Last updated: 14 August 2026

This policy explains what DecoyNest does with data. It covers three separate things: this website, the DecoyNest WordPress plugin, and the services the plugin talks to. They collect different things, and the differences matter.

Who we are

DecoyNest is operated by MB G4T, registered in Lithuania.

Contact for anything in this policy: privacy@decoynest.com

This website

decoynest.com runs on WordPress with a theme we wrote ourselves. It loads no analytics, no advertising scripts, no tracking pixels, and no third-party fonts or assets. Nothing about your visit is sent to anyone else.

The only cookies set are the ones WordPress needs to keep you logged in if you have an account here. There is no cookie consent banner because there is nothing to consent to. If we add analytics later, this section will change before that happens, not after.

Our web server keeps standard access logs (IP address, page requested, timestamp, user agent) for security and troubleshooting. These are deleted after 30 days.

The plugin: what stays on your site

By default, everything the plugin records stays in your own WordPress database, on your own server. We have no access to it.

That includes honeypot events (attacker IP, user agent, request path, payload with credentials stripped, and a classification), the admin audit log, hardening scan results, and your firewall rules.

You control retention for this data in the plugin’s own settings, and deleting the plugin removes it.

The plugin: what is sent to us

Licence verification — paid tiers only

If you hold a paid licence, the plugin verifies it with us. Each check sends your licence key, your site URL, a random installation identifier generated on your site, and the plugin version. We store only a SHA-256 hash of the key, never the key itself.

Checks are cached for 24 hours, so this is not happening on every page load. Free installations never make this request.

Vulnerability scanning

To tell you whether your software has known vulnerabilities, we need to know what you are running. The plugin sends the name and version number of your WordPress core, plugins, and themes.

It does not send your content, your files, your database, your users, or anything about your visitors.

Threat intelligence sharing — opt-in, off by default

You can choose to contribute anonymised attack data to help improve detection for everyone. If, and only if, you switch this on, the plugin shares: the attacking IP address, the user agent string, the attack category, which decoy was triggered, and the timestamp.

It does not share your site’s content, your users, your files, or data about legitimate visitors. You can switch it off at any time and the plugin works identically without it.

Attacker IP addresses

An IP address is personal data under GDPR even when it belongs to someone attacking a website. We collect them because identifying attack sources is the entire function of the product, and because seeing the same infrastructure across many sites is what makes the detection useful.

We do not attempt to identify the individual behind an attacking IP address, and we do not sell or share this data with advertisers or data brokers.

Legal basis

  • Data on your own site — you are the controller. Your own privacy policy governs it, not this one.
  • Licence verification and vulnerability scanning — necessary to provide the service you asked for (GDPR Art. 6(1)(b)).
  • Threat intelligence sharing — your explicit consent (Art. 6(1)(a)), withdrawable at any time.
  • Our own server logs and fraud prevention — legitimate interest (Art. 6(1)(f)).

How long we keep things

  • Shared attack data — IP-level records for up to 24 months, after which they are deleted. Only anonymised aggregate statistics, which cannot be traced back to an IP address or a site, are kept beyond that.
  • Licence records — for the life of the licence plus the period we are required to keep accounting records.
  • Scan inventories — the most recent scan per site, replaced each time you scan.
  • Website server logs — 30 days.

Backups and Sentinel

Neither feature sends your data to us.

Backups are encrypted on your server before they go anywhere, and are stored either on that server or in your own Google Drive, OneDrive or Dropbox account. We do not operate backup storage and never hold your archives.

The Microsoft Sentinel integration sends events directly from your site to your own Azure workspace. We are not in that path.

Your rights

Under GDPR you may request access to your data, correction of it, erasure, restriction of or objection to processing, and portability. You may withdraw consent at any time without affecting processing that already happened lawfully.

Email privacy@decoynest.com and we will respond within 30 days. If you are unhappy with how we handle it, you can complain to your local data protection authority — in Lithuania that is the State Data Protection Inspectorate.

Who else processes data

We do not sell data. We use ordinary infrastructure providers for hosting and email delivery, who process data on our behalf under their own agreements. A current list is available on request.

Vulnerability data is matched against publicly available vulnerability databases. Your inventory is not disclosed to them.

Children

This is a tool for people who administer websites. It is not directed at children and we do not knowingly collect data from anyone under 16.

Changes

If we change this policy we will update the date at the top. For changes that affect what we collect or why, we will say so in the plugin’s admin screen or by email to licence holders, before the change takes effect.

Contact

MB G4T, Lithuania
privacy@decoynest.com