Privacy policy
Last updated · July 25, 2026
NetSecWall watches your network traffic for you, on your machine. Your traffic, connection history, rules, and detections stay on your PC — they are never uploaded. The app works without an account, and everything it sends anywhere is listed on this page.
What stays on your device
- All captured traffic metadata, per-app history, and statistics (local SQLite database).
- Firewall rules, whitelists, detection rules, category lists, and parental-control settings.
- Alerts, incidents, and everything you see in the app's dashboards.
What the licensing service receives
- Your license key, email, and name (to issue and validate keys you request).
- A one-way device hash — a salted fingerprint used to run the 7-day trial and count seats. It cannot be reversed into hardware identifiers.
- App version, hostname, and coarse country for your own account's device list.
- Raw IP addresses are not stored — only a salted hash that rotates daily. A raw IP is retained solely on concrete abuse signals (key sharing or tampering).
Telemetry — off unless you turn it on
- Anonymous usage analytics are strictly opt-in. You are asked once, during the 7-day trial, and you can change your answer at any time under Help ▸ Privacy & telemetry. Left alone, telemetry stays off.
- When enabled: coarse events (app launched, feature used), OS version, app version, locale. Never traffic contents, hostnames you visit, or file paths.
- Events are allow-listed server-side; anything else is dropped. Retained at most 425 days, then purged automatically.
Saying no costs nothing. Declining telemetry, or switching it off later, is unconditional: it does not shorten your trial, lock a feature, change a price, or affect a license you own. The app is identical either way. If you decline during the trial, we do take that moment to show you what a license costs. That is an offer, not a condition, and dismissing it leaves your answer exactly as you set it. We do not operate “consent or pay”: there is no version of NetSecWall you have to buy in order to refuse analytics, and no discount for accepting them.
Enterprise / on-prem deployments
With the self-hosted NetSecWall Management Server, agents report to your organization's own server — events, versions, and compliance state never reach us. The server contacts our licensing API exactly once, at activation, to validate your Enterprise key. After that it runs fully offline.
Payments
Card, PayPal, and wallet purchases are sold and processed by Paddle.com Market Ltd, our Merchant of Record. Paddle collects the payment details, runs fraud checks, charges the applicable tax, and issues your invoice. We never see or store your card number — it does not pass through our servers.
Purchases are handled by our payment provider. We never see or store your card number — it does not pass through our servers. What reaches us is the order reference, the plan, the amount, and the email you gave us.
Where we offer cryptocurrency, the payment is handled by that processor and we are the seller of record. We receive the order reference, the plan, the amount, and the email you gave us — the same fields as any other order. We do not receive or store your wallet address unless you send us one yourself to receive a refund, and we keep that only as long as the refund takes. A blockchain payment is public by nature: the transaction itself is visible on-chain to anyone, which is a property of the network and not something either of us controls.
What we receive back from Paddle is limited to what's needed to issue and support your license: an order reference, the plan bought, the amount and currency, your email address, and the country used for tax. Paddle's own handling of your data is described in its privacy notice.
Order records are kept for as long as tax and accounting law requires (typically 7 years), then deleted. This retention overrides an erasure request for the invoice itself, because it is a legal obligation we cannot waive. Everything else tied to you is still erased on request.
Cookies and this website
- This site sets no advertising or tracking cookies and runs no third-party analytics.
- Your light/dark theme choice is kept in
localStorageon your own browser. Nothing is sent to us. - Web fonts are loaded from Google Fonts, which receives your IP address as part of serving the request.
- The checkout page loads the payment provider's secure fields; the provider may set cookies strictly necessary to process your payment and prevent fraud.
- Standard web server logs (IP, user agent, path, timestamp) are kept briefly by our host for security and troubleshooting.
Legal bases and sharing
- Contract — issuing, validating, and supporting a license you bought or requested.
- Consent — optional telemetry, freely given, never a condition of using or buying the software, and withdrawable at any time with one toggle.
- Legitimate interests — preventing license abuse and fraud, keeping the service secure.
- Legal obligation — keeping invoices and tax records.
We share data only with the processors that make the service work: our payment provider, our email delivery provider, and our hosting provider. We do not sell or share personal information for advertising, under any definition, including the CCPA/CPRA meaning of “sell” and “share.”
Your rights (GDPR · CCPA/CPRA · APPI · PDPA)
- Access & export — request a machine-readable copy of everything tied to your install or email.
- Correct — fix the name or email on your license.
- Delete — request erasure of your telemetry, devices, and account data.
- Opt out — stop all telemetry with one toggle; licensing checks carry only the minimum above.
- Complain — you may lodge a complaint with your local data-protection authority. We'd rather you told us first.
The first four are available in-app under Help ▸ Privacy & telemetry, or by email — make a privacy request. We answer within 30 days and never charge for one.
Children
NetSecWall is sold to adults. The parental-control features are configured by a parent or guardian on a family device; we do not knowingly collect personal information from children. If you believe a child's data reached us, make a privacy request and we will delete it.
What we never do
- Sell, rent, or share your data with advertisers or data brokers.
- Upload your browsing or traffic history — the product's entire design keeps it local.
- Ask for an account, an email, or a card to run the 7-day trial.
- Make analytics the price of anything — see the telemetry note above.
Questions? make a privacy request
Questions about this page? contact us