At Agent Tunnel, we take your privacy seriously. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
Key Point: Agent Tunnel processes your messages and code locally on your machine. We do not have access to your code, commands, or AI conversations. We collect minimal data necessary to operate licensing and prevent abuse.
1. Information We Collect
1.1 License and Purchase Information
When you purchase a license, we collect:
- Email address: To deliver your license key and communicate about your account
- Payment information: Processed securely by LemonSqueezy; we do not store credit card details
- Order ID: To track purchases and provide support
1.2 Machine Identifier
When you install and activate the Software, a randomly generated unique identifier (UUID) is created and stored locally on your device. This identifier is sent to our server during license activation and validation to ensure each license is used on one machine at a time. This identifier is not derived from your hardware and cannot be used to fingerprint your device.
1.3 Download and Activation Data
When you download the Software or activate a license, we collect:
- IP address: Collected automatically from the network request
- Approximate location: Country, region, city, and timezone, derived from your IP address by Cloudflare's network infrastructure
- Platform and architecture: Operating system and CPU architecture (e.g., macOS ARM64)
- Application version: The version of the Software being used
- Timestamps: When the download or activation occurred
This data is collected to prevent license abuse, detect unauthorized redistribution, and understand where our users are located. It is stored in a Cloudflare D1 database.
1.4 WebAuthn Credentials
The Software uses WebAuthn (Face ID, Touch ID, or equivalent) for device authentication. WebAuthn credentials are stored locally on your device and on your server instance. We do not have access to your biometric data; WebAuthn is a public-key protocol where your biometric never leaves your device.
1.5 What We Do NOT Collect
We do NOT collect, transmit, or have access to:
- Your code, source files, or project contents
- Messages or instructions you send to the AI
- The AI's responses or outputs
- Your Cloudflare account credentials or tunnel tokens
- Contents of any files on your machine
- Browsing history, keystrokes, or screen contents
2. How We Use Your Information
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Email, order ID | License delivery, account management, support | Contract performance |
| Machine identifier | License activation, single-machine enforcement | Contract performance |
| IP address, geolocation | Abuse prevention, unauthorized redistribution detection | Legitimate interest |
| Platform, app version | Product improvement, compatibility tracking | Legitimate interest |
| Download timestamps | Abuse detection, usage analytics | Legitimate interest |
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
3. Data Storage and Security
Your data is stored using:
- Cloudflare D1: Activation and download tracking data is stored in Cloudflare's distributed database infrastructure
- Cloudflare KV: Short-lived download tokens (auto-expire within 5 minutes)
- LemonSqueezy: Payment and subscription data (managed by LemonSqueezy under their security practices)
- HTTPS: All API communications between the Software and our servers are encrypted in transit
License keys are stored as SHA-256 hashes in our activation database; we do not store your full license key on our servers after initial validation.
4. Data on Your Machine
The following data is stored locally on your machine and never transmitted to us:
- Your Cloudflare tunnel credentials and configuration
- Your workspace directory path
- All Claude Code sessions, history, and outputs
- WebAuthn credentials and authentication tokens
- Push notification keys (VAPID keys)
- All code, files, and project data
We have no access to this data. Uninstalling the Software and deleting the application data directory removes all local data.
5. Third-Party Services
5.1 LemonSqueezy (Payment Processing)
Handles payment processing and subscription management. See their Privacy Policy.
5.2 Cloudflare (Infrastructure)
Provides hosting, tunneling, database, and content delivery services. When you use the Software, your connection passes through Cloudflare's network. See their Privacy Policy.
5.3 Anthropic (AI Provider)
Provides the Claude Code AI assistant. When you use the Software, your messages are processed by Anthropic's systems under their terms. We do not act as an intermediary for this data. See their Privacy Policy.
6. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data (note: this will invalidate your license)
- Portability: Receive your data in a standard, machine-readable format
- Objection: Object to processing based on legitimate interest
- Restriction: Request restriction of processing in certain circumstances
To exercise any of these rights, contact us at privacy@agenttunnel.app. We will respond within 30 days.
7. Data Retention
- Active licenses: Data retained while your license is active
- Expired or cancelled licenses: Data retained for 2 years for support and dispute resolution purposes
- Revoked licenses: Data retained for 5 years for fraud prevention
- Download tracking data: Retained for 2 years
- Download tokens: Auto-deleted after 5 minutes
8. Children's Privacy
Agent Tunnel is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have collected such information, please contact us immediately and we will delete it.
9. International Data Transfers
Your data may be processed in the United States and other countries where Cloudflare operates data centers. By using the Software, you consent to the transfer of your data to these jurisdictions. We rely on Cloudflare's data processing agreements and standard contractual clauses to ensure appropriate safeguards for international transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of changes by:
- Posting the updated policy on our website
- Updating the "Last updated" date at the top of this page
- Sending an email notification for material changes that affect how we collect or use your data
Your continued use of the Software after changes to this policy constitutes acceptance of the updated policy.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to know: What personal information we collect and how we use it
- Right to delete: Request deletion of your personal information
- Right to opt out of sale: We do not sell your personal information
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights
- Right to correct: Request correction of inaccurate personal information
To exercise these rights, contact us at privacy@agenttunnel.app.
12. European Privacy Rights (GDPR)
If you are in the European Economic Area, you have additional rights as described in Section 6 above. Our legal bases for processing are:
- Contract performance: Processing necessary to deliver the licensed software (license validation, machine activation)
- Legitimate interests: Abuse prevention, product improvement, and security (download tracking, geolocation)
You have the right to lodge a complaint with your local data protection authority if you believe we are processing your data unlawfully.
13. Contact Us
For privacy-related questions, data requests, or concerns:
Email: privacy@agenttunnel.app
For general support: support@agenttunnel.app