Privacy Policy
Last updated: October 6, 2026
1. Our Privacy Commitment
At talu, we believe privacy is fundamental to developer tooling. We practice strict data minimization: we collect only what is strictly necessary to run, secure, and operate the hosted tunnel infrastructure. We do not sell your personal data or monetize your traffic.
Zero Payload Logging Guarantee: We do NOT inspect, store, or log the payloads (request bodies, responses, cookies, auth headers, or WebSocket messages) running through your tunnels. Your traffic is forwarded strictly in-memory between the internet and your local machine.
2. Information We Collect
We collect information in two limited categories:
A. Account & Authentication Information:
- When you authenticate via GitHub or Google OAuth, we receive your email address, unique provider account identifier, and public profile avatar.
- We generate and store cryptographic tokens associated with your account so your CLI client can authenticate.
- We never ask for or store passwords.
B. Operational & Security Metadata:
- Active tunnel session metadata (e.g., allocated subdomain name, port requested, tunnel start and disconnection timestamps).
- Aggregated byte counts and request rates to enforce fair-use limits and prevent network degradation.
- Connecting IP addresses in server access logs retained temporarily for security auditing, DDoS mitigation, and abuse prevention.
3. What We Never Collect or Store
We believe your localhost development code and private APIs belong to you:
- No Request/Response Bodies: Data transmitted through HTTP POST/PUT/PATCH or WebSocket streams is never written to disk or database.
- No Sensitive Headers: Authorization headers, API keys, and session cookies passing through your tunnel are not logged.
- No Advertising Trackers: We do not include third-party tracking scripts, advertising pixels, or telemetry beacons on our website or within our CLI.
4. How We Use Information
We use collected data solely to:
- Authenticate your identity and provide you with reserved subdomains and access tokens.
- Route traffic from the public edge to your local tunnel client.
- Protect our network against abuse, attacks, spam, and malicious exploits.
- Provide technical support and notify you of critical service updates.
5. Cookies and Local Storage
We use strictly necessary, HTTP-only cookies to preserve your signed-in session state and protect against Cross-Site Request Forgery (CSRF). We do not use third-party analytics cookies or tracking cookies.
6. Third-Party Service Providers
We rely on trusted infrastructure providers to deliver the service:
- Cloud Hosting & Edge Providers: Servers and networks that host talu's relay nodes.
- OAuth Identity Providers: GitHub and Google for user authentication.
These providers process data only as necessary to provide infrastructure services, and are subject to strict confidentiality obligations.
7. Data Retention and Deletion
Account data and reserved subdomain configurations remain stored while your account is active. You may delete your account, revoke access tokens, or release subdomains at any time through the dashboard or by contacting us. Upon account deletion, all associated authentication records and tokens are permanently purged.
8. Security Measures
All communication between the public internet and talu, as well as between talu's edge servers and your local CLI client, is encrypted using modern TLS (HTTPS) and secure transport protocols. We apply least-privilege security controls across our infrastructure.
9. Changes to this Policy
We may update this Privacy Policy as our services evolve. Any revisions will be reflected with a revised "Last updated" date on this page. We encourage you to review this policy periodically.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at [email protected].