PRIVACY POLICY
Your information.
Your choices.
Defend HQ is built to protect you with as little of your information as possible. This page explains, in plain English, what the Defend HQ Chrome extension, the family website (app.defendhq.app) and this website do with it.
Last updated: October 2, 2026
The short version
- Defend HQ does its protecting on your computer. Your browsing history stays there.
- When it needs outside help, it sends as little as it can, usually just a website’s name.
- Nothing about you goes to our own server unless you use a feature that needs it (the family connection, Leak watch), and each one says so. Defend HQ only asks it, every few hours, which optional features are switched on.
- We don’t sell your information, show you ads, or use trackers. This website sets no cookies.
What stays on your computer
Chrome keeps these on your computer, for Defend HQ only: your settings, your trusted contact’s name and number, the activity list (what Defend HQ stopped and when, with website names only, never full web addresses), the websites you chose to trust, and the scam-website lists.
Messages you check with “Is this a scam?”, and emails Defend HQ looks at in Gmail, Outlook, Yahoo and AOL, are checked on your computer. Their words are not sent anywhere. “Read this to me” uses a voice on your computer when it has one (Windows, Mac and Chromebooks do).
“My details online” (help with people-search websites) keeps your name, town, state and the other details you choose to add on your computer only. They are never sent to our server.
Removing Defend HQ from Chrome deletes all of it. The one exception is Leak watch: the addresses you ask it to watch are kept on our server (next section), so they can be checked while your computer is off.
When Defend HQ asks other services for help
Some checks need up-to-date information from outside. Each service below receives only what’s listed. Like any website, they also see your internet (IP) address when your computer contacts them.
Which optional features are switched on
- Who
- Defend HQ’s own server (defendhq.cloudpod.pro)
- What they get
- Nothing about you: a plain question, “which optional features are on?”. Like any website, it sees your internet (IP) address.
- When
- When Chrome starts, at most once every few hours.
Scam-website lists
- What they get
- Nothing about you. Defend HQ downloads their public lists.
- When
- About every 6 hours.
Checking an unfamiliar website
- Who
- Cloudflare’s security service (security.cloudflare-dns.com)
- What they get
- The website’s name, like example.com. The same thing your computer already sends when it looks up a website.
- When
- The first time you visit a website that isn’t on any list and isn’t a popular website. You can turn this off: Settings → “Check unfamiliar websites online”.
How old a website is
- Who
- The registry that runs the website’s address (through RDAP, the modern WHOIS), or rdap.org
- What they get
- The website’s registered name, like example.com.
- When
- When the green shield menu shows a website, when a card form appears on an unfamiliar shop, or when a download comes from an unfamiliar website. Only with online checks on.
Password check
- Who
- Have I Been Pwned (Pwned Passwords)
- What they get
- The first 5 characters of a scrambled (hashed) copy of the password. Never the password itself. The comparison happens on your computer.
- When
- Only when you press the button.
Email address check
- Who
- LeakCheck
- What they get
- A scrambled (hashed) form of the address you type in: the first 24 characters of its SHA-256. Never the address itself.
- When
- Only when you press the button.
Leak watch (Premium)
- Who
- Our server asks LeakCheck, and reads Have I Been Pwned’s public list of breaches
- What they get
- LeakCheck gets the same scrambled form of each watched address. Have I Been Pwned gets nothing about you.
- When
- Every week, and when a new breach is published — only for addresses confirmed with the code we email to them.
People-search removal (Premium)
- Who
- The people-search websites you choose to work on, like Whitepages and Spokeo
- What they get
- Only what you send them yourself: Defend HQ types your details into a website’s own form when you press “Fill in my details” on that website, and you press the website’s button to send it.
- When
- Only in a tab Defend HQ opened for you from “My details online”.
Family phone alerts and the weekly report
- Who
- ntfy (ntfy.sh, or a server you choose)
- What they get
- The alert: what happened, the website’s name, and the computer’s nickname, sent to your family’s private topic. The weekly report has counts only.
- When
- Only if you turn family alerts on.
Alert when Defend HQ is removed
- Who
- ntfy, sent by our goodbye page (defendhq.app/goodbye.html)
- What they get
- The computer’s nickname. The details travel in the part of the web address that browsers never send to our server.
- When
- Only if Defend HQ is removed while family alerts are on.
The family website and connected computers
The family website at app.defendhq.app lets family members see how the computers they look after are protected. It runs on our own server. Nothing about you is sent there unless someone starts connecting a computer or turns on Leak watch (apart from the plain “which features are on?” question above).
Leak watch
The email addresses you ask Leak watch to watch (up to 5), each confirmed with a code we email to it, are stored on our server encrypted, with the leaks found for them: the website, when it happened, and what kinds of data it included. Your family helper sees them only if you turn on “Share with my family”, and then only shortened (like p•••@example.com).
People-search progress
If you turn on “Share with my family”, your family helper also sees how far you’ve got with each people-search website: its name, whether you’re listed, asked or removed, and the dates. Never your details or your listing’s address. When you turn sharing off, our server deletes it.
Your family account
Your name, your email address, your password (stored scrambled, so nobody can read it, including us) and your family’s name. Your name is shown on the computers you connect, so the person can tell it was really you.
A connected computer
- Its nickname, the kind of computer and browser (for example, “Chrome on Windows”), the Defend HQ version, when it last checked in, and who connected it.
- A protection summary: whether protection is on, which protections are switched off, a protection score, how many things were stopped today, and whether any browser extensions need a look.
- Protection events: what Defend HQ did, when, how serious it was, the website’s name and a short explanation. An event can name a paused program, a browser extension that was flagged, or a data breach that included an email address.
Never shared: full web addresses, your browsing history, what you type, passwords, messages, or emails.
When a family member changes a protection setting or presses a button like “Check now” on the family website, the computer lists it in its own activity list, so nothing happens behind anyone’s back.
How long it’s kept
- Activity is deleted automatically after 180 days.
- Leak watch addresses and their leaks are deleted when you stop watching an address, and with the computer’s other records when it hasn’t checked in for 30 days and isn’t connected to a family.
- Connection codes stop working after 10 minutes.
- Removing a computer from the family stops all sharing straight away. Its earlier activity stays in the family’s history until it’s 180 days old.
- Deleting your account deletes it. If you were the family’s last member, the family and all its activity are deleted too.
Payments
Defend HQ doesn’t take payments yet. During early access, Premium features are included at no cost, and there’s nowhere to enter a card. When Premium goes on sale, payments will be handled by Stripe, and we’ll update this page first.
This website
defendhq.app sets no cookies and uses no analytics or advertising trackers. If you choose light or dark mode, that choice is saved in your own browser. Like most websites, our web server keeps standard logs (internet address, the page asked for, browser type) for security and to fix problems.
We don’t track you across websites, so we treat every visitor the same whether or not their browser sends “Do Not Track” or Global Privacy Control.
The family website keeps you signed in by saving a sign-in key in your browser. Signing out removes it.
Chrome’s permissions, and why Defend HQ asks
- The websites you visit: to check each page for scams and show a warning before a scam page opens. This happens on your computer; pages are not sent to us.
- Your downloads: to pause programs that could let a stranger control your computer.
- Your extensions: to spot harmful browser extensions, including new ones a scammer asks you to add.
- Notifications: to let you know when something needs your attention.
- Only if you ask: your browsing history and website settings, to find websites that send pop-up messages and turn them off. Chrome asks you first.
Your choices
- Turn online checks off in Defend HQ’s Settings: “Check unfamiliar websites online”.
- Stop watching an address in Passwords & email → Leak watch; turn sharing with your family on or off there too.
- Forget your people-search details and progress: My details online → Forget my details.
- Turn family alerts on or off in Defend HQ’s Family page.
- Disconnect a computer: on the computer (Family → Disconnect), or on the family website (Computers → Remove from family).
- Delete your family account on the family website: Account → Delete your account.
- Remove Defend HQ: type chrome://extensions in Chrome’s address bar and choose Remove. Everything on the computer is deleted.
- Ask us what we hold about you, or to delete it: support@defendhq.app.
Keeping it safe
Every connection is encrypted (HTTPS). Passwords are stored scrambled. Each connected computer has its own sign-in and can only send its own information. No security is perfect, which is why we keep what we store to a minimum.
Children
Defend HQ isn’t meant for children under 13, and family accounts are for adults.
Questions, and changes to this page
Write to us at support@defendhq.app. If we change how Defend HQ uses information, we’ll update this page and the date at the top first.

