Living with it

Your data and your privacy

What stays on the PC, what the license check sends, what telemetry is, and how to export or erase everything.

5 min read · updated July 25, 2026

A tool that watches every connection your computer makes is exactly the kind of tool you should be suspicious of. So here's the whole picture: what stays local, what leaves, and how to get rid of any of it. The privacy policy is the formal version; this is the plain one.

What never leaves your PC

  • Every connection you have ever seen — addresses, hostnames, ports, byte counts, timings.
  • The DNS log: which names were looked up, and by what.
  • Your rules, whitelists, categories, and parental-control settings.
  • Detections, incidents, and everything in the dashboards.

That's not a policy choice we could quietly reverse. It's the design: there is no upload path for traffic data in the product.

NetSecWall never decrypts anything. It records that a connection happened and how big it was, never what was inside it. The contents of your messages and downloads do not exist anywhere in the product.

What does leave, and why

Goes outCarriesWhy
License checkYour key, a one-way device hash, app version, hostname, coarse countryTo validate the license and count seats. The device hash is salted and cannot be reversed into hardware identifiers.
Threat feedsNothing about you — it's a downloadTo fetch the blocklists. We don't send the addresses you visited to be checked; the lists come to you and matching happens locally.
Update checkCurrent versionTo find out whether a newer build exists.
TelemetryCoarse events, OS and app version, localeOnly if you switched it on. Never traffic, hostnames, or file paths.
The second row is the one worth noticing. Some tools send every domain you visit to a server to be checked against a reputation list. NetSecWall downloads the list instead, so your browsing is never the query.

Telemetry is opt-in, and declining costs nothing

You're asked once, during the trial. Left alone, it stays off. Turning it down does not shorten the trial, lock a feature, change a price, or affect a license. The app is identical either way. You can change your mind in both directions underHelp ▸ Privacy & telemetry.

When it's on, the events are allow-listed on our side: anything not on the list is dropped rather than stored. Retention is capped and purged automatically.

Getting your data out, or deleting it

Both live under Help ▸ Privacy & telemetry in the app:

  • Export — a machine-readable copy of everything tied to your install or email.
  • Erase — deletes your telemetry, devices, and account data. Immediate, and not reversible.
  • Opt out — stops telemetry with one toggle, keeping everything else working.

You can also raise these as a privacy request. We answer within 30 days as the law requires, usually far sooner, and never charge for it.

Erasure covers what we hold. It cannot remove invoices, which tax law requires us to keep for several years. That obligation overrides an erasure request for the invoice itself, and any provider claiming otherwise is not being straight with you. Everything else goes.

Uninstalling

Uninstalling removes the program, its service, and its rules. Your local traffic database is left in place, because people reinstall and expect their history back. If you want it gone, delete it explicitly — the app's factory-reset option does exactly that.

If someone else administers your machine

On a company device running the Enterprise management server, entitlement and policy come from your organization's server, and compliance state is visible to whoever runs it. That's the point of a managed deployment. Our acceptable use policy requires organizations to have a lawful basis and to tell their users. If you didn't know the software was there, that's a conversation to have with whoever installed it.

Still stuck? Open a support ticket — we reply within one business day.