a request.

3. What we receive, why, and on what legal basis

DataWhenWhyLegal basis (GDPR)Kept for
3.1 Email address, and a referral code derived from itYou start a trial or buy ProTo issue and email your licence key, send receipts and service messages, and credit referralsContract (Art. 6(1)(b))While your licence is active, then 24 months (to answer questions and prevent repeat trials), then deleted
3.2 Device fingerprint: a one-way hash of your computer’s hardware ID, never the ID itselfYou activate a licenceTo enforce the device limit of your plan without accounts or passwordsContract (Art. 6(1)(b))As 3.1
3.3 Payment records: name, billing country, VAT number (if a business), amount, date. Card details go to Stripe and never reach us.You buy ProTo take payment, issue invoices and meet tax lawContract; legal obligation (Art. 6(1)(c))Invoices: 7 years after the tax year, as Cypriot tax law requires
3.4 Sealed phone alertsOnly if you pair the iPhone appTo pass an alert summary from your computer to your phoneContract (Art. 6(1)(b))Deleted automatically after 7 days at most; only the most recent few are ever held
3.5 Alert emailsOnly if you turn on email escalationSent from your own email account on your computer to the address you choose. They do not pass through us.None neededNot held by us
3.6 Technical request data: IP address, time, user agentThe Software checks for updates and Rules, activates a licence, or you visit the websiteTo deliver updates and pages, and to keep the services secure and workingLegitimate interests (Art. 6(1)(f)): delivering a secure serviceHeld briefly in our providers’ logs (typically up to 30 days); we do not build profiles from it
3.7 Your messagesYou email usTo answer youLegitimate interests; contract where it concerns your licenceUp to 24 months after the conversation ends

Sealed phone alerts are encrypted on your computer with a key only your paired phone holds. We store and forward them but cannot read them. An alert contains a short summary of a finding (for example, the rule, the agent and the project name), never a transcript.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. AgentWarden’s findings are about agents’ actions on your device and stay on your device.

4. Website, cookies and tracking

Our website sets no cookies and uses no analytics, advertising pixels or third-party trackers. It does not store anything on your device, except what your browser caches to load the page. If this ever changes, we will update this policy and ask for consent where the law requires it before anything non-essential runs.

5. Who processes data for us

We use a small number of service providers, each under a data processing agreement that binds them to act only on our instructions:

ProviderWhat forWhere
Stripe Payments Europe Ltd (Ireland) and Stripe, Inc.Payments, invoices, tax calculationEU; USA
Cloudflare, Inc.Website hosting, licensing and phone-relay services and their storageGlobal network; USA
Supabase, Inc.Hosting of signed software updates and RulesEU/USA
Resend (Plus Five Five, Inc.)Sending licence and receipt emailsUSA
Microsoft Ireland Operations Ltd; Apple Distribution InternationalCode-signing and notarisation of the Software (no customer data)EU; USA

Stripe also acts as an independent controller for its own fraud-prevention and legal obligations; see Stripe’s privacy policy.

6. Transfers outside the EU

Some providers above process data in the United States. Where they do, the transfer is protected by the EU–US Data Privacy Framework (where the provider is certified) and/or the European Commission’s Standard Contractual Clauses, with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.

7. Your rights

Under the GDPR you have the right to access your personal data; to have it corrected; to have it deleted; to restrict or object to our processing (including processing based on legitimate interests); to data portability; and to withdraw any consent at any time. To use them, email operations@praesi.ai from the address your licence is registered to. We answer within one month. We may ask you to confirm your identity; we will not charge you.

Deleting your data ends any active licence, because the licence is tied to it; we keep invoices where tax law requires.

You also have the right to complain to a supervisory authority: in Cyprus, the Office of the Commissioner for Personal Data Protection (Iasonos 1, 1082 Nicosia; dataprotection.gov.cy), or the authority where you live or work. We would appreciate the chance to put things right first.

8. How we protect it

We collect as little as possible and design so that the most sensitive data never leaves your device. Licences and updates are cryptographically signed. Phone alerts are end-to-end encrypted. Access to our systems is limited to the people who need it and protected by strong authentication. If a personal-data breach occurs that is likely to put you at risk, we will tell you and the supervisory authority as the law requires. See also our Security page.

9. Children

The Service is for adults and is not directed at children under 16. We do not knowingly collect their data; if you believe we have, contact us and we will delete it.

10. Additional information for US residents

We do not sell or “share” personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for purposes that require a right to limit. The categories we collect are listed in section 3. You may request access to or deletion of your information as described in section 7, and we will not discriminate against you for doing so.

11. Changes

We will update this policy when our practices change. For material changes we tell you in the Software or by email before they take effect. The date and version at the top show which version applies.