tunnelbox lets you control the AI agents on your PC from your phone. This policy explains what data is processed, where it is stored, and how you can control it.
1. What the apps and adapters process
The tunnelbox apps and adapters let you browse agent sessions, stream output, send tasks, and approve permissions. Agent sessions and conversation history are fetched from your PC in real time and are stored only in your agent's local storage on that computer.
Your adapter keeps a small state file on your PC (~/.tunnelbox/remote-state.json) containing your agent ID and your preferred language. Nothing else about your conversations is written to disk by the adapter.
2. How the official relay handles data
The relay is a stateless forwarder. It routes encrypted messages between your phone and your PC's adapters and stores no conversation content.
Session tokens are stored as SHA-256 hashes, and pairing codes are single-use and expire after 10 minutes. The relay keeps no record of the text of your prompts, responses, or files.
3. This website: analytics and local storage
This website uses Baidu Tongji and Microsoft Clarity analytics to understand aggregate traffic and page usage. These services may process technical data such as your IP address, browser type, and pages visited.
Your browser stores a single setting in local storage to remember your theme preference (light or dark). No account, profile, or personal data is collected by the website itself.
4. Third-party services and links
The website loads a QR-code rendering library from a public CDN (jsDelivr) to display download QR codes, and links to external services such as GitHub. Those services have their own privacy policies.
5. Security
Transport between your phone, the relay, and your PC is encrypted with TLS. Tokens are hashed, and pairing codes are short-lived and single-use. Privacy-sensitive users can self-host the relay so that data stays on their own infrastructure.
6. Your rights and control
Because conversation data stays on your own computer, you control it directly: delete sessions or files locally at any time, run adapters on your own machine, or self-host the relay. If you have questions or want to exercise a privacy right, contact us at the address below.
7. Changes and contact
We may update this policy from time to time; the "last updated" date at the top reflects the latest revision. For any privacy questions or requests, email foquanlin@gmail.com.