Last updated 7 September 2026
Ward tells you who can reach your accounts and what to do about it. To do that it handles a small amount of data about you. This page says exactly what, why, and for how long.
The short version. Your email addresses are encrypted on our servers and are only ever decrypted to check them against breach records. Device checks run on your phone and never leave it. We do not use advertising identifiers, we do not track you across apps, and we do not sell anything to anyone. You can delete everything from inside the app in one tap.
The data controller for Ward is:
Sheriff Security AG
c/o Maryna Stryzhova, Brunngasse 66, 4153 Reinach, Switzerland
D-U-N-S® Number: 487350682
We process personal data under the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Swiss Federal Act on Data Protection (“FADP”).
When you ask Ward to check or watch an email address, that address is stored on our servers encrypted with AES-256-GCM. It is decrypted only inside the scheduled job that queries breach records, and it is never shown to us in a readable list.
We also store a keyed hash of the address so we can recognise duplicates without decrypting anything, and a masked form (a•••••v@example.com) so the app can show you which address is which.
Ward checks your iPhone for signs of tampering, whether a passcode is set, and whether your iOS version is missing published security fixes. These checks run entirely on your device. The contents of your phone are never transmitted. Only the outcome — for example “iOS is three releases behind” — is stored so your protection score survives a restart.
The seven access questions are answered by you, not measured by us. Your answers are stored so the app can show progress and so it survives reinstalling.
If you allow notifications, we store the push token for your device together with its iOS version. The version is needed to tell you when an update fixes something you are exposed to — and to avoid sending that message to a device that is already up to date.
When you use the scam-message or link check, the text or address you submit is sent to our server and, for message checks, to our AI provider for analysis. We do not store the text of your messages. Links are stored only as an irreversible hash, never as readable addresses. The AI provider retains submitted text for up to 30 days for abuse prevention (see section 4).
Password checking uses k-anonymity: only the first five characters of a SHA-1 hash of your password ever leave the device. Your password itself, and its full hash, never do. This is not personal data and it cannot be reversed to your password.
We collect anonymous usage events — which screens were opened, whether a check succeeded, where people stop during setup — and automatic crash reports. These never contain your email address, message text, link addresses, breach names, Wi-Fi network names, or any other identifying content. Numbers are recorded in ranges rather than exactly. Our analytics provider derives an approximate city from the IP address of the request.
Purchases are processed by Apple. We never see your payment details. Apple sends us a signed notification of your subscription status, which we store to know whether your subscription is active.
We use a small number of processors. Each one is bound by a data processing agreement, and each sees only what it needs.
Google (Firebase)
Encrypted email addresses, account identifier, anonymous analytics, crash reports, notification tokens. Database and server functions run in the EU (Frankfurt).
Have I Been Pwned — Superlative Enterprises Pty Ltd, Australia
Your email address in readable form, in order to search breach records.
Anthropic, United States
The text of messages you submit for scam checking.
Apple
Payment details and notification delivery, under Apple’s own policy.
Please read this one carefully. Checking whether an address appears in a breach requires sending that address to the breach database. On our current plan the search is not anonymised, which means Have I Been Pwned receives your email address in readable form. We would rather tell you this plainly than bury it. If that is not acceptable to you, do not add addresses to monitoring — every other part of Ward works without them.
The text you submit for message checking is retained by Anthropic for up to 30 days for abuse prevention and is not used to train their models. Content flagged by their automated safety systems may be kept for up to two years.
Deleting the app does not delete your data from our servers. Use Profile → Delete account inside the app, or write to us.
Our database and server functions run in the European Union. Two processors are outside it: Have I Been Pwned (Australia) and Anthropic (United States). Both transfers rely on the Standard Contractual Clauses adopted by the European Commission, supplemented as required for Switzerland and the United Kingdom.
Under the GDPR and FADP you have the right to:
Write to ward@sheriff.com.ua and we will answer within 30 days. You also have the right to complain to a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, the authority where you live.
Ward is not intended for people under 16, and we do not knowingly collect their data. If you believe a child has provided us with personal data, write to us and we will delete it.
Email addresses are encrypted at rest with AES-256-GCM under a key held only by the scheduled monitoring job. Access to your data is enforced by database rules that scope every read to your own account. Traffic between the app and our servers is encrypted in transit, and requests are attested so that data cannot be requested by anything other than a genuine copy of Ward.
No system is perfect. If we ever discover a breach affecting your data, we will notify you and the relevant authority as required by law.
If we change this policy in a way that affects you, we will say so in the app before the change takes effect. The date at the top always reflects the current version.
Sheriff Security AG
c/o Maryna Stryzhova, Brunngasse 66, 4153 Reinach, Switzerland