Privacy Policy

Privacy Policy

What we collect, how long we keep it, who we share it with, and how to delete it. Written without legal boilerplate, because a document nobody can read tells you nothing. Listed separately and in detail β€” which cookies we set: two of our own, technical ones, plus the cookies of three analytics systems.

If a translated version of this document disagrees with the English original, the English version prevails.

Revision 2.0 In effect since August 6, 2026 Questions: [email protected]

01In short

  • Traffic content is never logged or decrypted. Not the full URL, not request bodies, not headers, not cookies, not files.
  • We keep connection metadata for 90 days: time, target domain, volume, duration. Without them we couldn't bill you or respond to an abuse complaint.
  • Product analytics runs on the site: PostHog, Google Analytics, and Microsoft Clarity, on every public page and in the cabinet. PostHog and Clarity record the session β€” on-page actions, except for passwords, two-factor codes, connection strings, and wallet addresses. This is about site usage and has nothing to do with your traffic through the proxy. Details in section 07.
  • We don't sell data and don't pass it to ad networks or data brokers. The complete, closed list of recipients is in section 06.
  • Delete your account by emailing [email protected].

What follows is the same thing in detail, with legal grounds and time limits. If questions remain after reading it, they aren't rhetorical β€” write to us, we answer.

02What we collect

Account data

What you tell us when registering and in correspondence: your email address, your name or organization name, billing details if an invoice is needed, your Telegram contact if that's where we talk. The password is stored only as a hash (Argon2id) β€” the original password can't be recovered from it, which is why a forgotten password is reset rather than sent back to you.

Connection metadata

For every connection through the proxy we record: start and end time, target hostname and port, bytes sent and received, duration and reason for closing, the proxy credential used, the address you connected to our gateway from, and the exit address and its country.

These same records are the basis on which we respond to abuse complaints; how they're handled is set out in the Acceptable Use Policy.

Payment data

Card numbers, CVC codes, and bank account details never reach us at all: payment is processed on the payment provider's side, and all we get back is the fact of payment, the amount, the currency, the time, and a masked identifier β€” the card's last four digits or a wallet hash. For invoiced bank transfers we keep the organization's billing details, because without them we can't issue closing documents.

Platform technical records

Service operation logs: errors, response times, exit-address check results, records of tariff changes, and administrator actions. Customer data appears in them only as account identifiers.

03What we don't collect

This section matters more than the previous one, because "we don't log" is the most common and most empty promise in this industry. Here's what actually stands behind it for us.

  • Traffic content. HTTPS connections pass through the gateway using the CONNECT method: two sockets are joined and bytes are relayed between them. We have no keys, no substitute certificate, no MITM proxy β€” reading the stream is technically impossible, not merely "forbidden by policy". For plain HTTP the content passes through us unencrypted but isn't logged: only the hostname goes into the log, not the request.
  • Full URLs. We record example.com, not example.com/user/12345?token=…. The path and query parameters are often the content itself.
  • Files, request and response bodies, cookies, headers. Nowhere, ever.
  • Lists of visited sites as a product. Metadata exists for billing and complaint handling. We don't build profiles from it, don't enrich it, don't analyze customer behavior, and don't sell aggregates.
  • Traffic content in analytics. The three measurement systems from section 07 run on the site's and the cabinet's pages. They play no part in proxied connections: those go to a different domain name where none of our scripts run. What you open through the proxy never reaches PostHog, Google Analytics, or Clarity.
  • Special categories of data. We don't request or process information about health, beliefs, religion, or anything similar.

04Why, and on what legal basis

DataPurposeLegal basis
Account Service access, operational correspondence, invoices and closing documents Contract performance
Connection metadata Calculating consumed volume, confirming balance, responding to complaints, troubleshooting Contract performance; legitimate interest in protecting infrastructure
Payment records Payment confirmation, refunds, accounting and tax records Contract performance; legal requirements
Technical logs Platform reliability, incident analysis, security Legitimate interest

We don't make automated decisions with legal consequences: disconnection under the section on the consequences of violations in the Acceptable Use Policy is a human decision, and it can be appealed by replying to the email.

05Retention periods

WhatCommentPeriod
Connection metadata Time, host, volume, duration. Deleted entirely 90 days
Aggregated volumes Totals for a period without target hosts β€” needed for calculations and reporting 3 years
Balance transaction log Top-ups and charges. This is what lets us show how a balance was made up 3 years
Payment and accounting documents The period is set by law, not by us 5 years
Account While active, then 12 months β€” the same period during which an unused balance is kept in the absence of activity 12 months
Technical logs Errors, response times, address check results 30 days
Support correspondence So we don't have to work through the same issue again 24 months
Complaint materials The complaint, our findings, measures taken 24 months

There's one exception to these periods, and it's more honest to state it plainly: if a complaint or a request from an authorized body concerns specific connections, the related records are kept until the matter is resolved, even if the 90 days have already passed.

Database backups are kept encrypted, on a rotation of up to six months. This means deleted data can remain in backups for up to six months after being removed from the primary database: restoring a backup just to delete one row would create more risk than it removed. When restoring from a backup, deletions are reapplied.

06Who we share it with

We don't sell data and don't pass it to ad networks or data brokers. The three measurement services in the list below receive data about site usage, and that's stated outright rather than hidden behind the word "infrastructure". The complete list of everyone who receives anything from us at all:

  • Payment providers. Receive the amount and whatever is needed to process the payment. Card data is handled by them, not by us.
  • PostHog, Inc. (product analytics, hosted in the US). Receives: events on the site's and cabinet's pages β€” page views, clicks, form submissions, registration, email confirmation, login, trial activation, viewing the purchase page, applying a promo code, placing an order, successful payment, proxy generation, ticket creation; technical request details (IP address, User-Agent, window size, page address, and referrer address); session recording β€” the sequence of on-page actions; and for a logged-in visitor, the account identifier and email address, so that visits from different devices can be linked. Does not receive: passwords, two-factor codes, proxy passwords and connection strings, wallet addresses β€” these fields are excluded from recording β€” and nothing about the content of your traffic through the proxy. PostHog's Privacy Policy.
  • Google LLC / Google Ireland Ltd. (Google Analytics 4). Receives: the fact of a page view, the same product events, technical request details, and an approximate location derived from the IP address, and the account identifier for a logged-in visitor. Does not receive session recordings β€” GA doesn't keep them β€” and doesn't receive the content of input fields. Advertising features (Google Signals, remarketing) are not enabled. Google's Privacy Policy.
  • Microsoft Corporation (Microsoft Clarity). Receives: session recording and heatmaps β€” pointer movements, scrolling, clicks, navigation; technical request details; the account identifier and email address for a logged-in visitor. The same four kinds of fields are excluded from recording. Microsoft's Privacy Statement.
  • Email service. Sends emails on our behalf: the email confirmation code, the password reset link, new-device notifications, support replies. Receives the recipient's address and the content of the email we ask it to send β€” nothing more β€” and has no access to the rest of the account's data.
  • Hosting provider. Provides the servers the platform runs on. Has no access to the database; physical access to the disks is possible, which is why backups are encrypted.
  • Exit-address providers. See the fact and volume of connections passing through their addresses, and the target hosts β€” that's unavoidable, the traffic runs through their network. Your account data isn't shared with them: to them, you're indistinguishable from anyone else.
  • Cloudflare. Handles HTTPS connections to this site and sees the IP addresses of its visitors. Only for the site β€” proxy traffic goes to a different domain name and doesn't pass through Cloudflare at all.
  • Object storage operator. Stores encrypted backups. Does not have the encryption key.
  • Authorized bodies β€” on a lawful, properly executed request, to the extent it specifies and no further. The procedure is set out below.

Requests from authorized bodies

We verify that a request is lawfully formed and comes from a body entitled to send it; we respond only within the scope requested and only with what we actually have. We won't expand our data collection in anticipation of future requests: what isn't recorded can't be handed over.

We notify the customer of a request we've received, unless the law forbids it or it would directly obstruct an investigation. We don't comply with requests that aren't lawfully formed.

A separate rule applies to material involving child exploitation: such reports are passed to law enforcement together with all the metadata we have, without notifying the customer.

Transfers outside the country

The platform's servers and backups are located in data centers within the European Union. Exit addresses are located in 100+ countries β€” that's the product itself: by initiating a connection through an address in another country, you're the one sending data there. Which data goes there is your call, because it's your traffic.

07The site: analytics and cookies

Product analytics runs on the site and in the cabinet. Three systems, all three on every public page and every cabinet page, with no consent banner and no conditions: PostHog (events and session recording), Google Analytics 4 (aggregate statistics) and Microsoft Clarity (session recording and heatmaps). The previous revision of this document claimed otherwise; it became outdated the day these systems were connected, and this one replaces it.

We measure site usage: which pages are opened, in what order, where visitors stop, which forms are abandoned. Beyond automatically collected clicks, we explicitly send events: registration, email confirmation, login, trial activation, viewing the purchase page, applying a promo code, placing an order, successful payment, proxy generation, ticket creation. For a logged-in visitor, the account identifier and email address are sent along with the events β€” so that one person's visits from different devices form a single history.

Session recording

PostHog and Clarity record the session: pointer movements, scrolling, clicks, page-to-page navigation, input into ordinary fields. This isn't a screen video, but a sequence of page changes that can be replayed; other tabs, the camera, and the microphone never enter it.

Four kinds of fields are excluded from recording: passwords; two-factor codes and address confirmation codes; proxy passwords and ready-made connection strings, including generated lists and code samples; crypto wallet address in the withdrawal form. The reason is technical: these values give product analytics nothing β€” no funnels are built on them β€” while if our account in the analytics system were ever compromised, they'd be working credentials of our customers. Everything else is recorded without restriction.

None of the three systems is loaded at all on the admin panel's pages: the panel's address is a random secret string, and session recording would send it to three external services forever.

What's not in the analytics

The content of your traffic through the proxy. Proxied connections go to a different domain name, where these scripts don't load and can't load; the target hosts, volumes, and connection times stay in our own logs, on the schedule set out in section 05, and are never passed to analytics.

Advertising features. Google Signals and remarketing are not enabled; there are no ad-network pixels on the pages; analytics data is never passed to brokers or sold.

Cookies and how to opt out

The three systems set their own cookies; their names, purposes, and durations are listed in the Cookies Policy. The same page lists working ways to opt out: a content blocker, Google's GA opt-out add-on, Clarity's opt-out form, deleting these domains' cookies. The site, the cabinet, purchasing, and string generation work the same with or without them.

The site's own cookies are still just two: the session and CSRF protection, both technical and required.

Everything else on the pages

Fonts and the logo are served from this same host, not from fonts.googleapis.com or an image-hosting service. Apart from the three measurement systems and a request to our own /api/pricing (a fresh pricing scale; nothing in it identifies you, and the table is drawn before it even arrives β€” from a grid baked into the page), the pages make no requests to third-party hosts.

Cloudflare, which handles connections to the site, may set its own technical cookie to defend against automated traffic; we neither control it nor read it.

The web server keeps a standard access log β€” IP address, time, requested path, response code, User-Agent β€” and retains it for 30 days. It's needed to understand why a page returned an error.

08How we protect it

  • Passwords are stored as Argon2id hashes. The password can't be recovered from the hash.
  • Exit-address passwords are encrypted in the database (AES-256-GCM) with a key that isn't stored in the database.
  • Backups are encrypted with a public key whose private half isn't stored on the server. A backup that falls into the wrong hands is useless. Restoring a backup is tested automatically every week β€” otherwise it's not a backup, it's a hope.
  • Administrator access to the database and panels is only possible through an SSH tunnel; only the proxy ports themselves and this site are open to the outside.
  • Connections to the site β€” HTTPS only, with HSTS.

In the event of a personal data breach that creates a risk to customers, we notify affected customers and the supervisory authority within 72 hours of learning of it, with a description of what happened, which data is affected, and what we did.

Found a vulnerability? Write to [email protected]. We respond, and we don't pursue anyone for a good-faith report.

09Your rights

You can:

  • Find out what we have. We'll send you a copy of your account data and connection metadata for the available period.
  • Correct what's wrong. Billing details, contact information, organization name.
  • Delete your account. Everything is deleted except documents the law requires us to keep (section 05), and materials related to open complaints.
  • Get your data in a machine-readable format β€” JSON or CSV.
  • Object to processing based on legitimate interest.
  • Lodge a complaint with the supervisory authority where you're located. Try writing to us first: most often the matter is resolved faster that way.

Requests are accepted at [email protected] from the address registered on your account, otherwise we can't be sure the request is from you, and handing data to the wrong person is worse than refusing. Response time β€” 30 days, usually faster. We don't charge for this.

The one thing we can't do on request is hand over the content of your traffic or a list of URLs you visited. We simply don't have them β€” that's section 03, not an excuse.

10Contact and changes

Questions about data β€” [email protected].
Complaints about the use of our addresses β€” [email protected].
Vulnerabilities β€” [email protected].
Legal questions β€” [email protected].

The current version is always available at https://tunnelops.cloud/privacy. We notify the account's contact address of material changes β€” new categories of data, new recipients, longer retention periods β€” at least 14 days before they take effect.

Related documents: the Terms of Service, the Acceptable Use Policy, the Cookies Policy and the Refund Policy. . General questions and the seller's details are on the contacts page.

The exit country of a proxy address and upstream geodata, as well as the city shown in the session list in the cabinet's security settings, are determined by the local IP Geolocation by DB-IP, licensed under CC BY 4.0.