Product data · Updated

Data and privacy in JiggleGuard

What the JiggleGuard agent reads on a work computer, what it sends to the console, how long it's kept and who can see it. This describes the current Windows beta, and we'll update it when the product changes.

What the agent reads and what it sends

This is limited activity monitoring: enough to judge whether input looks machine-generated, without recording the content of anyone's work.

SignalRead on the computerSent to the consoleWhy
Pointer position and movementPosition, timing and whether the input was injected, in a rolling ten-minute windowA numeric behaviour summary at each regular report (every five minutes by default); the movement trace for a flagged time windowSpot machine-like movement
Clicks and scrollingType and timing of each click or scrollCounts in the regular summary; the click events for a flagged time windowCheck whether movement leads anywhere
KeyboardKey codes and timing, needed to spot a single key pressed on a steady beatPress counts and timing statistics. In the current beta, also the five most frequently pressed key codes in each reporting window. Never typed text or the order of keysCheck whether typing goes with mouse movement
Connected mice and keyboardsVendor and product IDs, manufacturer and product names, serial numbersDevice details for a flagged time windowRecognise known jiggler hardware
Running appsProcess names, checked on the device against known jiggler and keep-awake toolsYes or no only. No app namesRecognise known tools
Keep-awake, remote-session and accessibility stateWhether the system is being kept awake, and whether a remote session or assistive technology is activeYes or no onlyAdd weight to other signals; avoid flagging legitimate injected input
Foreground app changesWhich app is in front, as an internal reference rather than its name or window titleA count of changes onlySee whether the computer is in active use
The computerAgent ID, hostname and agent versionThe same, when the agent registersIdentify the computer in your console

On the computer, raw input is held only in the rolling ten-minute window. If the console can't be reached, reports wait in a local queue capped at 10 MB and are sent when the connection returns.

How long it's kept

  • Flags, reports, movement traces and findings: 90 days by default, then deleted. The period is currently set for the whole service; per-organisation settings are planned.
  • Detailed behaviour summaries: 14 days.
  • Backups: encrypted daily backups are kept for 7 days, so deleted data can remain in a backup until it expires.
  • Enrolled computers and their known devices: not yet deleted automatically. Ask us and we'll remove them.

Who can see it

Access to the console is role-based. Within an organisation, viewers and organisation administrators can see that organisation's computers and flags. Managed service providers have MSP administrators who manage several client organisations. JiggleGuard's own administrators can access the service to run and support it.

Data is encrypted in transit and stored on an encrypted volume. To report a security issue, see contact.

What your organisation is responsible for

Your organisation decides whether to use JiggleGuard, on which computers and for what purpose. Under UK GDPR and the ICO's guidance on monitoring workers, that means having a lawful basis, being able to show the monitoring is necessary and proportionate, telling staff what is monitored and why, and carrying out a data protection impact assessment where the monitoring is likely to be high risk.

A product that collects less data can make that easier, but it can't make monitoring compliant on its own. This page is general information, not legal advice.

This page covers the product. For the JiggleGuard website itself, see website privacy and cookies.

Try it in the Windows beta

We're inviting a small number of organisations to the private beta. Join the list for an invitation, or ask us a question first.