legal

Privacy Policy

This Privacy Policy explains how Varhal Tunnel collects, uses, shares, protects, and retains information when you use varhal.com, the Varhal Dashboard, the Varhal client, tunnel configuration files, APIs, and related services.

Effective date: July 25, 2026

1. Who We Are

Varhal Tunnel provides localhost tunneling for HTTPS, TCP, and UDP services. In this policy, "Varhal", "we", "us", and "our" refer to the operator of the Varhal Tunnel service. You can contact us at [email protected] for privacy requests, security concerns, and data protection questions.

2. Information We Collect

CategoryExamplesPurpose
Account dataUsername, optional email address, password hash, account status, creation time.Create accounts, authenticate users, prevent abuse, provide support.
Tunnel dataProtocol, subdomain, assigned TCP/UDP port, target host and port, tunnel status, node ID.Create, route, monitor, troubleshoot, and secure tunnels.
CredentialsHashed tunnel tokens, temporary plain token display, frp metadata token, session cookie.Authenticate clients, reject unauthorized tunnels, let users rotate leaked keys.
Usage and metering dataDaily bytes in/out, tunnel traffic totals, quota status, connection status.Show usage, enforce free limits, detect overload, operate fair-use controls.
Security and operational logsIP address, user agent, login events, registration events, error logs, abuse signals.Protect the service, investigate abuse, debug outages, prevent duplicate or fraudulent accounts.
Tunnel content in transitTraffic passing through HTTPS, TCP, or UDP tunnels.Transmit packets between the public endpoint and your local client. We do not use tunnel content for advertising.

3. How We Use Information

  • Provide public tunnel endpoints and route traffic to your authenticated Varhal client.
  • Authenticate users, sessions, tunnel tokens, and frp client connections.
  • Display Dashboard information such as tunnel status, public address, quota, and traffic usage.
  • Prevent spam, malware, phishing, credential theft, proxy resale, scanning, denial of service, and other abuse.
  • Maintain service reliability, debug incidents, measure capacity, and improve product functionality.
  • Comply with applicable law, enforce our Terms, and respond to lawful legal requests.

4. Legal Bases for EEA and UK Users

Where GDPR or UK GDPR applies, we process personal data under these legal bases: performance of a contract to provide the tunnel service; legitimate interests in security, abuse prevention, reliability, and product improvement; legal obligations when we must retain or disclose information; and consent where required for optional communications or non-essential cookies.

5. Cookies and Local Storage

Varhal uses essential cookies for login sessions, account security, and recently generated token display. The language selector may store your preferred language in the browser. We do not need cross-site advertising cookies to operate the service.

6. Sharing and Subprocessors

We do not sell personal information. We may share information with infrastructure, hosting, DNS, security, analytics, email, storage, payment, and support providers when needed to operate Varhal. Providers may process data only for the services they provide to us. We may disclose information if required by law, to protect users or the service, or in connection with a merger, acquisition, financing, or sale of assets.

7. International Transfers

Varhal is a global service. Your information may be processed in countries other than where you live. When legally required, we use appropriate safeguards such as contractual protections, security controls, and transfer assessments for international processing.

8. Data Retention

DataTypical retention
Account and tunnel recordsFor the life of the account, then deleted or anonymized unless needed for legal, security, or abuse reasons.
Usage countersRetained while needed for quota enforcement, billing readiness, abuse prevention, and operational reporting.
Security logs and audit eventsRetained as long as reasonably needed to protect the service, investigate abuse, and meet legal obligations.
Temporary plain tokensShown only for a short setup window where possible. Users should rotate keys if a config leaks.

9. Security

We use access controls, hashed passwords, token-based client authentication, operational monitoring, rate limits, and abuse controls. No internet service can guarantee perfect security. You should avoid sending secrets, regulated production data, or highly sensitive content through free development tunnels unless you have independently assessed the risk and protected the traffic end to end.

10. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal information. EEA and UK users may also lodge a complaint with a data protection authority. California and other US state privacy laws may provide rights to know, delete, correct, access, portability, opt out of certain sharing or targeted advertising, limit use of sensitive information, and not be discriminated against for exercising privacy rights.

To exercise rights, contact [email protected]. We may need to verify your identity and account ownership before fulfilling a request. We will respond within the time required by applicable law.

11. California Notice

In the last 12 months, Varhal may have collected identifiers, internet or network activity, commercial or account activity, approximate location derived from IP address, and inferences related to service security or abuse prevention. We collect this information for the business purposes described in this policy. We do not sell personal information for money. If we ever introduce activity that qualifies as "sale" or "sharing" under California law, we will provide the required notice and opt-out mechanism.

12. Children

Varhal is not intended for children under 13, and it is not directed to children under 16 in the EEA or UK. If you believe a child provided personal information to Varhal, contact [email protected] so we can review and delete it where required.

13. Abuse, Law Enforcement, and Emergency Requests

Tunnels can expose public endpoints. We may suspend tunnels, preserve relevant records, or disclose limited information when we believe it is necessary to prevent abuse, protect users, secure the service, comply with legal process, or respond to emergencies involving risk of harm.

14. Changes

We may update this policy as Varhal changes. Material changes will be reflected by updating the effective date and, when appropriate, by providing additional notice in the Dashboard or on varhal.com.

15. Contact

Privacy requests: [email protected]. Security reports: [email protected]. Abuse reports: [email protected].

Privacy Policy | Varhal Tunnel