Privacy Policy
Effective: 4 July 2026 · AEGISITE (aegisite.workflo.hu)
In short: AEGISITE is built so you don't have to trust us. Scanning runs on your device, your history is stored on your device, and our servers keep no durable data about you. What we never collect, we can never lose.
1. Who is the controller?
AEGISITE is operated by Workflo (a sole trader established in Ireland; contact: info@workflo.hu). For any privacy matter, write to this address.
2. What does the software process on your device?
The AEGISITE desktop app, browser extension and mobile app analyze locally, on your own device:
- metadata of running processes and installed apps (name, identifier, AI characteristics),
- content on AI sites for signs of prompt injection and data exfiltration,
- network connection metadata (where an AI process connects to).
This data never reaches our servers. The 30-day detection history is stored exclusively on your device, and you can delete or export it at any time.
3. What does our server see?
- Account data (if you register): email address and subscription status.
- Live overview: when we block a site, your device reports to your own account the blocked domain, a category, a severity, the time, and your device's identifier — that is how you see on your other devices what was blocked. The server keeps this in memory only, in a rolling 6-hour window, then discards it; it is never written to a durable database and it is cleared on restart. We report nothing about allowed traffic.
- Name resolution: while the filter is on, names are resolved by public DNS resolvers (1.1.1.1, 9.9.9.9, 8.8.8.8) instead of your network's own. They see the query, as any DNS resolver does — they receive no account identifier, and we receive nothing from them.
- Payments: card details are handled by Stripe, by Google Play on Android, and by Apple on iPhone. We never see them.
4. What we do NOT collect
- We cannot see what you type, paste, or ask an AI.
- We do not collect browsing history: we never report the pages you visit. Only what we blocked — and that only to your own account.
- We use no advertising or remarketing cookies, and we sell no data to anyone. The website itself uses analytics only, described in the Cookie Policy.
5. Legal basis and your rights (GDPR)
Account data is processed to perform the contract (GDPR Art. 6(1)(b)). You can request deletion of your account and data at any time, in-app or by email; deletion of durable account data takes effect immediately. You have the right of access, rectification, erasure, restriction and portability, and you may lodge a complaint with your supervisory authority.
6. Transfers and processors
Payments: Stripe (with EU data-processing terms), Google Play (Android) and Apple (iPhone). Transactional email (sign-in links): a transactional email provider. Beyond these, no data is shared with third parties.
7. Changes
If this policy changes materially, we will indicate it on the website. Continued use constitutes acceptance of the updated policy.