SwearGuard privacy policy
Last updated: 28 September 2026
SwearGuard is a parental-control app for Windows, with an optional phone app for parents, SwearGuard Parent. A parent installs it on a PC their child uses. This policy explains what it does with information.
In short:
- Listening and watching stay on the PC.
- What goes to the parent's phone is end-to-end encrypted, so our server can't read it.
- Website names are checked with Cloudflare's family filter, the way any web address is looked up.
- When monthly membership activation is enabled, keys are checked through the SwearGuard relay and Gumroad. Builds without a Gumroad product ID do not send keys for checking.
What SwearGuard looks at, and where it goes
| What | Why | Stored? | Leaves the PC? |
|---|---|---|---|
| Microphone sound | To notice swear words and shouting | No. Sound is analysed as it comes in and discarded. | No |
| The words spoken in a sentence that contained a swear word | So the parent can see what was said in the activity log | Yes, in the activity log on the PC | No |
| Webcam picture (only if the parent turns on a camera feature) | To notice wild movement, a phone held up, a covered camera, or nobody at the PC | No. Pictures are analysed as they come in and discarded. | No |
| The address of the browser tab in front | To apply the parent's YouTube and Shorts rules | No. Only minutes of YouTube and Shorts used today are kept. | No |
The name of each new website in the browser (for example example.com, never the full address) |
To close adult websites (on by default, can be switched off) | Answers are remembered in memory for an hour | Yes: the name is looked up with Cloudflare's family DNS (family.cloudflare-dns.com), like any DNS lookup |
| Adult websites the child tried | So the parent knows | Yes, in the activity log | Only end-to-end encrypted to the parent's phone, if one is connected |
| Settings, parent PIN (as a salted hash), strikes and activity log | So SwearGuard works and the parent can review what happened | Yes. Protected settings, PIN and counters are in %ProgramData%\SwearGuardPrivate on an installed PC; the ordinary activity log is in %ProgramData%\SwearGuard |
The PIN never. Status, activity (swear words masked) and some settings are sent end-to-end encrypted to paired phones |
| Screen-time and app-use totals (including app names), YouTube and Shorts minutes | To enforce the parent's time limits and show use | Yes, in usage files on the PC | Totals and app names are included in the encrypted status sent to paired phones |
| Phone-pairing key and access token | To connect the PC to the parent's phones | Yes, in protected state on an installed PC | The key is shared with a phone in the pairing QR code, not sent to the relay; the relay receives the PC's access token and stores its hash |
| License key, purchased device count, random installation ID and verification dates, when licensing is enabled | To activate and recheck a monthly membership and enforce its PC allowance | Yes, in protected state on an installed PC | The key, product ID and random installation ID are sent to the SwearGuard licensing relay on activation and normally once a day. The relay forwards the key and product ID to Gumroad (api.gumroad.com) and stores hashes of the key and installation ID for the device allowance; it does not store the raw key. The PC stops guarding after three days without successful verification |
SwearGuard has no user accounts, app analytics, advertising or tracking. It never uploads audio, pictures or browsing history. Its local activity log can include a swear-word sentence and the name of an adult site the child tried to open.
The SwearGuard Parent phone app (optional)
When a parent connects a phone, the PC sends it:
- the PC's status (locked, paused, strikes, screen time, YouTube and Shorts minutes, microphone and camera state), plus the names and use of apps found on the PC;
- activity (for example "Swearing: s***", "PC locked", "Asks for more time");
- the rules the parent may change from the phone.
The swear word is masked and the sentence around it is not sent.
All of this is encrypted on the PC with a key shared only by that PC and the paired phones. The key is inside the QR code the parent scans, and it is not sent to our server. Our server (a Cloudflare Worker) cannot read message content. It can see connection and event times, whether the PC is online, and which events request a push notification. It keeps:
| What | Why | How long |
|---|---|---|
| Encrypted latest status, the last 200 encrypted events, and up to 20 waiting commands | So the phone can catch up when it opens | Status remains until replaced or successfully deleted. Older events are replaced by newer ones. Waiting commands are cleared when the PC reconnects or newer commands replace them |
| Encrypted names of the PC and phones; hashes of their access tokens | To show paired devices and check access | Until the phone is successfully removed or all phones are successfully disconnected |
| A phone's push-service address | To make the phone buzz | Until that phone is successfully removed, all phones are successfully disconnected, or the push service reports the address invalid |
| Event and pairing times, push flags, and whether and when the PC went offline | To show activity and connection state and send alerts | Event times roll off with the oldest of the last 200 events. Pairing and offline times remain until the relevant entry is removed or the family data is successfully deleted |
Push notifications carry no content. They only wake the app, which then fetches and decrypts the news itself. Standard web requests to the parent app also pass through Cloudflare, which receives connection details such as IP addresses and request times.
The parent app keeps each pairing's encryption key and access token in the phone's IndexedDB storage. It also caches the latest decrypted status and up to 60 activity events in the phone's local storage, so they remain visible when it is offline. Removing a PC from the phone removes that local pairing and cache and tries to delete the phone's entry on the relay.
When the relay confirms a Disconnect all phones request from the PC, it deletes the family's data on the relay. If that request fails, if a phone is removed while offline, or if SwearGuard is uninstalled without a successful disconnect, server data can remain. There is currently no automatic expiry for an inactive family's stored data. Disconnect all phones while the PC is online before uninstalling.
Safe internet (optional)
When a parent turns on safe internet, SwearGuard changes Windows' own settings on the PC:
- the DNS servers, to Cloudflare for Families;
- the hosts file, for SafeSearch;
- the browser policies.
From then on, the PC's web addresses are looked up with Cloudflare's family DNS instead of the internet provider's. Cloudflare's privacy policy for its public DNS applies.
Turning safe internet off, or uninstalling SwearGuard, puts the previous settings back.
Children
SwearGuard is used by parents to supervise their own children. Nothing about the child leaves the PC except:
- website names looked up with Cloudflare's family filter;
- the end-to-end encrypted updates for the parent's own phones.
We can't read those encrypted updates. When paid licensing is enabled, the parent's license key goes through our licensing relay to Gumroad, which issued it with the purchase.
Your control
- The parent can switch features off in settings.
- The activity log can be read and deleted from the data folder (Settings → General → Open).
- Uninstalling SwearGuard deletes its local data folder, including the activity log, and turns safe internet off. It does not itself clear the relay's data.
- Parents can request Disconnect all phones from Settings → Parent app. A successful relay response deletes the family's server data. An offline PC cannot complete that deletion.
Purchases
When paid licensing is enabled, monthly memberships are handled by Gumroad and Gumroad's privacy policy applies to them. Builds without a Gumroad product ID do not contact the licensing relay or Gumroad to activate or recheck keys.
Contact
Questions or privacy requests: email support@goosen.biz.