BirdGuard for Windows 11
Privacy under your control
A security tool sees almost everything that happens on your computer. Here is exactly what BirdGuard does with it.
Everything stays on your computer
Checks, monitoring and history run and are stored locally. There is no account, no BirdGuard server, no telemetry and no error reports sent to the author.
Only what is listed leaves the computer
Mostly it is just downloading public lists, during which nothing about you is transmitted. Data about you leaves only on your explicit action: an AI query, or a password, e-mail or file check.
AI is off until you turn it on
It needs your own API key (Claude). It receives anonymised text, and everything sent can be read in the app. The text sent is processed by Anthropic under its API terms, which BirdGuard cannot influence.
You see the content before it is sent
The user and computer name, e-mails, Wi-Fi network names, MAC addresses, serial numbers, private IP addresses and your own custom words are replaced in the text. Passwords, tokens and keys are replaced irreversibly. The “What was sent to AI” overview shows the exact wording of every query.
What never goes to AI
File contents, names of sensitive files (only their counts and kinds), server names from connections, the data volume of connections, passwords and API keys.
Breach checks without giving anything away
A password is never sent: only the first 5 characters of its SHA-1 hash are used for the comparison. For a file on VirusTotal only the SHA-256 hash is sent, never the file.
API keys in the Windows store
Keys (Claude, Have I Been Pwned, VirusTotal) are kept in Windows Credential Manager, never in a file or a log.
Your approval, your control
Fixes come from a fixed catalogue; BirdGuard does not run arbitrary scripts or commands. They are applied only after approval and the original state is stored so you can undo a change.
What leaves the computer
The same list is in the app under Settings → App privacy. Windows itself continues to use the network (Windows Update, program signature checks).
| Where | When | What is sent |
|---|---|---|
| feodotracker.abuse.ch, www.spamhaus.org | every 12 hours | Nothing, only a list of malicious addresses is downloaded. Which hosts your computer connects to is compared locally. |
| standards-oui.ieee.org | once a month | Nothing, only the table of network card manufacturers is downloaded. |
| raw.githubusercontent.com (LOLDrivers) | once a day | Nothing, only hashes of vulnerable drivers are downloaded. The hashes of your drivers are compared locally. |
| cdn.winget.microsoft.com | when checking for app updates | A Windows Package Manager request for the catalogue. |
| updates.birdguard.cz | only when you click “Check for program updates” and have no source files | Nothing about you. A signed list of versions (latest.json, latest.json.sig) and possibly a package are downloaded. The server sees your IP address and the web server does not write access logs. |
| api.anthropic.com | only with AI turned on, when you ask | Anonymised text. |
| api.pwnedpasswords.com | when you enter a password to check | The first 5 characters of the SHA-1 hash, not the password or the whole hash. |
| haveibeenpwned.com | when you enter an e-mail and have their API key | That e-mail and your key. |
| www.virustotal.com | when you click “Verify on VirusTotal” | The SHA-256 hash of the file and your key, not the file itself. |
Downloaded lists can be verified only by the encrypted connection; their publishers do not sign them.
What is stored and for how long
All data stays on your computer. Only administrators and the BirdGuard service can access it.
| What | What it contains | How long |
|---|---|---|
| Check results | findings with details and the score | a limited number of recent checks |
| Events | system changes, suspicious launches, camera and microphone use | a limited number of recent events |
| Fix journal | what BirdGuard changed and the original values for “Undo” | unlimited, otherwise fixes could not be undone |
| AI agent sessions | programs launched, files changed and read, connections, rules broken | a limited number of recent sessions |
| Load history (Performance) | the most demanding programs in five-minute windows, without command lines; can be turned off and deleted | two weeks |
| What was sent to AI | the exact text of queries and answers | a limited number of recent ones, can be cleared |
Memory only, never on disk: server names from DNS queries (about 10 minutes), the password and e-mail during a breach check (for a single query only), connections just made and their data volume, and the table of running processes.
What BirdGuard does not do
- It does not send anywhere what is installed on the computer, which programs run or who they connect to.
- It does not watch the screen content, key presses, the clipboard or browser history.
- It does not read file contents, with one exception: the sensitive-file check scans the Desktop, Documents and Downloads for private keys, passwords and card numbers. Only the file name and the kind of finding are stored.
- It has no advertising, no usage statistics and no automatic crash reports.
- It does not update itself. On its own it only downloads data (address lists, the manufacturer table); it does not download or install a new BirdGuard version or an update of another app via winget until you click. A package from updates.birdguard.cz is verified with the BirdGuard key signature and SHA-256 before installation.
Export and deletion
- Export: History → Export report saves an overview as HTML to the Documents folder.
- You delete the AI record with the button on the “What was sent to AI” page.
- Deleting everything: uninstalling with the delete-data option removes the service, the data and the stored keys.
- Individual events and checks cannot be deleted; older records disappear on their own according to the limits.
This page describes the BirdGuard app. The processing of data on this website is described in the website privacy policy (Czech). More answers are in the FAQ.
