Skip to content

Privacy Policy

Effective date: · Operator: Tunelio · Contact: support@tunelio.dev

This policy explains what personal data Tunelio collects when you use the API, the Dashboard and the website, why we collect it, how long we keep it, who we share it with, and the rights you have. We collect the minimum needed to run a paid API and keep it secure.

1. Who we are and what this covers

This policy is published by the operator of the service at tunelio.dev (“Tunelio”, “we”). It applies to the website, the Dashboard, the Telegram bot and the API. It does not cover the practices of YouTube, of payment processors, or of any application you build with the API; those have their own policies.

2. Data we collect

Account data. When you sign in with Telegram we receive your Telegram user ID, username and display name from Telegram’s login widget. When you register with email we store the email address and a salted hash of your password (never the password itself). If you enable a passkey or an authenticator app we store the public key or a TOTP secret. We generate and store your API keys.

Usage data. Every API request is logged with the timestamp, the endpoint, the YouTube URL or video ID you submitted, the requested quality or format, the response status, the credits charged, your API key identifier, your IP address and user agent. Your Dashboard shows part of this as your download history. We also keep aggregate video metadata (title, duration, available formats) for public videos that anyone requested; this is not personal data.

Payment data. When you buy a plan or top up your wallet, our payment processor sends us an order ID, the amount and currency, the payment status, the network and transaction identifier of a cryptocurrency payment, and the payout address you used. We never receive or store card numbers or wallet private keys.

Support data. Emails sent to support@tunelio.dev and messages sent to our Telegram bot, including the address or Telegram account they come from.

Website analytics. The public pages use Google Analytics 4 and Yandex Metrika to understand traffic (pages viewed, approximate location derived from IP, device and browser type, referrer). See the cookies section for how to opt out.

3. Why we use it

  • to provide the Service: authenticate you, serve requests, meter credits and show your history;
  • to bill you and keep our accounting records;
  • to keep the Service secure and fair: detect abuse, leaked keys, fraud and traffic that breaks rate limits;
  • to answer support requests and notify you about your account, incidents or material changes to the Service;
  • to understand how the website is used and improve it.

We do not sell personal data, do not use it for advertising, and do not use your request logs to train models.

4. How long we keep it

  • API request logs and download history: up to 90 days, then deleted or reduced to anonymous aggregates;
  • web-server and security logs: up to 90 days;
  • account data and API keys: for as long as your account exists, then deleted within 30 days of closure;
  • payment and invoicing records: up to 7 years for accounting;
  • support correspondence: up to 24 months after the last message;
  • analytics data: according to the retention settings of the analytics provider (Google Analytics 4: 14 months).

5. Who we share it with

We share personal data only with providers that help us run the Service, under contracts that restrict what they may do with it:

  • infrastructure and hosting providers that operate the servers the Service runs on;
  • our edge and DNS provider, which terminates TLS and protects the website against attacks;
  • our payment processor, which handles cryptocurrency payments and shares payment status with us;
  • Google (Analytics 4) and Yandex (Metrika), which process website analytics on our behalf;
  • Telegram, when you choose to sign in or contact us through Telegram;
  • email delivery infrastructure for transactional messages.

If the Service is sold or merged, your data may be transferred to the new operator under the same commitments.

Some of these providers operate outside your country; each one is bound to protect your data under its contract with us.

6. Cookies

Strictly necessary: a session cookie that keeps you signed in to the Dashboard, and the security cookies set by our edge provider. These cannot be switched off.

Analytics: Google Analytics 4 (cookies beginning with _ga) and Yandex Metrika (cookies beginning with _ym) on the public website. You can block them with your browser’s cookie settings or a content blocker; the Service works without them. Google’s opt-out add-on and Yandex’s opt-out tools are also available.

We do not use advertising cookies or cross-site tracking.

7. Your rights

You can ask us at any time to show you the personal data we hold about you, to correct it, to delete it, to send you a copy, or to stop using it for analytics. You can see and change most account data in the Dashboard; for anything else, email support@tunelio.dev from the address on your account and we will respond within 30 days.

8. Security

All traffic to tunelio.dev is encrypted with TLS. Passwords are stored as salted hashes, API keys are shown once and stored hashed or encrypted, and access to production systems is restricted to the operator’s engineers. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay. Report vulnerabilities via /.well-known/security.txt.

9. Children

The Service is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.

10. Changes to this policy

We update this policy when our practices change. The effective date at the top shows the current version; material changes are announced on this page in advance and, for account holders, by email or Telegram.

11. Contact

Privacy questions and requests: support@tunelio.dev, or the Telegram bot @TunelioDevBot.