Privacy policy
Effective date: 7 October 2026
This policy covers Tunella for Windows and Android and this website at tunella.alexlv.com. Tunella is developed by Alex LV. Contact alex@alexlv.com with privacy questions or data deletion requests.
Data you store in Tunella
Tunella stores the SSH hosts, vaults, usernames, passwords, private keys, trusted host fingerprints, and shared settings you choose to save. The app encrypts its collection on your device using AES-256-GCM. It uses your collection password to protect access to the collection key. Decrypted data is available to the app while the collection is unlocked.
Device preferences and workspace layout are stored locally. SSH sessions connect directly to the servers you choose. Your servers receive the connection and authentication data they need to run those sessions.
Google data Tunella accesses
Google Drive sync is optional. Tunella requests https://www.googleapis.com/auth/drive.file. This grants access to files the app creates or files you explicitly make available to it. Tunella uses this permission for its own Tunella folder and encrypted collection snapshots. It does not request access to your entire Drive, Gmail, contacts, or calendar.
Tunella reads Drive file identifiers, filenames, timestamps, and snapshot metadata to find and reconcile collection revisions. The Windows app also reads the connected Drive account’s email address to show which account is connected.
How Google data is used and stored
Tunella uses Google data only to connect your account, identify its sync files, and synchronize encrypted collections across your devices. It uploads encrypted collection snapshots directly from your device to your Google Drive account. It downloads and decrypts them on your device.
Snapshot contents, including saved credentials and private keys, are encrypted before upload. Drive still stores file and folder names, file sizes, timestamps, collection identifiers, and revision ancestry as metadata. The collection password, recovery code, and device unlock key are not uploaded to Drive.
Google authorization tokens stay on your device and are sent to Google to authorize API requests. Windows protects its saved tokens with current-user Windows DPAPI. Android uses Google Play services for authorization and caches an access token in app-private storage. This website does not receive OAuth tokens or collection contents.
Sharing and Limited Use
Collection sync goes directly between your device and Google. The developer does not operate a server that receives your synced collections. Google processes data stored in Drive under Google’s privacy policy.
Tunella does not sell Google user data or use it for advertising, profiling, or training AI models. The developer does not access your Google account or synced collection contents. Tunella follows the Google API Services User Data Policy, including its Limited Use requirements.
Optional diagnostic uploads
The Android app keeps diagnostic logs locally. If you choose Send debug log, it uploads a log over HTTPS to the developer’s diagnostic service at callgate.alexlv.com for storage in the developer’s private debug-file archive. This is separate from Google Drive sync.
Logs can include the app version, device model, Android version, timestamps, errors, connection events, and collection, revision, or Drive file identifiers. Diagnostic logs are used to investigate app issues. Uploaded logs remain in the developer’s private archive until deleted. Contact alex@alexlv.com to request deletion of a log you sent.
Retention, disconnection, and deletion
- Your local collection and backups remain on your device until you delete them. Remove app data and any exported backups to remove local copies.
- Sync keeps encrypted snapshot history in your Drive. To delete it, delete the Tunella folder in Google Drive and empty the Drive trash. Google’s own retention rules may still apply.
- Disconnect Google in Tunella to remove the app’s local authorization cache. Disconnection does not delete existing Drive files or local collections.
- To revoke Google authorization, remove Tunella from your Google Account’s third-party connections. Disconnect each device to stop it from syncing.
Delete copies on each device and in Drive if you want to remove the collection everywhere. The developer cannot delete files in your account or recover a collection without its password or recovery code.
This website
This site uses no analytics, advertising, tracking scripts, or cookies. The web server records standard request logs, including IP address, request path, timestamp, browser information, and response status. These logs support site operation and troubleshooting and follow the server’s log rotation settings.
If you contact the developer by email, the developer uses your message and email address to answer your request.
Policy changes
Updates to this policy will appear on this page with a new effective date. Changes to the app’s data handling will be described here.