Privacy Policy
This policy explains what personal information Tenux collects, why we collect it, who we share it with, and the rights you have over your data. We try to keep it short and concrete.
0. The short version: we are the pipe, not the owner of your machine
Tenux connects your phone or browser to your own computer (or a cloud VM you rent). The work you do — your code, files, terminal output, and Tenux Chat history — lives on your machine, not in our database. We carry that traffic across our tunnels and relay so you can reach it remotely, but we do not store it server-side and we do not read it. What we do keep is the lean set of records needed to sign you in, route your connections, bill you, and debug failures — described below.
1. Information we collect
Account information
When you create a Tenux account we collect your email address and (optionally) your name. If you sign in with GitHub, we also receive your GitHub user ID, username, and email address from GitHub’s OAuth flow.
Authentication tokens
We store authentication state in Supabase (our auth provider). For users who connect a GitHub account, we hold OAuth tokens scoped to the permissions you approved. Each linked device (CLI, mobile, cloud VM) has its own short-lived access token and a long-lived device secret, which we rotate periodically.
Usage data
To provide the Service we collect:
- Heartbeat / connection state — whether your devices are online and reachable, last-seen timestamps, and tunnel session metadata (which device is connected, not what flows through it).
- Bandwidth metering — the volume of traffic carried across your tunnels, the relay, and any cloud VMs, attributed per device and per source so we can enforce your 100 GB pooled allowance and any overage you have opted into. We meter how many bytes moved, never their contents.
- Subscription and billing state — your current plan, subscription status, AI-credit balance, and the cloud VMs attached to your account. The authoritative payment and invoice records live with Stripe, not with us.
What we do not collect or store server-side: the contents of your terminals, files, code, live preview, or Tenux Chat history — those stay on your machine. When you send a Tenux Chat prompt, the messages and tool output the agent needs are forwarded to our AI provider (Section 3) for inference and are not retained by us afterward.
Payment information
Payments are processed by Stripe. We never see, store, or have access to your card number, CVC, or full bank details. Stripe gives us a customer ID and metadata about successful charges, which we link to your account for invoicing and quota enforcement.
Product analytics
We use PostHog to understand how the product is used in aggregate (which features are popular, where users get stuck). Analytics events carry only coarse, non-identifying properties — never your code, terminal output, chat content, file contents, or error messages. Optional session replay is limited to our billing and account pages (with inputs masked) and is never enabled on the workspace, so your terminal keystrokes are never recorded. We honour your browser’s Do-Not-Track signal.
Error tracking
We use Sentry to capture errors that occur in the web app, the agent, and the backend. Sentry events may include your account ID, the URL or operation that failed, a stack trace, and a snippet of recent user actions. We don’t intentionally send your code or chat content to Sentry.
2. How we use your information
- Provide the Service — establish and route connections between your phone or browser and your machines, carry tunnel and relay traffic, and forward Tenux Chat prompts to our AI provider for inference.
- Billing and account management — process subscription charges, meter pooled bandwidth and apply opted-in overage, track AI-credit balances, and send receipts and threshold notices.
- Debugging and reliability — investigate errors and outages, often using your account ID as the lookup key when you report a problem.
- Abuse prevention and security — detect and respond to attacks on our infrastructure or other users, enforce our acceptable-use rules.
- Product analytics — understand aggregate usage patterns so we can prioritise what to build next.
- Communication — send transactional emails (verification, billing receipts, security notices) and, if you opt in, occasional product updates.
3. How we share your information
We do not sell your personal information. We share data only with the sub-processors and partners we need to operate the Service:
- Stripe — payment processing and subscription management. Stripe is our financial system of record; your card details go to Stripe and never to us.
- Supabase — authentication and our primary (lean) database of account, routing, and billing state.
- Cloudflare — DNS, CDN / edge networking, DDoS protection, and the tunnel layer that fronts your workspaces.
- Fly.io — hosting for the managed relay (which carries your remote-access traffic) and for the cloud VMs you rent.
- Vercel — hosting for the web application.
- Anthropic — the AI provider that serves the Tenux Chat agent. When you send a prompt, the relevant context (your messages and any tool output the agent needs) is sent to Anthropic for inference. If you bring your own API key instead, that request is governed by your own agreement with the provider.
- Resend — transactional email delivery (verification, receipts, billing and security notices).
- PostHog — product analytics.
- Sentry — error monitoring.
- Upstash — the Redis service holding short-lived operational state: sign-up verification codes, sign-in challenges, and rate-limit counters.
- Axiom — storage and search for our application logs, which carry your account ID and IP address for debugging, security, and abuse prevention.
Each sub-processor receives only the minimum information needed to perform its function. The current, canonical list — with each provider’s purpose, the data shared, and its location — lives on our Sub-processors page; we update it whenever the list changes, and you can ask to be notified 30 days before a new sub-processor begins processing your data.
We may also disclose information when required by law (a valid subpoena, court order, or comparable legal demand), or when necessary to protect the rights, property, or safety of Tenux, our users, or the public.
4. Data retention
Our database is deliberately lean: we keep only what auth, routing, billing, and debugging need. High-volume event tables (such as bandwidth metering and AI-credit usage) are rolled up into bounded, privacy-minimised monthly aggregates so they cannot grow without bound, and we are rolling out automatic pruning of the underlying raw rows once an aggregate covers them.
- Account data — retained while your account exists. Cancelling your subscription does not delete your account: it reverts you to the free tier (we end the subscription, stop your cloud VMs, and keep your AI-credit balance), and your account and its data remain so you can keep using the free tier or re-subscribe. To remove your account and the personal data tied to it, use the delete-account control in your settings (Section 5) — that is an immediate, permanent deletion of your account.
- Cloud VM volumes — how long a VM’s data is kept depends on why it stopped. If you cancel your subscription, your Cloud VMs and their volumes are permanently deleted at the end of your billing cycle — there is no 30-day hold, so download anything you want to keep before then. If your subscription lapses because a payment failed, the VM is stopped and its volume is kept for 30 days so you can recover it by fixing your payment method, then permanently deleted. If a VM is stopped for bandwidth — you turned overage off and hit 100% of the pooled allowance — nothing is deleted: the volume is preserved and the VM resumes next cycle. The Billing Policy has the full cancellation effects.
- Chat, files, and terminal content — not retained by us at all. Tenux Chat history lives on your own device; deleting it there removes it. Prompt context forwarded to our AI provider for a response is not stored by us afterward.
- Bandwidth and AI-credit usage records — recorded per event so we can compute your bill and handle a dispute, and rolled up into a privacy-minimised monthly aggregate; the per-event rows for a closed period are kept only as long as we need them and are being phased out in favour of the aggregate.
- Application and error logs — retained for a short window (on the order of 90 days) for debugging and security purposes.
- Payment and invoice records — we do not keep a years-long local ledger. Stripe is our financial system of record and retains invoices and charge history for the period required by tax and accounting law; we hold only lean billing state (balances, quotas, flags).
5. Your rights
Wherever you live, you can ask us to do the following with the personal information we hold about you:
- Access a copy of the personal information we hold about you.
- Correct information that’s inaccurate (most fields are editable from your account settings).
- Delete / erase your account and the personal data tied to it.
- Export (portability) — receive your data in a portable, machine-readable format.
- Object or restrict — object to specific kinds of processing, restrict it, or withdraw consent where processing is based on consent.
If you are in the EEA or UK (GDPR): these are your statutory rights of access, rectification, erasure, portability, restriction, and objection. Our lawful bases are performance of our contract with you (operating the Service and billing), our legitimate interests (security, abuse prevention, and aggregate analytics), and your consent where we ask for it. You may also lodge a complaint with your local data-protection authority.
If you are a California resident (CCPA / CPRA): you have the right to know, access, delete, and correct your personal information, and to be free from discrimination for exercising these rights. We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising, as those terms are defined under California law. We run PostHog analytics in an analytics-only configuration — no advertising networks, no ad-targeting. Because we do not sell or share your personal information, there is nothing for an opt-out-of-sale signal (such as the Global Privacy Control) to turn off; if that ever changes, we will update this policy and honour those signals.
To exercise any of these rights, email [email protected] from the address associated with your account (an authorised agent may act for you). We’ll verify your request and respond within a reasonable period — within the statutory deadline where law requires — at no charge for a reasonable request.
6. Data transfers
Tenux LLC is operated from the United States, and our sub-processors host data in U.S. infrastructure. If you access the Service from outside the U.S. — including from the EEA or UK — your information will be transferred to and processed in the United States, whose data-protection laws may differ from your jurisdiction’s.
Where we transfer personal data of EEA or UK residents, we rely on appropriate safeguards — principally our sub-processors’ data-processing terms, which incorporate the European Commission’s Standard Contractual Clauses (with the UK Addendum) where applicable — rather than on your consent alone. To ask about these safeguards, email [email protected].
7. Cookies and similar technologies
We use a small set of cookies and equivalent storage:
- Authentication / session — required for you to stay signed in. These are first-party and cannot be disabled while using the Service.
- Analytics — our analytics (PostHog) runs without cookies and without storing anything on your device; measurements are kept in memory for the duration of your visit only.
- Preferences — we remember small UI state (e.g. theme, last visited tab) in local storage.
8. Children
Tenux is not directed at children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact [email protected] and we will delete it promptly.
9. Security
We take the security of your data seriously. Concretely:
- Encryption in transit — all connections to Tenux endpoints use TLS.
- Encryption at rest — the underlying databases and storage volumes are encrypted by our infrastructure providers.
- Row-level security (RLS) — our database enforces per-user isolation at the row level so a bug in application code can’t expose another user’s data.
- Strong authentication — passkeys are supported as a stronger, phishing-resistant alternative to passwords (we recommend adding one), and sensitive actions — changing your password, removing a passkey — require you to re-authenticate first.
- Token hygiene — access tokens are short-lived; device secrets rotate; we strip sensitive environment variables from interactive shells we open inside your VMs.
No system is perfectly secure. If you discover a vulnerability, please report it to [email protected] rather than disclosing it publicly — we’ll acknowledge receipt promptly and work with you on a fix.
10. Changes to this policy
We may update this Privacy Policy as the product evolves. If a change is material, we’ll notify you by email and/or in-product notice before it takes effect. The “Last updated” date at the top of this page always reflects the current version.
11. Contact
Tenux is operated by Tenux LLC, a California limited liability company. Privacy questions, data-rights requests, complaints, security issues, and general support all reach us at [email protected].