Privacy Policy

Last updated: August 28, 2026

tunnels.io ("tunnels.io", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

1. Information We Collect

Account Information

When you create an account, we collect your email address, name, and password (stored as a secure hash). If you subscribe to a paid plan, we collect billing information through our payment processor (Stripe). We do not store credit card numbers on our servers.

Usage Data

We automatically collect information about how you use our services, including:

  • Tunnel connections (creation time, duration, protocol, bandwidth usage)
  • API requests (endpoints accessed, request counts, response times)
  • Login activity (timestamps, IP addresses, user agent)
  • Feature usage (pages visited, actions taken)

Device and Browser Information

We collect your IP address, browser type, operating system, and device information when you access our services. This information is used for security, analytics, and to improve your experience.

Tunnel Metadata

When you create and use tunnels, we collect and store metadata about your tunnel activity, including:

  • Your IP address at the time of tunnel creation
  • Tunnel URLs, protocols, and port configurations
  • Connection timestamps (start, end, duration)
  • Bandwidth usage (bytes transferred in and out)
  • Request counts and error rates

We do not inspect, monitor, or store the content of traffic passing through your tunnels. We never record request or response bodies, cookies, or authorization headers. We do record request metadata, described in the next section, and we retain tunnel metadata for security purposes, abuse investigation, plan enforcement, and compliance with legal obligations.

Tunnel Visitor Data

This section is about people who are not our users. When somebody visits a tunnel that one of our customers has opened, we record a small amount of information about that request. Those visitors have no account with us and have not agreed to these terms, so we set out exactly what is kept and for how long.

For each HTTP request that crosses a tunnel, we record:

  • The visitor's IP address
  • The date and time of the request, and how long it took
  • The request method and path, for example GET /login.html
  • The hostname requested, and the tunnel that served it
  • The response status code, and the number of bytes transferred
  • The User-Agent and Referer headers

We do not record any other header, and we do not record request or response bodies. There is no field in our systems for cookies or authorization headers, so they cannot be stored even by mistake.

We do not record the query string. Everything after the ? in a URL is discarded before the record leaves our tunnel server, because an application can put a session token or a password-reset link in there and we do not want to hold one.

There is one exception, and it is narrow. When we are investigating abuse on a specific account, an administrator can switch query-string recording on for that one account. It is off for every account by default, it can only be enabled for a fixed period of 24 hours or 7 days, it expires on its own, and every time it is switched on or off we record who did it, when, and why. It is never enabled for all accounts at once, and it is never available to customers.

We keep these records for 30 days, then delete them automatically. If a customer deletes their account, we delete the records for their tunnels immediately, without waiting for the 30 days to pass.

We record this for one reason: to investigate abuse of our service. In August 2026 somebody used a tunnel to serve a fake login page. We removed it within minutes, but when the domain registry asked how many people the page had reached, we could not answer, because we did not keep this information. That gap took every one of our customers offline for two days.

Our lawful basis is legitimate interest under Article 6(1)(f) of the GDPR: running the service securely, investigating abuse, and answering a registry or law enforcement with evidence rather than an estimate. Under PIPEDA we rely on the investigation exception. The 30-day window is deliberately short, because we do not need a permanent record of who visited what.


2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and manage your subscription
  • Send you transactional emails (account verification, password resets, billing notifications)
  • Enforce plan limits (bandwidth, tunnel count, requests per second)
  • Detect and prevent fraud, abuse, and security threats
  • Respond to your support requests and inquiries
  • Generate aggregated, anonymized analytics to improve our platform

3. Information Sharing

We do not sell your personal information. We may share your information with:

  • Payment processors: Stripe processes your payment information. Their privacy policy applies to payment data.
  • Email service providers: We use third-party email services to send transactional emails.
  • Law enforcement: We may disclose your account information and tunnel metadata if required by law, court order, or government request. We may also proactively report illegal activity, including child exploitation material, to the appropriate authorities. This includes sharing IP addresses, tunnel logs, account details, and any other relevant metadata.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred.

4. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will:

  • Provide a 30-day grace period during which you can recover your account
  • Permanently delete your personal data after the grace period
  • Retain anonymized usage data for analytics purposes
  • Keep audit logs for up to 2 years for security and legal compliance
  • Delete tunnel request logs, including visitor IP addresses, after 30 days, or immediately on account deletion

5. Data Security

We implement industry-standard security measures to protect your data:

  • Passwords are hashed using bcrypt with a high cost factor
  • All connections are encrypted using TLS/HTTPS
  • API tokens are stored securely (hashed or encrypted)
  • Sessions are tracked and can be revoked at any time
  • Rate limiting protects against brute-force attacks
  • Account lockout after multiple failed login attempts

6. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Update or correct inaccurate personal data
  • Deletion: Request deletion of your account and personal data
  • Export: Request an export of your data in a portable format (JSON, CSV, or ZIP)
  • Restriction: Request that we limit how we use your data
  • Objection: Object to the processing of your personal data

To exercise any of these rights, contact us at [email protected] or use the account settings in your dashboard.


7. Cookies and Tracking

We use two first-party cookies, and no third-party cookie of any kind:

  • Session cookie (tnl_session): Required for authentication. It holds your sign-in session as an encrypted, tamper-proof value (AES-256-GCM sealed), so your browser only ever stores an opaque blob and your access tokens never appear in the page or in local storage. HttpOnly, Secure over HTTPS, SameSite Lax, expires after 7 days. Its SameSite Lax attribute also protects against cross-site request forgery.
  • Attribution cookie (tnl_attr): Records how you first reached this site so we can tell which channels bring people to us. It stores the campaign parameters in the link you followed, the domain name of the site that referred you, and the path of the first page you landed on. HttpOnly, Secure over HTTPS, SameSite Lax, expires after 90 days. It is set once on your first visit and never updated after that. If you create an account, this cookie is deleted immediately and the values are stored with your account so we know which channel it came from.

The attribution cookie contains no identifier for you. There is no visitor ID, no device fingerprint, no IP address, no browser or device details, no full referring web address and no query string from the page you landed on. It records how you arrived, never who you are, and it cannot be used to recognise you on any other website.

We do not use third-party tracking cookies, advertising cookies, advertising pixels or any third-party analytics script. Nothing on this site sends your browsing to another company.


8. Third-Party Services

Our services integrate with the following third parties:


9. Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 16, we will delete it promptly.


10. International Data Transfers

Our servers are located in North America. If you access our services from outside this region, your data may be transferred to and processed in Canada or the United States. By using our services, you consent to this transfer.


11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website or sending you an email. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.


12. Contact Us

If you have questions about this Privacy Policy, contact us at: