Guardshore runs on your Mac. It requires no account and contains no telemetry or analytics. It never uploads browsing hostnames, screen images, classifier inputs, custom blocklist entries, or diagnostic data.
Guardshore may download a static, cryptographically signed blocklist update. That request necessarily exposes ordinary network metadata such as the requesting IP address to the file host, but its request contains no device identifier or user data. The app verifies the update against its embedded keyring before sending resolved policy to the authenticated system extension.
Screen frames are processed in memory by an on-device CoreML model. Guardshore does not save or transmit frames. Production logging excludes hostnames, URLs, frame content, classifier inputs, and user additions. Apple or macOS may independently produce operating-system crash reports according to the user’s system settings; Guardshore does not add sensitive payloads to them or operate its own crash-reporting service.
Custom additions and provider last-known-good policy state are encrypted at rest with keys stored in the macOS Keychain. Encryption protects local confidentiality; it does not make Guardshore tamper-proof. A Mac administrator can disable or uninstall the product.
A wrongly blocked-site report is composed only after the user presses the report control. The user can inspect, edit, copy, or send it with their mail application. Guardshore does not send the report itself.