Legal
Privacy Policy
Who we are
This policy covers ntunn, operated by MakeWithPaul ("ntunn", "we", "us") and the ntunn tunneling service at ntunn.com and *.tunnel.ntunn.com (the "Service"). It explains what we collect, why, and the choices you have.
What we collect
Account data. Your email address and a bcrypt hash of your password. We never store plaintext passwords.
API keys. Keys you create are stored as one-way hashes; the full key is shown to you once at creation and cannot be recovered by us afterwards.
Usage data. Tunnel metadata (tunnel ID, protocol, connection times, bytes transferred) and request metrics (counts, status classes, timing) used to operate the dashboard and enforce plan limits.
Request capture. When you use the request inspector, we store captured request metadata — method, path, status, headers, and a truncated body snippet — so you can inspect and replay requests. Do not tunnel traffic containing secrets you do not want captured; you can delete captures from the dashboard.
Logs. Standard server logs (IP address, user agent, timestamps) for security, abuse prevention, and debugging. Audit-log entries are retained for 30 days.
Support correspondence. If you email us, we keep the conversation to resolve your issue.
What we do not collect
We do not run advertising trackers, do not sell your data, and do not use third-party analytics that profile you across sites. The only cookie the dashboard sets is a first-party session cookie required to keep you signed in.
How we use data
To provide and secure the Service: routing your tunnels, authenticating you, enforcing plan limits, preventing abuse, and sending transactional email (verification, password reset, critical service notices). We do not send marketing email without your consent.
Sub-processors
The Service runs on Amazon Web Services (us-east-1): EC2/ALB for serving, DynamoDB for storage, S3 for release artifacts. Transactional email is delivered by Resend. These providers process data only to provide their services to us.
Retention
Account data is kept while your account exists. Request captures and metrics expire automatically (short-lived TTLs). Audit logs are retained 30 days. When you delete your account, your tunnels, API keys, sessions, and request history are deleted immediately; residual backups and logs age out on their normal schedule.
Your rights
You may access, correct, export, or delete your account data at any time from the dashboard, or by emailing legal@ntunn.com. Deleting your account is self-serve from Settings and is permanent.
Security
All traffic is served over HTTPS with certificates from Let's Encrypt. Passwords and API keys are stored hashed. Access to production systems is restricted to the operator. No method of transmission or storage is 100% secure; if we discover a breach affecting your data we will notify you by email.
Children
The Service is not directed at children under 13 (or the equivalent minimum age in your jurisdiction) and we do not knowingly collect their data.
Changes
We may update this policy; material changes are announced by email or a notice in the dashboard before they take effect. The "last updated" date above always reflects the current version.