Privacy Policy
Last updated: September 5, 2026 • 100% Client-Side In-Browser Execution.
Our Core Promise: Your Data Never Leaves Your Device
BandwidthGuard is built with an absolute privacy-first architecture. All payload analysis, field size breakdowns, 3-tier actionable recommendations, compression benchmarks (Gzip, Brotli, Zstandard, MessagePack, CBOR), network latency modeling, and egress cost simulations execute 100% locally in your client device's browser memory. No JSON records, headers, tokens, or PII ever touch a remote server.
1. Zero Data Collection & Zero Telemetry
When you paste, drag-and-drop, or fetch API responses in BandwidthGuard:
- We do not send your JSON payloads to any remote backend server, cloud service, or database.
- We do not log, store, or inspect authentication headers, API keys, bearer tokens, or cookies.
- We do not run user session trackers, analytics pixels, or advertising beacons.
- All AST parsing, field breakdowns, and compression streams run strictly inside local browser memory.
2. URL Hash Sharing Security (RFC 3986)
When you use the "Share Analysis" button, the application encodes the payload into the URL hash fragment (the portion after the # symbol).
Only individuals with whom you explicitly share the URL can access and decode the payload in their local browser. Caution: Do not generate share links containing production passwords, confidential tokens, or secrets.
3. Live Fetch & Ephemeral Memory
When you use the "Fetch API Endpoint" modal, HTTP requests are dispatched directly from your browser client to the target server (subject to standard browser CORS security policies).
Response headers, timing metrics, and JSON data are stored ephemerally in browser RAM and are never relayed to any third-party relay. If you refresh or close your browser tab, your working state is immediately discarded from memory.
4. Client-Generated AI Fix Prompts
BandwidthGuard generates formatted markdown prompts for AI coding assistants (such as Cursor, Claude, ChatGPT, Antigravity, Gemini, and Copilot) directly on your device using client-side string templating.
BandwidthGuard does not make background API calls to external LLM providers. Pasting generated prompts into your IDE or external AI tools is governed by your own direct agreements with those respective providers.
5. Regulatory Compliance (GDPR Article 17 & CCPA)
Because BandwidthGuard collects, retains, and processes zero personal data on its servers, there is no personal data record to request, modify, or delete under GDPR Article 17 or CCPA regulations. You maintain 100% sovereignty over your data at all times.