Gozuh
About Privacy Support

Privacy Policy

Last updated: June 30, 2026

1. General information

This Privacy Policy explains what data is processed when you use Gozuh. Gozuh is a completely free iOS client for viewing information from a Wazuh environment that you configure yourself.

Gozuh is not a cloud service. The developer does not operate a backend that receives your Wazuh data, credentials, tokens, alerts, hosts, inventory, vulnerabilities, or configuration.

2. Gozuh app data

The Gozuh iOS app does not send your Wazuh data, credentials, tokens, alerts, hosts, vulnerabilities, inventory, or configuration to the developer. These data are processed locally on your device and are transmitted only to the Wazuh Manager API and Wazuh Indexer API endpoints that you configure.

3. Network access

The app requires network access so it can connect to the Wazuh endpoints you enter in Settings. Depending on your configuration, this may involve server URLs, hostnames, IP addresses, usernames, passwords, API responses, and JWT tokens used by your Wazuh environment.

This communication takes place between your device and your configured Wazuh services. Gozuh does not route this traffic through a Gozuh-operated server and does not transmit this information to the developer.

4. Local storage of credentials and tokens

Wazuh usernames, passwords, and manager JWT tokens are stored locally in the iOS Keychain. The Keychain is the Apple-provided secure storage mechanism for sensitive app data.

Non-secret preferences, such as configured server URLs, connection mode, and default time range, may be stored in UserDefaults. These preferences are used only to restore the app configuration on your device.

5. Biometric Lock

Gozuh includes an optional Biometric Lock that can and should be enabled in the app settings. When enabled, Gozuh locks after entering the background and asks you to unlock it with Face ID, Touch ID, Optic ID, or the authentication method available on your device.

Biometric verification is handled locally by iOS through Apple's LocalAuthentication framework. Gozuh does not receive your raw biometric data, does not store biometric templates, and does not send biometric information to the developer.

6. App analytics, tracking, and crash reporting

Gozuh does not include analytics SDKs, advertising SDKs, crash-reporting SDKs, tracking SDKs, CloudKit, or third-party telemetry. The app does not create automatic crash reports for the developer and does not perform session recording.

7. Support communications

If you contact support, the developer may process your email address, message content, app version, iOS version, and any information you voluntarily include. This data is used only to respond to your request, troubleshoot issues, protect legal claims, and improve documentation.

Please do not send passwords, tokens, private hostnames, customer data, alert payloads, screenshots containing secrets, or other confidential information.

8. Website logs

When you visit gozuh.com, the hosting provider may process technical logs such as IP address, browser user-agent, requested URL, date and time, and error logs. These logs are used for security, abuse prevention, diagnostics, and maintaining the website.

9. Cookies and analytics

This website does not use advertising cookies, tracking cookies, analytics SDKs, or marketing pixels. If this changes, this policy will be updated and, where required, cookie consent will be requested.

10. Legal bases for processing

Support communications are processed to respond to your request and, where applicable, to take steps before entering into a contract or to perform a support-related request.

Website logs are processed based on the developer's legitimate interest in security, abuse prevention, diagnostics, and maintaining the website.

Legal claim-related retention is processed based on the developer's legitimate interest in establishing, exercising, or defending legal claims.

11. Third-party websites

The app and website may link to external websites such as the Gozuh website, Wazuh, the App Store, or support pages. Opening those links is optional. External websites are controlled by their respective owners and may have their own privacy practices.

12. Security

Gozuh is designed as a read-focused client and avoids destructive actions such as deleting, restarting, or upgrading agents. Sensitive credentials are stored in the iOS Keychain, and network requests are made directly to the endpoints you configure.

You remain responsible for securing your own Wazuh infrastructure, API users, certificates, network access, device, and credentials. Use HTTPS for non-local endpoints and grant only the permissions needed to read the data you want to view in the app. You should also enable Biometric Lock in Gozuh Settings when your device supports it.

13. Terms of Use / EULA

Use of Gozuh is also governed by the Terms of Use / EULA.

14. Retention

Support emails are kept for up to 24 months after the last contact, unless longer retention is required to establish, exercise, or defend legal claims. Website server logs are kept for up to 90 days unless longer retention is necessary for security or legal reasons.

Data saved by the Gozuh iOS app is stored on your own device and can be removed by clearing the app configuration or deleting the app.

15. Your rights

Where GDPR applies, you may request access, correction, deletion, restriction, objection, and portability of your personal data. You may also lodge a complaint with your local data protection authority. In Poland, this is the President of the Personal Data Protection Office (UODO).

16. Changes to this policy

This Privacy Policy may be updated when the app changes. The latest version will be published on this page.

17. Contact

For privacy questions, contact support@gozuh.com or use the support page: Gozuh Support.

Home About Support Privacy Policy Terms of Use / EULA Legal Notice