Skip to content

BirdGuard for Windows 11

Privacy under your control

A security tool sees almost everything that happens on your computer. Here is exactly what BirdGuard does with it.

Everything stays on your computer

Checks, monitoring and history run and are stored locally. There is no account, no BirdGuard server, no telemetry and no error reports sent to the author.

Only what is listed leaves the computer

Mostly it is just downloading public lists, during which nothing about you is transmitted. Data about you leaves only on your explicit action: an AI query, or a password, e-mail or file check.

AI is off until you turn it on

It needs your own API key (Claude). It receives anonymised text, and everything sent can be read in the app. The text sent is processed by Anthropic under its API terms, which BirdGuard cannot influence.

You see the content before it is sent

The user and computer name, e-mails, Wi-Fi network names, MAC addresses, serial numbers, private IP addresses and your own custom words are replaced in the text. Passwords, tokens and keys are replaced irreversibly. The “What was sent to AI” overview shows the exact wording of every query.

What never goes to AI

File contents, names of sensitive files (only their counts and kinds), server names from connections, the data volume of connections, passwords and API keys.

Breach checks without giving anything away

A password is never sent: only the first 5 characters of its SHA-1 hash are used for the comparison. For a file on VirusTotal only the SHA-256 hash is sent, never the file.

API keys in the Windows store

Keys (Claude, Have I Been Pwned, VirusTotal) are kept in Windows Credential Manager, never in a file or a log.

Your approval, your control

Fixes come from a fixed catalogue; BirdGuard does not run arbitrary scripts or commands. They are applied only after approval and the original state is stored so you can undo a change.

What leaves the computer

The same list is in the app under Settings → App privacy. Windows itself continues to use the network (Windows Update, program signature checks).

WhereWhenWhat is sent
feodotracker.abuse.ch, www.spamhaus.orgevery 12 hoursNothing, only a list of malicious addresses is downloaded. Which hosts your computer connects to is compared locally.
standards-oui.ieee.orgonce a monthNothing, only the table of network card manufacturers is downloaded.
raw.githubusercontent.com (LOLDrivers)once a dayNothing, only hashes of vulnerable drivers are downloaded. The hashes of your drivers are compared locally.
cdn.winget.microsoft.comwhen checking for app updatesA Windows Package Manager request for the catalogue.
updates.birdguard.czonly when you click “Check for program updates” and have no source filesNothing about you. A signed list of versions (latest.json, latest.json.sig) and possibly a package are downloaded. The server sees your IP address and the web server does not write access logs.
api.anthropic.comonly with AI turned on, when you askAnonymised text.
api.pwnedpasswords.comwhen you enter a password to checkThe first 5 characters of the SHA-1 hash, not the password or the whole hash.
haveibeenpwned.comwhen you enter an e-mail and have their API keyThat e-mail and your key.
www.virustotal.comwhen you click “Verify on VirusTotal”The SHA-256 hash of the file and your key, not the file itself.

Downloaded lists can be verified only by the encrypted connection; their publishers do not sign them.

What is stored and for how long

All data stays on your computer. Only administrators and the BirdGuard service can access it.

WhatWhat it containsHow long
Check resultsfindings with details and the scorea limited number of recent checks
Eventssystem changes, suspicious launches, camera and microphone usea limited number of recent events
Fix journalwhat BirdGuard changed and the original values for “Undo”unlimited, otherwise fixes could not be undone
AI agent sessionsprograms launched, files changed and read, connections, rules brokena limited number of recent sessions
Load history (Performance)the most demanding programs in five-minute windows, without command lines; can be turned off and deletedtwo weeks
What was sent to AIthe exact text of queries and answersa limited number of recent ones, can be cleared

Memory only, never on disk: server names from DNS queries (about 10 minutes), the password and e-mail during a breach check (for a single query only), connections just made and their data volume, and the table of running processes.

What BirdGuard does not do

  • It does not send anywhere what is installed on the computer, which programs run or who they connect to.
  • It does not watch the screen content, key presses, the clipboard or browser history.
  • It does not read file contents, with one exception: the sensitive-file check scans the Desktop, Documents and Downloads for private keys, passwords and card numbers. Only the file name and the kind of finding are stored.
  • It has no advertising, no usage statistics and no automatic crash reports.
  • It does not update itself. On its own it only downloads data (address lists, the manufacturer table); it does not download or install a new BirdGuard version or an update of another app via winget until you click. A package from updates.birdguard.cz is verified with the BirdGuard key signature and SHA-256 before installation.

Export and deletion

  • Export: History → Export report saves an overview as HTML to the Documents folder.
  • You delete the AI record with the button on the “What was sent to AI” page.
  • Deleting everything: uninstalling with the delete-data option removes the service, the data and the stored keys.
  • Individual events and checks cannot be deleted; older records disappear on their own according to the limits.

This page describes the BirdGuard app. The processing of data on this website is described in the website privacy policy (Czech). More answers are in the FAQ.