1. Overview
AiTun ("we", "us", "our") operates a secure tunnel and NAT traversal service at https://aitun.cc. This Privacy Policy explains what data we collect, how we use it, and the choices you have.
Minimal-data design: AiTun tunnels are end-to-end passthrough — we never inspect, log, or store the content of traffic flowing through tunnels. We only record the routing metadata required to operate the service.
2. Information We Collect
2.1 Account Information (Registered Users)
- Email address — for account identification and password recovery
- Hashed password — bcrypt-hashed, never stored in plaintext
- Subdomain name — the *.aitun.cc subdomain you registered
- Tunnel tokens — opaque tokens used to authenticate your tunnel client
2.2 Google OAuth Data (Admin Login)
If an admin chooses Google OAuth for admin panel login, Google shares:
- Google User ID — stable identifier, not your Google password
- Email address (as verified by Google)
- Display name and profile picture URL
These are used solely for admin authentication. We do not request access to any other Google service data.
2.3 Tunnel Operation Metadata
- Tunnel connection timestamps and durations
- Bytes transferred (aggregated counts, not content)
- Tunnel client IP address (for abuse prevention, retained 7 days)
- Subdomain-to-tunnel mapping (necessary for routing)
2.4 Free Trial Tunnels (No Account)
Anonymous trial tunnels (24-hour auto-expiring, served at *.t.aitun.cc or /s/<code>) collect only the minimal routing metadata above. No email or personal information is required.
3. What We Do NOT Collect
- We do not inspect, log, decrypt, or store the content of HTTP/TCP traffic flowing through your tunnels.
- We do not sell, rent, or share your personal data with third parties for marketing.
- We do not run analytics on individual user behavior.
- We do not request access to your Google Contacts, Drive, Gmail, or any other Google service.
4. How We Use Your Information
- Service operation — tunnel routing, subdomain management, billing
- Security — rate limiting, abuse prevention, DDoS protection
- Legal compliance — respond to legitimate law enforcement requests where required
5. Data Retention
- Account data — retained while account is active; deleted within 30 days of account deletion
- Tunnel metadata — 30 days for billing/audit purposes
- Connection logs — 7 days
- Tunnel content — never stored (passthrough only)
6. Your Rights
Depending on your jurisdiction (GDPR/CCPD/LGPD), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated tunnels
- Revoke Google OAuth access via Google Account Permissions
Email privacy@samai.cc to exercise these rights.
7. Google OAuth Compliance
AiTun's Google OAuth integration (admin login only) follows Google's OAuth 2.0 Policies:
- Restricted scope: Only
openid email profile — minimum required for authentication.
- No silent refresh: We do not request offline access tokens.
- Transparent disclosure: This Privacy Policy is linked from the OAuth consent screen.
- Revocation: Revoke access anytime via Google Account Permissions; we delete your Google ID within 30 days.
8. Security
- TLS 1.3 for all transport connections
- bcrypt password hashing (cost factor 12)
- Tunnel traffic encrypted in transit (P2P mode uses direct encryption, relay mode uses TLS)
- PostgreSQL with disk-level encryption
- Regular security audits and prompt patching
9. International Transfers
Your data may be processed on servers located in Singapore and Hong Kong. We comply with GDPR Chapter V for data transfers outside the EU/EEA.
10. Changes to This Policy
We may update this Privacy Policy. We will notify users of material changes via the admin panel and update the "Last updated" date above.
11. Contact
For privacy questions or requests: