Privacy Policy
Effective: 28 August 2026 · AEGISITE (aegisite.workflo.hu)
In short: AEGISITE is built so you have to trust us with as little as possible. Scanning runs on your device and your detection history stays on your device. Section 3 lists everything our servers hold, and there is nothing beyond it: your account, and — only where a parent has turned on child monitoring — alerts we cannot read, kept for 30 days.
1. Who is the controller?
AEGISITE is operated by Workflo (a sole trader established in Ireland; contact: info@workflo.hu). For any privacy matter, write to this address.
2. What does the software process on your device?
The AEGISITE desktop app, browser extension and mobile app analyze locally, on your own device:
- metadata of running processes and installed apps (name, identifier, AI characteristics),
- content on AI sites for signs of prompt injection and data exfiltration,
- network connection metadata (where an AI process connects to).
The content itself never reaches our servers: what you type, the text of the pages you read and the files on your disk stay on the device. What does reach your own account is the detection summary described in section 3. The 30-day detection history is stored exclusively on your device, and you can delete or export it at any time.
The browser extension in particular makes no network requests of its own: its detection rules ship inside the extension, and when it catches something it notifies only your own AEGISITE app on the same device, never our servers.
3. What does our server see?
- Account data (if you register): email address and subscription status.
- Live overview: when we block a site, your device reports to your own account the blocked domain, a category, a severity, the time, and your device's identifier — that is how you see on your other devices what was blocked. The server keeps this in memory only, in a rolling 6-hour window, then discards it; it is never written to a durable database and it is cleared on restart. Besides blocks, your device also reports the AI tools it detects even when nothing is blocked (the tool or app name, a rule or package identifier, a category, a severity and the time; on iPhone also the result of the AI Safety Check), so the overview can list them. Nothing about the pages you visit, or what you did on them, is included.
- Name resolution: while the filter is on, names are resolved by public DNS resolvers (1.1.1.1, 9.9.9.9, 8.8.8.8) instead of your network's own. They see the query, as any DNS resolver does — they receive no account identifier, and we receive nothing from them.
- Payments: card details are handled by Stripe, by Google Play on Android, and by Apple on iPhone. We never see them.
- Child-safety alerts — only if a parent has turned child monitoring on for a device in their family. When the check running on that device flags something, your account receives a category, a severity, the time, the kind of device, and a short excerpt of the flagged text. The excerpt is encrypted on the child's device so that only the parent can open it. We keep the alert for 30 days and then delete it. So that you do not lose those alerts when you replace your phone, your device also creates a master key for the family. That key is wrapped with your account password on your own device (technically, with a key derived from that password); only the wrapped form ever reaches us, and we cannot unwrap it — only your password can open it. That is what lets you sign in on a new device and still open older alerts, with no code to type. The trade is plain: if you ever do a password reset because you forgot your password, the older alerts can no longer be opened; new ones keep working. The excerpt is what an AI answered on the device — or, where picture checking is also on, text recognised from a picture the child attached, in which case the picture itself never leaves the device, in any form. Nothing is blocked automatically because of an alert: the parent reads it and decides.
- Counts that outlive the alert: separately from the alerts above we keep a running count of how many were raised, per day, category, severity and kind of device. It is a number and nothing else — no account, family, child, device or subscription identifier, no excerpt, and no time of day. We keep it so we can answer questions such as how many self-harm flags the product raised last month. Because it identifies nobody, the 30-day deletion above does not remove it, and neither does an erasure request.
4. What we do NOT collect
- We cannot see what you type, paste, or ask an AI. Child monitoring does not change that: what the child types is not sent. What may be sent is a short excerpt of the AI's answer, and only to their own parent, encrypted — see section 3.
- We do not collect browsing history: we never report the pages you visit. Only the domains we blocked and the AI tools we detected (section 3) — and those only to your own account.
- We use no advertising or remarketing cookies, and we sell no data to anyone. The website itself uses analytics only, described in the Cookie Policy.
5. Legal basis and your rights (GDPR)
Account data is processed to perform the contract (GDPR Art. 6(1)(b)). You can request deletion of your account and data at any time, in-app or by email; deletion of durable account data takes effect immediately, and any child-safety alerts held for your family go with it. The identifier-free counts described in section 3 are the one exception, because they contain nothing that could be traced back to a person. You have the right of access, rectification, erasure, restriction and portability, and you may lodge a complaint with your supervisory authority.
6. Transfers and processors
Payments: Stripe (with EU data-processing terms), Google Play (Android) and Apple (iPhone). Transactional email (sign-in links): Resend. Push notifications to parent devices (child-safety alerts and access requests): Expo's push service, which receives the device's push token, a generic notification text and the alert's category and severity — never the excerpt. Beyond these, no data is shared with third parties.
7. Changes
If this policy changes materially, we will indicate it on the website. Continued use constitutes acceptance of the updated policy.