Privacy Policy
Effective 6 September 2026CSP Warden is operated by Warden Software Ltd. This policy explains what we collect when you use the product and the website, why we collect it, who processes it on our behalf, how long we keep it, and the rights you have over it. Questions go to hi@cspwarden.com.
Who we are
Warden Software Ltd is the data controller for the personal data of people who visit cspwarden.com and of people who hold a CSP Warden account.
For the Content Security Policy reports that your website's visitors send to your reporting endpoint, you are the controller and we are your processor. We store and process those reports only to provide the service to you, on your instructions, and the terms of service set out that arrangement.
What we collect about you
When you create an account and use the product, we hold:
- Your name, email address and profile picture, as provided by Google when you sign in. Sign-in is through Google only, so we never hold a password for you.
- Your preferences: the language and the theme you have chosen.
- If you turn on two-factor authentication, the secret your authenticator app uses and the backup codes you were given, stored so that we can check them.
- Your sessions: when each one started, the IP address and browser it came from, and which organisation it was working in, so that you can review and end them from your account.
- Your organisations: their names, the people in them and their roles, and the email addresses of people who have been invited but have not yet joined.
- Billing details for a paid plan: the plan, its status and billing period, and the identifier of your customer record at Stripe. Your card details go to Stripe directly and never reach us.
- Emails you send us and the notices we send you, such as security notices and invitations.
What we collect from your website's visitors
When a visitor's browser sends a Content Security Policy report to one of your endpoints, we keep the parts of it that describe the violation:
- The address of the page, with its query string and fragment removed before storage.
- The address of the blocked resource, with its query string, fragment and any credentials removed. Resources that are not web addresses, such as inline scripts or data URLs, are recorded by kind only.
- The directive that was violated, whether the policy was enforcing or reporting, and the policy itself with any nonces replaced by a placeholder.
- The referring page, sanitised in the same way, the source file, line and column where the browser could name one, the HTTP status of the page, and a short sample of the blocked script where the browser included one.
- The visitor's browser identification string.
- A keyed hash of the visitor's IP address, computed per organisation. The address itself is discarded at the edge and is never stored or queued. The hash lets the inbox count distinct browsers without our being able to recover the address.
We never fetch the pages or resources named in a report. A report is treated as untrusted data from the moment it arrives and is sanitised before anything is stored or shown.
Because these reports come from your website, what they contain depends on how your site is built. If your pages place personal data in paths or in inline scripts, some of it may appear in a report. You are responsible for telling your visitors about this reporting in your own privacy notice.
What we collect on the website
- Vercel Analytics and Vercel Speed Insights run on cspwarden.com and in the product. Neither sets cookies. Page addresses are stripped of their query strings and fragments before they are sent.
- Google Analytics runs on the website only if you accept it in the cookie notice. Until you do, no analytics cookie is set. You can change your choice from the footer at any time.
- Our servers keep request logs holding the request identifier, the account and organisation involved, timings and error messages. They do not hold report bodies, credentials or session cookies.
Why we use it
- To provide the service you signed up for: receiving reports, grouping them into issues, showing them to your organisation and to the agents you connect, and sending you the emails the product needs to send. This is necessary to perform our contract with you.
- To keep the service secure and working: rate limiting, abuse prevention, session review, monitoring and debugging. This is our legitimate interest, and yours.
- To bill you for a paid plan and keep the records the law requires us to keep.
- To understand how the website and product are used, so that we can improve them. Analytics cookies are used only with your consent.
- To respond when you write to us.
We do not sell personal data, and we do not use it for advertising.
Who processes it for us
We use a small number of providers, each of which handles data only to provide its service to us:
- Vercel hosts the website and the product, and provides its analytics.
- Cloudflare runs the reporting endpoints, the queue that carries reports to the database, and the configuration store for endpoints.
- PlanetScale hosts the PostgreSQL database.
- Stripe handles payments and holds your card and billing address.
- Resend delivers the emails we send.
- Google provides sign-in and, if you accept it, analytics.
Some of these providers process data outside the United Kingdom and the European Economic Area. Where they do, the transfer is covered by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, or by an adequacy decision.
Beyond these providers, we disclose personal data only where the law requires it or to protect the service and its users from abuse.
How long we keep it
- Individual reports are kept for 7 days on the Free plan and 60 days on the Pro plan, then deleted automatically. When a plan ends, the shorter period applies.
- The issues built from those reports, meaning the title, the counts and the first and last time each was seen, stay for as long as the organisation exists, so an issue keeps its history after the reports behind it have gone.
- The record that a particular report was received is kept for 14 days so that a delayed redelivery is not counted twice.
- The monthly count of reports received per organisation is kept for billing and quota purposes.
- A session lasts up to 30 days without use, and you can end any session sooner from your account.
- When you close your account, your personal details are deleted immediately and you are removed from every organisation. Anything you did inside an organisation stays with that organisation, without your name on it.
- When an organisation is deleted, its endpoints, issues, reports, members and invitations are deleted with it, and any subscription is cancelled.
- Billing records are kept for as long as tax and accounting law requires.
- Server logs are kept for 90 days for security and debugging, then discarded.
Your rights
You can see and change your name and email address, review and end your sessions, and close your account, all from the account pages. Organisation owners can delete an organisation from its settings.
You also have the right to ask for a copy of the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, and to receive it in a portable form. Write to hi@cspwarden.com and we will respond within a month.
If you are in the United Kingdom you can complain to the Information Commissioner's Office. If you are in the European Economic Area you can complain to your local supervisory authority. We would rather you spoke to us first.
Cookies
- A session cookie keeps you signed in to the product. It is strictly necessary and is set only on the product's own domain.
- A preference cookie remembers the language you chose, so the first page you see is in that language.
- Your answer to the cookie notice is kept in your browser's local storage so that we do not ask again.
- Google Analytics cookies are set on the website only after you accept them.
Security
Everything travels over HTTPS. The product publishes strict security headers, including its own Content Security Policy, and reports its own violations to itself. Reports are sanitised at the edge before they are stored, and the visitor's IP address never leaves the edge. Access to production systems is limited to the people who operate them, and two-factor authentication is available for your account.
If you believe you have found a security problem, please email hi@cspwarden.com and give us a reasonable opportunity to fix it before disclosing it.
Children
CSP Warden is a tool for people who operate websites and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
When we change this policy in a way that matters, we will email account holders before the change takes effect and update the date at the top. Smaller changes, such as a new provider doing the same job, will simply appear here.
Contact
Warden Software Ltd, hi@cspwarden.com.