Privacy Policy

Last updated: September 11, 2026

This Privacy Policy explains what information SecureShield ("we," "us," "the Service") collects, why we collect it, and the choices you have. It's written to reflect exactly what the product does — not a generic template.

1. What SecureShield is

SecureShield is a website security and uptime monitoring service. For any domain you add and verify ownership of, we regularly check whether it's online, the status of its SSL certificate, and the strength of its HTTP security headers, and we scan for a small set of commonly exposed sensitive files (like .env or .git/config). Separately, for customers who explicitly opt in and point their domain's DNS at us, SecureShield can also run as a reverse proxy with basic firewall (WAF) rules that filter obvious attack patterns before traffic reaches your real server. Section 4 below covers that feature specifically, since it involves more than passive scanning.

2. Information you give us directly

3. Information we generate by monitoring your verified domains

Once you've verified a domain, we automatically collect and store, for that domain only:

None of this monitoring begins until domain ownership is verified, and it only ever targets the domain you've added — never any other site.

4. The reverse proxy / WAF feature (opt-in only)

This feature is off by default and only takes effect if you deliberately enable it for a domain and repoint that domain's DNS at SecureShield. When enabled, incoming requests to your domain pass through our infrastructure, get checked against a basic set of rules (looking for patterns like SQL injection, cross-site scripting, and path traversal attempts), and are then forwarded to your real origin server.

We do not log or store the content of individual requests that pass through the proxy, and we don't retain visitor-level data such as individual IP addresses tied to specific requests. We keep aggregate daily counts per domain — total requests seen and total requests blocked — so you can see traffic trends on your dashboard. If you disable this feature or remove a domain, we stop forwarding its traffic and it reverts to passive monitoring only (or nothing, if you remove it entirely).

Because this feature is a first-pass filter and not a substitute for a mature WAF like Cloudflare or AWS WAF, see the Terms of Service for the specific limits of what it does and doesn't guarantee.

5. How we use your information

6. What we don't do

We don't sell your personal information. We don't monitor, proxy, or access any domain until you've verified you own or control it. We don't use tracking or advertising cookies, and we don't read or store the content of proxied traffic beyond the aggregate counts described above.

7. Data retention

We retain your account, website, and activity data for as long as your account is active. If you remove a website, its associated monitoring history, traffic stats, and detected-threat records are deleted along with it. If you delete your account, all associated data is removed from our systems within a reasonable timeframe.

8. Cookies

We use a single essential session cookie to keep you logged in securely. We don't use tracking or advertising cookies of any kind.

9. Third-party services we rely on

We use a small number of infrastructure providers to operate the Service: a hosting platform to run our servers, a managed PostgreSQL database provider to store data, and a transactional email provider to send account and alert emails. Each only receives the data necessary to perform its specific function, and none of them are permitted to use your data for their own purposes.

10. Your rights

You can update your account information at any time from Settings, generate or revoke your own API key, and configure or remove your alert webhook. You can remove a monitored website at any time, which deletes its associated data. You can request full account deletion, or ask what data we hold about you, through the contact options available in your dashboard.

11. Children's privacy

SecureShield is a business/developer tool and is not directed at children. We don't knowingly collect information from anyone under the age of 16.

12. Changes to this policy

We may update this Privacy Policy from time to time as the Service changes. Material changes will be reflected by updating the date at the top of this page.

13. Contact

Questions about this policy can be sent through the contact options available in your dashboard.