Privacy Policy
This Privacy Policy explains what CF Guard Desk and the public website at cfdesk.greeff.dev collect, store, and expose. The desktop application is designed as a local-first product. By default it does not send product telemetry to greeff.dev, and it does not use a hosted user-account system to function.
1. Who this policy covers
This policy covers:
- the CF Guard Desk desktop application
- the public website at cfdesk.greeff.dev
- support and commercial interactions related to the product
2. Desktop application privacy posture
CF Guard Desk is local-first desktop software.
By default:
- workspace state is stored locally on your device
- Cloudflare secrets are stored in OS-backed secure storage
- findings, history, exports, and notes remain local to the machine
- the desktop app does not send analytics events, crash reports, or product telemetry to greeff.dev by default
3. Local data stored by the app
The desktop app may store the following locally:
- workspace and scan history metadata
- findings, annotations, and suppressions
- export files you explicitly create
- configuration needed to remember operator preferences
- cached license state used for local plan enforcement
The app must not store raw Cloudflare tokens, auth headers, cookies, or other unredacted credentials in SQLite, exports, logs, or diagnostics bundles.
4. Cloudflare communication
When you connect the product to Cloudflare, the app communicates directly with Cloudflare APIs and any limited public-edge verification paths used by the scan profile.
This communication is used to:
- validate access
- discover zones
- collect posture signals
- build findings and scoring output
5. Diagnostics and support bundles
Diagnostics are operator-triggered.
They are not collected automatically, and they are expected to be redacted before sharing. Support bundles are intended to help reproduce issues without exposing secret material.
6. Licensing and purchases
Commercial checkout and license lifecycle actions are handled through Lemon Squeezy.
If you buy or activate a plan, the commercial provider and greeff.dev may process limited commercial data such as:
- name
- product or variant purchased
- license lifecycle state
- purchase timestamp
That data is used for billing, licensing, support, and compliance.
7. Public website analytics and cookies
The public website may use:
- Usercentrics for consent management
- Google Analytics for website traffic analytics
- gtag-based download click tracking when analytics is enabled
This website analytics data is separate from the desktop runtime and does not provide visibility into your local findings, workspaces, Cloudflare tokens, or scan results.
8. Cookies and consent choices
Analytics and related consent choices on the website are managed through Usercentrics. You can review or revise those choices through the site's privacy controls when the consent tooling is enabled.
9. Security expectations
No system can be guaranteed perfectly secure. If you believe a privacy or security issue affects CF Guard Desk, report it through the published support path.
10. Your rights
Depending on applicable law, you may have rights to request access to, correction of, or deletion of personal data associated with support or purchase interactions, subject to legal retention requirements.
11. Contact
For privacy questions, support, or legal notices, contact:
greeff.dev
Email: pio@greeff.dev