Security
Protection built around least access
Guardian Daily limits who can reach personal and family information, and keeps sensitive actions behind verified identity and explicit permission.
Last updated: October 1, 2026
Account and family access
Signed-in information is separated by account. Family spaces are limited to approved members, and family administrators control membership. Family roles limit who can manage membership or see role-specific information. Access rules are enforced by the backend rather than trusting what a browser says.
Identity and sessions
Private pages require a signed-in session. Account credentials are handled by Guardian's hosted sign-in service, and access checks run again when protected information is requested. Anyone with access to an unlocked, signed-in device may be able to use the account, so devices should be locked and shared-device sessions should be signed out.
Private sharing
Shared plans name who can view or edit them. Access can be revoked. Private file links expire quickly. Revoking future access cannot erase a copy someone already downloaded or information they already saw.
One-tap check-in links
A one-tap link uses a long random token. Guardian stores a cryptographic hash rather than the link token itself. The link is limited to one person's check-in, can be revoked or regenerated, is rate-limited, and exposes no other family or account data.
Approval and action boundaries
Guardian separates a prepared action from an executed action. A draft, suggestion, or approval record is not presented as proof that an email was delivered, a payment happened, an appointment changed, or a person received an alert. Connected services must prove their own result before Guardian can show it as confirmed.
Data in transit and secrets
Guardian's public and signed-in pages use encrypted web connections. Service credentials stay on the server and are not placed in public page code. Guardian does not ask members to paste passwords or private service keys into a conversation.
Data controls
Settings provides controls for reviewing, exporting, and deleting personal Guardian data, as well as reviewing saved memories and permissions. Account deletion is separate from clearing an individual category. The app reports failures rather than claiming deletion succeeded when it did not.
Latest security check
October 1, 2026 — automated backend check: no issues found. This check looks at the database and sign-in setup for exposed data, missing access rules and misconfigurations. It is an automated check run by the Guardian Daily team, not an independent audit, a penetration test or deep code analysis. We will update this section after each new check, including when something is found and fixed.
No security claim beyond the evidence
No online service can promise absolute security. Guardian Daily does not claim a certification, independent audit, penetration test, uptime promise, or security guarantee that has not been completed. Report a concern to support@guardiandaily.ai or through the contact page for human review. Do not include passwords or private keys.