Back to home

Privacy Policy

How we collect, use, retain, and protect information when you use our local Agent tunnel service.

Last updated: 2026-07-02

Introduction

This Privacy Policy explains how we collect, use, share, retain, and protect personal information when you visit, register for, purchase, or use the service. The service is designed for local Agent node access, encrypted reverse tunnels, an OpenAI-compatible API gateway, and channel subscriptions. The platform is a tunnel service: your models, tools, and local data stay on your own devices by default, while the platform handles authentication, routing, encrypted forwarding, and necessary service-state management.

By using the service, you acknowledge that you have read and understood this policy. If you do not agree with it, please stop using the service.

Information We Collect

Depending on the features you use, we may collect the following information:

  • Account information: name, display name, email address, avatar, sign-in method, account status, roles, permissions, and authentication records.
  • Login and authentication information: email/password sign-in data, Google or GitHub account identifiers, OAuth authorization status, and necessary session information.
  • Subscription and payment information: tunnel plans, order IDs, payment status, invoices, receipts, subscription status, device quota, and billing metadata. Full card numbers and other sensitive payment credentials are processed by third-party payment providers and are not stored by us.
  • Node and key information: AgentID, node status, NodeToken status, ApiToken status, allowlists, QPS/quota settings, and necessary security audit information. Keys are stored or displayed using appropriate safeguards.
  • Tunnel invocation information: invocation logs are stored only when you enable log retention. When log retention is off, the platform does not store prompts, responses, error details, or invocation metadata.
  • Device and basic log information: IP address, browser type, device information, access time, page paths, crash logs, and performance data for login, security, anti-abuse, and service stability.
  • Cookies and local storage: used for sessions, language preferences, security controls, payment flows, and basic analytics.
  • Information you submit voluntarily: content sent through forms, support channels, tickets, email, or other communications.

How We Use Information

We use information for the following purposes:

  • To create and maintain your account and provide login, registration, permission checks, and security verification.
  • To provide local Agent node access, an OpenAI-compatible gateway, encrypted tunnels, and online-state management.
  • To process orders, refunds, billing, subscriptions, device quota, API keys, and payment status.
  • To route authorized requests to your local nodes and return results in standard API formats.
  • To send service notices, security alerts, transaction confirmations, product updates, or necessary operational messages.
  • To troubleshoot issues, improve performance, analyze usage trends, and optimize the product experience.
  • To prevent fraud, abuse, spam, unauthorized access, and violations of our Terms of Service.
  • To comply with applicable laws, regulations, legal processes, or lawful government requests.

Log Retention Choice

You can choose in account settings whether the platform may retain invocation logs. By default, invocation logs are not retained.

  • Log retention off: the platform authenticates, routes, and forwards encrypted traffic without storing prompts, responses, error details, or invocation metadata.
  • Log retention on: the platform may store invocation logs for debugging, audit, and statistics, depending on the product UI and admin configuration.

Regardless of invocation log retention, account, subscription, payment, security, node-online-state, and necessary compliance records may still be retained for service operation and legal requirements.

Third-Party Services

To provide the full service, we may use third-party services such as:

  • OAuth providers, including Google and GitHub.
  • Payment providers, including Stripe, PayPal, Creem, or WeChat Pay.
  • Email providers, including Resend or Cloudflare Email.
  • Hosting, database, storage, logging, analytics, and security providers.
  • Tunnel, gateway, email, payment, or other infrastructure services configured by an administrator.

These third parties process information according to their own privacy policies. We share only the information reasonably necessary to provide the service.

Information Sharing

We do not sell your personal information. We may share information only in the following circumstances:

  • With trusted vendors, payment providers, cloud providers, or model providers as needed to operate the service.
  • In connection with a merger, acquisition, asset transfer, financing, or similar business transaction, subject to appropriate confidentiality protections.
  • To comply with legal obligations, enforce our Terms of Service, or protect the rights, property, or safety of us, our users, or the public.
  • With your explicit consent.

Data Retention

We retain information for as long as necessary to provide the service and fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Account, order, billing, security audit, and compliance records may be retained for a reasonable period after account closure. You may contact us to request deletion or export of your data, although some records may need to be retained for legal, financial, security, or dispute-resolution reasons.

Data Security

We use reasonable technical and organizational measures to protect information, including access controls, encryption in transit, key management, least-privilege access, audit logs, and configuration isolation. No method of transmission or electronic storage is completely secure, so we cannot guarantee that information will never be accessed, disclosed, altered, or lost.

Your Rights

Subject to applicable law, you may request to:

  • Access, correct, or update your personal information.
  • Delete your account or certain personal information.
  • Export your data.
  • Restrict or object to certain processing activities.
  • Withdraw consent where processing is based on consent.
  • Unsubscribe from marketing communications.

We may need to verify your identity before processing your request.

Cookie Management

You can block or delete cookies through your browser settings. If you disable necessary cookies, login, payments, language preferences, security checks, or some workspace features may not work properly.

Children's Privacy

The service is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us and we will take appropriate steps after verification.

Changes to This Policy

We may update this policy from time to time. For material changes, we will update the date on this page and may provide in-product notice or another reasonable notice. Continued use of the service after the changes take effect means you accept the updated policy.

Contact Us

If you have questions about this Privacy Policy or our handling of personal information, contact us at:

[email protected]