Privacy Policy
Version 1.1 · Effective 2 October 2026
This policy explains what personal data GuardMyMark ("we", "us") collects when you use GuardMyMark (https://guardmymark.com) and its website, why we collect it, how long we keep it, and what rights you have.
Summary.
- We collect only what we need to run the product and bill you. We do not sell personal data, and we do not use it for advertising.
- Our website uses no tracking or advertising cookies. We measure visits with self-hosted, cookieless analytics.
- Data you put into the product belongs to your organisation. We process it on your organisation's instructions (we are its "processor"), under our Data Processing Addendum.
- Our servers are in Germany (EU). The few services we use are listed on our Subprocessors page.
- Email privacy@guardmymark.com to access, correct or delete your data.
Contents
- Who we are
- Our two roles: controller and processor
- What we collect and why
- Data in the product
- Cookies and analytics
- AI features
- Who we share data with
- Where your data is stored and international transfers
- How long we keep data
- How we protect data
- Your rights
- US state privacy notice
- Children
- Changes to this policy
- Contact and complaints
1. Who we are
GuardMyMark is provided by Kostyrin Maksym, a sole proprietor registered in Ukraine, at Milutenka 23, Kyiv. For privacy questions email privacy@guardmymark.com.
Representatives (GDPR Art. 27 / UK GDPR). We are not established in the EU or the UK. Our position on representatives is:
- EU representative: not appointed — the service is offered to businesses in the United States only
- UK representative: not appointed — the service is offered to businesses in the United States only
We are a one-person company, so we have not appointed a data protection officer; the founder is responsible for privacy.
2. Our two roles: controller and processor
- Controller. We decide how and why we use data about visitors to our website, people who use our free tools, people who sign up for an account, people we contact about our products, and people who contact us. This policy mainly covers that data.
- Processor. When your organisation uses GuardMyMark, it decides what data goes into the product (for example, content from a connected system, or details submitted by its own customers). For that data your organisation is the controller and we act on its instructions under our DPA. If you are one of those people (for example, a customer of a business that uses GuardMyMark), please contact that business first; we will help it respond. Section 4 describes this data.
3. What we collect and why
| Who | Data | Why | Legal basis (EU/UK) |
|---|---|---|---|
| Website visitors | Pages viewed, referrer, approximate country, browser and device type, derived from your request. Your IP address is used transiently and not stored by our analytics. | To understand which pages are useful and to keep the site secure (rate limits, abuse prevention). | Legitimate interests (running and improving a website; security) |
| Free-tool users | What you enter in the tool (see section 4 and the product section below), your email address if you ask us to email you the result, and technical data as for visitors. | To run the tool and send you the result you asked for. | Performance of your request (contract); legitimate interests (preventing abuse) |
| Account holders | Name, email address, organisation name, sign-in data (a Google account ID if you sign in with Google), team members you invite, settings, and records of your acceptance of our terms. | To create and secure your account, provide the service, and send service emails (for example email confirmation and password reset, alerts, reports, billing and security notices). | Contract; legitimate interests (security, keeping records) |
| Customers (billing) | Plan, subscription status, invoices and the country for tax. Creem collects your payment details; we never see or store full card numbers. | To manage your subscription. | Contract; legal obligation (tax and accounting records) |
| Product usage | Which features are used and when, error reports, and logs (IP address, time, request path). | To operate, fix, secure and improve the service. | Legitimate interests |
| People who contact us | Your messages to support (email or chat) and any information you include. | To answer you and improve support. | Legitimate interests; contract (if you are a customer) |
| People we contact about our products | Business contact details that are publicly available (for example a business name, website, business email address and city) that we gathered from public business listings and websites. | To tell businesses about a product that may be useful to them, by email, with an opt-out in every message. | Legitimate interests (B2B direct marketing). We don't send marketing email to individuals where the law requires prior consent. |
| Product news | Your email address, if you opt in (checkbox at sign-up or on a waitlist). | To send occasional product updates. You can unsubscribe at any time. | Consent |
We don't knowingly collect special-category data (such as health data) about you, and we don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
If you don't provide data. We need your email address to create an account. Everything else is optional or comes from your use of the product.
4. Data in the product
GuardMyMark handles three kinds of data — public register records, the content of your workspace, and what a visitor types into the free clash check — and the rules are not the same for all three.
4.1 Public register data (we are the controller)
We download what the trademark offices listed on our website publish about new applications — today the USPTO, with the EUIPO and WIPO added as each office grants us access: the mark text, the application number, the Nice classes, the filing and publication dates, the status and the applicant's name. An applicant is often a person, so that name is personal data. We process it because comparing new filings against our customers' marks is the entire service and cannot be done any other way; our legal basis is legitimate interests (Art. 6(1)(f)), the data is already public by law, and we add nothing to it. Applicants are not our customers and we never contact them.
We keep a copy of the raw register file a record was parsed from for 30 days, so that a fix to our parser can be replayed over a window without re-downloading it.
4.2 Your watch list and its results (we are your processor)
For everything your organisation puts into the product we act on your instructions under our DPA:
| What | What it holds |
|---|---|
| Watched marks | The mark text you entered, the Nice classes, which registers to watch, and the sensitivity you set |
| Hits | A link to the filing that scored, the score out of 100, the signals behind it, and your "not relevant" feedback |
| Deadlines | The closing date we computed for a hit, and the extension if the office published one |
| Lookalike domains (where your plan includes them) | Domains resembling a watched mark that appeared in a public Certificate Transparency log, with the certificate issuer and whether the domain can receive mail |
| Attorney packs | A PDF per hit, holding what the hit page shows, stored in EU object storage and downloadable from the hit (or rebuilt from the rows above if we no longer hold a copy) |
| Workspace settings | Your brand logo and white-label flag, bought seats, and whether the weekly notice is paused |
What we never store. We do not store an opinion about whether a filing infringes your mark or whether you should oppose it. There is no field for one. See the Disclaimer.
Taking it with you. Every row in the table above leaves in the account export (/account → export your data) as
JSON, together with the address of each attorney pack. Your payment records are not in it: the merchant of record holds
those, and your plan is on your billing page.
The weekly notice goes to the owner of the organisation. Its links carry a signed token instead of a login, because they are clicked out of a mail client: a token covers one filing, or the on/off switch for the notice itself, and nothing else. Anyone you forward a notice to can see that one filing, and can download that filing's attorney pack — which is the point of the link: the pack is what you forward to your attorney, and they have no account. Turning the notice off with the unsubscribe link pauses the email, never the watch — the watch keeps running and the hits keep arriving in the app.
The calendar feed (/ics/…) works the same way: the URL is the credential. Treat it like a password, and ask us to
rotate it if it leaks.
4.3 The borderline comparison, and the only place AI is involved
Most comparisons are decided by arithmetic we wrote: phonetics, spelling distance, shared words and Nice-class relatedness. For the small share of pairs that land in the middle band, where those signals cannot settle it, we ask a language model (Anthropic's Claude Haiku — see Subprocessors) how similar the two texts read.
What is sent: the watched mark's text and classes, the filing's text, classes and office, and our own signal scores. Nothing else — not your name, not your email address, not the rest of your watch list, not your workspace. The model is told it is not a lawyer and is forbidden from saying that a filing infringes, that marks are legally confusable, or that anyone should oppose; an answer that says so is discarded rather than stored. Under Anthropic's commercial terms the content is not used to train models.
4.4 The free clash check (we are the controller)
The free check at /check needs no account. We store the mark text and classes you typed and the report we produced.
The report lives at its own unguessable address so that you can forward it to your attorney without them signing in —
anyone holding that link can read that one report, and it contains nothing but public register data and your own
query.
We store an email address against a report in exactly two cases:
- You asked us to send it to you. We then send you that one report, once. We do not add the address to a mailing list, and that report sends no other email.
- You were signed in when you ran the check. We store the verified address already on your account, so the report appears in your own list of checks and you can find it again. It is taken from your session, never from anything you typed, and it is never used to send you anything you did not ask for.
A report with no address on it stays anonymous: it is not listed against any account, and signing up later does not attach it to you.
A free report and the address attached to it are deleted 90 days after the check was run — the link stops working then, for you and for anyone you sent it to. You can have it deleted sooner: email privacy@guardmymark.com with the report link and we delete the row within 30 days.
4.5 Retention
| Data | How long |
|---|---|
| Watched marks, hits, deadlines, lookalike domains, attorney packs | While your account is open. Deleted within 30 days after you delete them or close the account, and from backups as those expire |
| Public register records in our index | Kept while we run the service; they are public records, not account data, so closing your account does not remove them |
| Raw register files | 30 days |
| Free clash-check reports | 90 days from the check, or sooner on request (section 4.4) |
| Your "not relevant" feedback | On the hit, so it goes when the hit goes. We may copy the pair it labelled — the two mark texts and the score, with nothing that identifies you or your workspace — into the test set that keeps our scoring honest, and that copy stays |
5. Cookies and analytics
We don't use advertising, social-media or cross-site tracking cookies, and we don't use Google Analytics. That is why you don't see a cookie banner.
What we do use:
| Name / type | Where | Purpose | Duration |
|---|---|---|---|
Session cookie (for example better-auth.session_token) |
App, after you sign in | Keeps you signed in. Strictly necessary. | Until you sign out, or up to 30 days |
| Sign-in security cookies (state / CSRF) | Sign-in pages | Protects sign-in and "Sign in with Google" against forgery. Strictly necessary. | Minutes |
Cloudflare security cookies (for example __cf_bm, Turnstile) |
Website and app | Bot and abuse protection. Strictly necessary. | Up to 30 minutes |
| Creem checkout | Checkout page only, when you choose to buy | Processes your payment and prevents fraud. Set by Creem as the seller, on Creem's own domain. | Set by Creem |
| Chat widget | Only after you click "Chat with us" | Keeps your support conversation open. See the Subprocessors page. | Up to 6 months |
Analytics. We use Ahrefs Web Analytics (Ahrefs Pte. Ltd.), a cookieless analytics tool. It does not set cookies and stores nothing on your device, and it builds no profile of you across sites. It records the page address, the referring page, your browser and device type, your screen size, and a country derived from your IP address; the IP address itself is not stored. We cannot identify you from this data and we don't combine it with other data. Unlike the tools we run on our own servers, Ahrefs is a third party, so it is listed on the Subprocessors page. If your browser sends Global Privacy Control or "Do Not Track", the analytics script is not loaded at all — it is never sent to your browser, rather than sent and asked to stay quiet. Pages whose address could itself identify you or carry a token — a shared report link, a password-reset link — load no analytics whatsoever.
If we ever add non-essential cookies (for example advertising conversion tracking), we will ask for your consent first and update this section.
6. AI features
The product section above says which features use AI and what they send — and a product that says it sends nothing, sends nothing. Where a feature does send content to an AI provider (named on the Subprocessors page) to generate results such as drafts or suggestions, we send only the content needed for the task. Under the provider's commercial terms, it does not use this content to train its models and keeps it only for a limited time for safety and abuse monitoring. We never use your content to train any AI model.
7. Who we share data with
We share personal data only:
- With service providers (subprocessors) who help us run the product, such as hosting, email delivery and AI. They may use the data only to provide their service to us. The full list, with locations, is on our Subprocessors page.
- With Creem, our reseller and Merchant of Record, which processes your purchase as an independent controller under its own privacy notice.
- With Google, if you choose "Sign in with Google" (Google tells us your name, email address and account ID; Google's privacy policy applies to your Google account).
- With systems you connect. When you connect a third-party system, data flows between it and GuardMyMark because you asked for it.
- When the law requires it, or to protect our rights, users or the public (for example in response to a valid court order). Where allowed, we will tell you first.
- If the business is transferred, for example if the product is moved into a company the founder sets up or is sold. We will tell you, and this policy will continue to protect your data.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
8. Where your data is stored and international transfers
Our application servers and database are hosted by Hetzner in Germany (EU). Encrypted backups are kept on our Hetzner server and in Cloudflare R2 storage restricted to the EU jurisdiction. Some subprocessors are in the United States (see the Subprocessors page); for those we rely on the EU–US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses (with the UK Addendum for UK data).
The founder works from Ukraine, which the EU and UK have not recognised as providing "adequate" protection. Access from Ukraine is remote, encrypted and limited to what is needed to run and support the service. Data is not copied to local devices except where needed to handle a support request, and then deleted.
9. How long we keep data
| Data | How long |
|---|---|
| Account data | While your account is open. Deleted within 30 days after you close it (60 more days in backups). |
| Customer data in the product | See the product section above. Deleted within 30 days after your account closes, or earlier when you delete it. |
| Billing records | As long as tax and accounting law requires (currently up to 7 years). Creem keeps its own records. |
| Support conversations | 3 years after the last message. |
| Server logs and error reports | 30 days. |
| Website analytics | Aggregated, without personal identifiers; kept indefinitely. |
| Records of outreach and opt-outs | Contact details of people we contacted: 24 months after the last contact. Opt-out list: kept permanently so we never contact you again (only the email address). |
| Records of your consents and acceptance of terms | For as long as your account exists plus 3 years, to prove what was agreed. |
10. How we protect data
Data is encrypted in transit (TLS) and at rest. Secrets such as API keys are additionally encrypted in our database. Access is limited to the founder, uses strong authentication, and is logged. See our Security page for details. If a personal-data breach affects you, we will notify you (and, as your processor, your organisation) without undue delay.
11. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- correct it if it is wrong;
- delete it;
- restrict or object to our use of it, including objecting at any time to direct marketing;
- port it to another service in a machine-readable format;
- withdraw consent where we rely on consent (this doesn't affect what we did before); and
- complain to a data protection authority (see section 15).
To exercise these rights, email privacy@guardmymark.com from the address linked to your account, or use the account settings where available (export, delete account). We reply within 30 days. We may need to verify your identity. We don't charge for requests unless they are clearly unfounded or excessive.
If your request concerns data that an organisation put into GuardMyMark (section 2, "Processor"), we will forward it to that organisation and help it respond.
12. US state privacy notice
This section is for residents of US states with consumer privacy laws, including California.
- Categories of personal information we collect are described in section 3: identifiers (name, email, IP address), commercial information (subscription records), internet activity (product usage and analytics), and the content of your communications with us. Sources: you, your organisation, your device, Creem, Google sign-in and public business listings.
- We do not sell or share personal information (as those terms are defined in California law), and we have not done so in the past 12 months. We do not knowingly sell or share personal information of people under 16.
- We don't use sensitive personal information for purposes that would give you a right to limit it.
- Your rights: to know, access, correct and delete your personal information, and not to be discriminated against for exercising these rights. You can use an authorised agent. Contact privacy@guardmymark.com.
- Global Privacy Control and Do Not Track. We honour GPC and "Do Not Track" signals by disabling analytics for that browser. We don't track you across third-party websites.
13. Children
GuardMyMark is a business tool and is not intended for anyone under 18. We don't knowingly collect personal data from children. If you believe a child has given us personal data, email privacy@guardmymark.com and we will delete it.
14. Changes to this policy
We will update this policy when our practices change. The version and effective date are at the top. If a change materially affects how we use your personal data, we will email account owners at least 30 days before it takes effect (or ask for your consent where the law requires it).
15. Contact and complaints
GuardMyMark, Milutenka 23, Kyiv, Ukraine. Email: privacy@guardmymark.com.
If you are unhappy with how we handled your data, please contact us first. You can also complain to your local data protection authority, for example:
- in the EU, the supervisory authority of the country where you live or work (list);
- in the UK, the Information Commissioner's Office (ico.org.uk);
- in Ukraine, the Ukrainian Parliament Commissioner for Human Rights.