GURDN

Documentation / Engineering

Privacy

What is stored, where, and what leaves the machine.

GURDN observes network configuration, which is sensitive by nature. The design answer is to keep it on the machine and to require nothing of you in exchange.

This page describes how the application behaves. It is not a legal privacy notice, and it does not claim compliance with any regulation. Compliance is established by assessment, not by assertion on a website.

What the application can see

  • Network interfaces, their type, status, addresses and gateways.
  • Configured resolvers, and whether they changed from what was recorded.
  • The associated wireless network, its security type, and previous associations.
  • Whether a VPN interface is present.
  • Host firewall profile state.
  • What Windows reports about a mobile broadband interface, where one exists.
  • The actions you authorised, when, and what GURDN did as a result.

It does not read the contents of your traffic. It is not a web filter, a content inspector, a keystroke logger or a parental control product, and it does not record which sites you visit.

What is stored, and where

Observations, decisions and the audit record are written under the machine's program data directory, resolved from Windows rather than assumed from an environment variable. Some columns are encrypted at rest. Retention is bounded by size and age under a documented policy, so the record does not grow without end.

What leaves the machine

Two honest categories, rather than a blanket claim.

  • Nothing, as a condition of running. No account, no sign-in, no mandatory telemetry, and no server that has to answer for observation, assessment or protection to work.
  • What you ask for, when you ask for it. A check about whether something is reachable necessarily involves a network request. Checking for an update contacts an update source. A diagnostic bundle you choose to export goes wherever you send it.

This is why the site does not say everything works offline. Local observation and assessment do. A question about whether something on the internet is reachable cannot be answered without the internet.

Diagnostics

A diagnostic export is produced on request, written locally, and transmitted nowhere automatically. Crash and diagnostic handling follows the same retention policy as the rest of the local store.

Why the architecture is the guarantee

A privacy policy is a promise about what a company will do with data it holds. An architecture with no backend has no data to hold. The second is checkable, which is why GURDN is built that way. See architecture.