Privacy Notice
SuperWatchDog and Super Recovery are local tools for Windows PCs. This notice explains how the website, installers, and Windows clients handle data related to you.
Scope
This notice applies to the shared SuperWatchDog and Super Recovery website and to each product's installer and Windows client. We will update it if related services or data-handling practices change.
What We Do Not Collect
- We do not upload your files, file lists, recovered results, preview content, vault contents, passwords, recovery keys, or personal documents.
- We do not save plaintext BitLocker passwords or store your recovery materials for you.
- We do not upload camera frames, screen captures, window contents, or local file path lists.
- The website does not embed third-party analytics, advertising scripts, tracking scripts, or remote fonts.
Local Processing
Vault operations, trusted device state, and protection actions are processed on your Windows PC. Basic protection features do not depend on a remote account or cloud service.
Super Recovery reads only the disk or image you select and saves attempted recovery content to the destination you choose. Discovered names, paths, sector data, file contents, and preview content are not sent to the website or licensing service. Recovered results are written to disk only after you explicitly confirm.
Local Logs and Diagnostics
The software may write essential local status, error, and diagnostic logs. After an unexpected exit, it may also save an error code, app version, redacted logs, and a limited number of small crash dumps locally.
A diagnostic report is sent or exported only after you confirm. Small crash dumps are excluded by default and require a separate selection; a dump may contain a small amount of memory near the failing thread. Reports do not collect vault contents, file lists, passwords, recovery keys, camera frames, screenshots, or window contents.
Website Analytics
The official website uses first-party anonymous analytics to measure page views, raw visitors, browser-confirmed activity, candidate visitors, installer-button clicks, popular pages, first-visit sources, campaigns, landing pages, browser and device categories, interface language, and country- or province-level geography. The website sets a random first-party identifier containing no identity, account, device, or IP information, and the server stores only its hash. Browser and device categories are derived from browser information. Sources are retained only as categories such as direct, search engine, GitHub, or a supported content platform. Campaign reporting stores only controlled utm_source and utm_campaign markers from the URL; full referring URLs and other query parameters are not stored. The browser may keep those two controlled markers for the current session so page views and download entry points in the same visit can use the same attribution. After a page has been visible in the foreground for at least 10 seconds, or after a click, key press, touch, or scroll, the website sends one browser-activity confirmation for the same anonymous identifier. The confirmation stores only the public page path, receipt time, and identifier hash; it does not store the specific ordinary interaction type, content, coordinates, or key. When you click an installer download button on this site, a separate download-intent event stores the public page path, receipt time, and the same identifier hash so an intent can be distinguished from an actual transfer start; click coordinates and page input are not stored. Browser-confirmed activity, or at least two page views on the same Beijing calendar day, is used only to derive a candidate visitor and does not confirm a human identity. Operational classification does not delete or rewrite raw visitor and page-view records within the same data baseline; anonymous operations data may be cleared under disclosed retention or system-maintenance policies without affecting diagnostic reports. The request IP is converted locally on the server into country- and province-level geography and then discarded. Raw IP addresses, cities, and precise locations are not written to the operations database. Recognized crawlers are excluded from website visitors and page views. Analytics failures do not affect website use, and no third-party analytics, advertising, or tracking service is used.
Downloads and Updates
The website may provide installer download links. The download endpoint reuses or sets the same type of first-party random identifier containing no identity, account, device, or IP information. It distinguishes download starts, completed transfers, and repeated requests by browser, Beijing calendar day, version, and channel, and links first-visit source, campaign, and landing page to download conversion; only a hash of the identifier is stored, and it is not used to identify a person. A download is counted as completed only after the installer has been fully transferred, while interrupted or cancelled transfers are excluded. English pages use an external GitHub Release mirror. The website can record the download start but cannot confirm whether an off-site transfer finishes, so it is not counted as a completed download. Entry-request counts are retained only for traffic and fault diagnostics. Recognized search crawlers are excluded from unique download starts and completed downloads. Your language choice is stored only in the current browser. Updates verify the installer before it runs, and the website does not embed third-party analytics, advertising, or tracking scripts.
Timed Pro License Connection
Free and permanent licenses do not need an online license-term check. A timed Pro license periodically uses an encrypted connection to confirm that its term remains valid. The request does not send a device identity, license ID, vault information, device list, or usage statistics.
Anonymous Usage Statistics
The software may send a random installation identifier, app version, release channel, Windows version and build, system architecture, interface language, and app-start record to measure first starts, start-based activity, retention, and version or system distribution. When an installer is downloaded or an app-start record is submitted, the server locally converts the request IP into country- and province-level geography for aggregate download and first-start reporting. A first start means the server observed an identifier's app-start record for the first time; it does not confirm installation success. Raw IP addresses, cities, and precise locations are not written to the operations database. The identifier is not derived from hardware or a Windows account, and no vault information, device list, file path, or camera frame is included. Data is sent only through encrypted connections, and failure does not affect product features.
Your Responsibility
Keep your vault files, BitLocker password, and recovery materials safe. If you forget the password and lose recovery materials, vault contents may be unrecoverable. SuperWatchDog does not save plaintext BitLocker passwords and cannot decrypt a vault for you.
Contact
For privacy questions, contact support@superwatchdog.me.
SuperWatchDog