Updated July 14, 2026

Tunello privacy

Tunello is designed without advertising, tracking, or developer analytics.

Data on your Mac

Tunello locally stores the configuration you enter, including server addresses, usernames, forwarding rules, workspaces, preferences, and history required to operate the app.

Imported private keys are copied into Tunello’s sandbox. If you separately consent to saving a passphrase, it is stored in the macOS Keychain. Tunello backups never contain private keys or passphrases.

Network connections

Tunello connects only to the SSH servers and destination services you configure. Their operators may process network metadata under their own policies.

Optional iCloud

iCloud/CloudKit sync is off by default and requires explicit opt-in. Eligible configuration is stored in your private iCloud database. Private keys, passphrases, and trusted host-key material are excluded from sync.

No data collection or tracking

F1REFlY does not receive Tunello configuration, tunnel traffic, private keys, passphrases, or local audit records through the app. Tunello includes no advertising SDK, cross-app tracking, developer analytics, or crash telemetry.

Support, retention, and deletion

If you contact support, F1REFlY processes only the information you choose to send in order to respond. Remove credentials and sensitive server information before sending diagnostics.

Local data remains on your Mac until you remove it in Tunello or delete the app container. iCloud data can be removed through sync settings and your iCloud account controls.