Privacy Policy
Last updated: September 23, 2026 • Effective immediately
This Privacy Policy applies to DW Group LLC ("DW Group," "we," "us," or "our"), a Maryland limited liability company, and covers our websites, software tools, client portals, and Software-as-a-Service (SaaS) applications, including isUserFriendly (accessible at https://isuserfriendly.com).
We respect your privacy and are committed to protecting your personal information. This policy explains what information we collect when you visit our sites, use our software, or authenticate via third-party identity providers such as Google OAuth, how that data is used and protected, and your rights regarding your personal data.
Covered Products & Services
This Privacy Policy applies to all websites, web applications, client portals, APIs, and SaaS products owned and operated by DW Group LLC, including but not limited to:
- DW Group LLC: https://dwgroupllc.com
- is UserFriendly: https://isuserfriendly.com
- Stargazing Sites: https://stargazingsites.com
1. Introduction & Scope
This Privacy Policy governs the collection, use, retention, and disclosure of information gathered through DW Group LLC digital products and services. By accessing or using our Services, you consent to the practices described in this Privacy Policy.
2. Google OAuth & Authentication Services
Some of our SaaS products and digital platforms utilize Google Sign-In and Google OAuth 2.0 to provide seamless, secure account registration and single sign-on (SSO). When you choose to authenticate using your Google Account, we request access only to the minimal necessary scopes required to verify your identity and manage your product session.
Data Received from Google
- Basic Profile Information: Your unique Google User ID, full name, and profile avatar URL (used to identify you within the application interface).
- Primary Email Address: Used for account creation, critical system notices, transactional emails, and authentication validation.
- Authentication Tokens: Secure OAuth access and refresh tokens used solely to validate active sessions and communicate with authorized endpoints.
Google API Services User Data Policy Compliance (Limited Use)
DW Group LLC's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:
- We do not sell, rent, or trade Google user data to third parties.
- We do not allow human review of your private Google user data unless required to resolve security incidents, comply with applicable law, or when explicitly requested by you for technical troubleshooting.
3. Information We Collect
In addition to authentication data, we may collect the following categories of information:
- User-Provided Data: Form submissions, project inquiries, support requests, and billing information (processed securely through PCI-DSS compliant third-party payment gateways such as Stripe; we do not store raw credit card numbers).
- Diagnostic & Audit Inputs: Target URLs submitted for automated analysis, evaluation logs, and structured diagnostic scorecards.
- Ephemeral In-Memory Visual Processing: During automated visual audits (such as on isUserFriendly), our headless browser engine captures in-memory viewport snapshots exclusively to execute visual AI evaluation. These image buffers are held strictly in volatile RAM within edge workers (e.g., Cloudflare Workers) and are immediately discarded and garbage-collected upon audit completion. We do not save, store, sell, or retain any audited website screenshots.
- Technical & Log Data: Internet Protocol (IP) addresses, browser type, operating system, referring URLs, timestamps, and page request metadata collected automatically for security monitoring, fraud prevention, and performance diagnostics.
- Application Usage Data: Feature interactions and error traces within our SaaS applications to troubleshoot bugs and optimize user workflows.
4. How We Use Your Information
We collect and process personal information strictly for legitimate business and operational purposes, including:
- Provisioning, maintaining, and improving our software, SaaS tools, and consultancy services.
- Authenticating user credentials and verifying authorized access to protected features.
- Sending transactional communications, such as security alerts, billing invoices, system updates, and responses to support inquiries.
- Detecting, preventing, and mitigating security threats, abuse, spam, fraud, or violations of our Terms of Service.
- Complying with applicable legal and regulatory obligations.
5. Data Sharing & Infrastructure Sub-processors
We do not sell, rent, or monetize your personal information under any circumstances. We disclose data only in the following limited situations:
- Trusted Infrastructure Providers (Sub-processors): Sub-processors who host our applications and databases under strict data protection and confidentiality agreements:
- Cloudflare: Global edge network, DDoS mitigation, DNS routing, compute workers, and headless browser rendering.
- Neon Postgres & Supabase: Encrypted relational database storage and backend infrastructure.
- Google Cloud Platform: Cloud compute, identity verification (Google Sign-In), and storage infrastructure.
- Stripe: PCI-DSS Level 1 certified payment processing (we never store raw payment card data).
- Legal & Regulatory Compliance: When compelled by valid legal processes (such as court orders, subpoenas, or statutory mandates) or to defend our legal rights.
- Business Transfers: In the event of a merger, acquisition, reorganization, or sale of company assets, user data may be transferred as an operational asset subject to the protections of this Privacy Policy.
6. Data Security & Retention
We apply defensive security engineering practices to protect your data against unauthorized access, disclosure, alteration, and destruction. All data in transit is encrypted using modern TLS (Transport Layer Security) protocols, and sensitive data at rest is encrypted using industry-standard AES-256 encryption. We enforce least-privilege access controls across all infrastructure.
API Key & Secret Cryptography
For services supporting user-supplied credentials or Bring Your Own Key (BYOK) integrations, all provider API keys are encrypted at rest using authenticated AES-256-GCM encryption with unique per-key initialization vectors (IVs). Encryption keys reside exclusively in secure runtime environment secrets and are never exposed to client browsers or third-party log aggregators.
Retention & Purging Protocols
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, provide our services, maintain auditable records, and comply with statutory obligations. When an account is terminated, data is securely purged or anonymized in accordance with our deletion protocols.
7. Your Rights, Data Deletion & Revoking Google Access
You retain full control over your personal data. Depending on your jurisdiction (including the European Economic Area, United Kingdom, California, and Maryland), you may have the right to request access to your data, request corrections to inaccurate information, or request full deletion of your account and personal records.
Requesting Account & Data Deletion
To delete your account and remove all personal information collected by our SaaS applications, please send an email to privacy@dwgroupllc.com (or support@isuserfriendly.com) with the subject line "Data Deletion Request". We process verified requests within 30 days.
Revoking Google Account Access
You may revoke DW Group LLC's access to your Google Account at any time directly through Google's Account Permissions Manager.
8. Cookies & Client Storage Policy
Under the European Union ePrivacy Directive (Directive 2002/58/EC as amended) and GDPR (Regulation (EU) 2016/679), consent banners are mandatory strictly for non-essential tracking technologies. DW Group LLC platforms exclusively utilize strictly necessary cookies and functional local storage required to provide the services requested by the user:
| Identifier / Key | Mechanism | Duration | Classification & Purpose |
|---|---|---|---|
| Authentication Session | HTTP-Only Cookie | Session / 30 Days | Strictly Necessary: Authenticates active user session and protects against CSRF. |
| UI & Hydration Cache | HTML5 localStorage |
Persistent / Session | Strictly Necessary: Prevents UI layout shift and provides zero-flash hydration. |
| Audit / Report Cache | HTML5 localStorage |
Local Storage | Functional: Stores recent diagnostic reports locally in browser memory for instant retrieval. |
Security Tokens (__cf_bm, cf_clearance) |
First-Party Cookie | Up to 30 min | Strictly Necessary: Cloudflare edge bot protection, rate-limit defense, and DDoS mitigation. |
Because we operate zero third-party advertising trackers (no Meta Pixel, TikTok, or Google Ads tags), zero cross-site profiling beacons, and zero data-broker synchronization, an intrusive cookie consent banner is neither legally required nor displayed on our platforms.
9. Children's Privacy
Our websites, software, and services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If we become aware that a child under 16 has provided us with personal information without parental consent, we will promptly delete such information.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect modifications in our services, technical infrastructure, or legal obligations. We will notify users of material modifications by updating the "Last Updated" date at the top of this page. We encourage you to periodically review this page.
11. Data Processing Addendum (DPA) Terms
For enterprise customers subject to the European General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA/CPRA), this section outlines our standard technical processing terms:
- Data Controller: Customer submitting URLs, user accounts, or proprietary credentials.
- Data Processor: DW Group LLC.
- Authorized Sub-processors: Cloudflare (Edge compute & Browser Rendering), Neon Postgres / Supabase (Encrypted Relational Storage), Stripe (Payments).
- Data Locations: Multi-region edge locations within the United States and European Union.
- Security Controls: TLS 1.3 encryption in transit, authenticated AES-256-GCM encryption at rest, strict role-based access control (RBAC), and principle of least privilege.
12. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
DW Group LLC
State of Maryland, United States
Email: privacy@dwgroupllc.com
Website: https://dwgroupllc.com