Privacy

What we can see, and what we cannot.

Fowlguard sits between an organisation's people and the internet. That earns scrutiny, so this page describes the actual boundary the software enforces rather than the widest one the law would allow.

Last updated 11 September 2026

Two parties, and they see different things

Your organisation is the controller of what its own deployment records. Fowlguard operates the platform underneath it. The split is not a policy we promise to keep; it is a division in the product, and the two consoles are separate builds with separate data.

What Fowlguard sees to run the service

Your contacts and their email addresses, your plan, licences, payments and support entitlements, the health of each of your gateways, connection and audit records, and the domain names your traffic asked for. That last one is how new filtering signatures are built.

What Fowlguard cannot see

Your own security decisions (filter rules, access policy, blocked lists, device posture, interception settings, your block page) and content of any kind: payloads, files, message bodies, session recordings, credentials and keys. These are not withheld by convention; the operator console has no route to them.

Content inspection is your choice, on your estate

Where an administrator enables TLS interception, decryption happens on infrastructure you control, under a certificate authority generated on your own host. Banking, healthcare, government and legal destinations are exempt by default; the list is your administrator's to change.

Devices identify themselves, and that is recorded

An enrolled device reports a hardware fingerprint (hostname, network adapter, processor and disk identifiers) so a cloned or stolen credential can be told apart from the machine it was issued to. It is held against your organisation's device record.

Names are resolved locally

DNS queries from an enrolled device are answered by the client on the device itself and by your gateway. They are used to apply your policy, and are recorded where your policy asks for a record.

Sign-in identity

When you sign in with a work identity (Google, Microsoft or another provider) we receive the address and the fact that the provider vouched for it. We do not receive your password, and we do not gain access to that account.

Keeping, sharing, and asking for it back

Operational records are kept while your organisation is a customer and for as long afterwards as we are required to keep billing and audit history. Your administrators can export or delete the records their own deployment holds, from the console, without asking us.

We do not sell personal data, and we do not use your traffic to build products for anyone else. Subprocessors are limited to the infrastructure and payment providers needed to run the service.

Where the law gives you rights over your personal data (access, correction, erasure, objection) write to us and we will act on them; if your employer deployed Fowlguard, ask them first, as they hold the records about your use of it.

Questions, requests and disclosures: privacy@fowlguard.com.