Tunl — Privacy Policy
Last updated: 2026-09-03
Tunl is a WireGuard® VPN client for macOS. It is built so that your data stays on your device and travels only to the VPN servers you configure. This policy explains what that means in practice and what rights you have under the EU General Data Protection Regulation (GDPR) and comparable laws.
Summary
- Tunl collects no personal data and sends nothing to the developer or any third party.
- There are no analytics, no telemetry, no crash reporting, no advertising, no tracking, and no user accounts.
- Everything Tunl stores stays on your Mac.
Because the developer never receives any of your data, the developer is not a data controller of any transmitted personal data — there is none. Tunl simply processes your own data, on your own device, at your direction.
What Tunl stores, and where
| Data | Where it is stored | Purpose |
|---|---|---|
| Tunnel configurations, including private keys | macOS system VPN preferences (Network Extension, Keychain-backed) | Needed to create and run the WireGuard tunnel you imported |
| Per-tunnel usage totals (bytes sent/received, connected time, last-connected date) | Local app storage on your Mac | The in-app statistics view |
| Connection history (when each tunnel connected, stalled, or was repaired; kept 30 days, 250 events) | Local app storage on your Mac | The in-app history view and the diagnostics report |
| App settings (launch-at-login, Dock icon, auto-reconnect choice) | Local app storage on your Mac | To remember your preferences |
Tunl keeps no browsing history, no DNS logs, no record of the sites or services you reach, and no copy of your keys anywhere off your device.
What Tunl transmits
- The app itself makes no outbound network connections of its own.
- When you connect a tunnel, your network traffic is carried over WireGuard to the endpoint in your configuration. The developer operates no servers and can see none of this traffic.
- Two features send packets of their own, and both are addressed only to the server in your own configuration: the liveness probe (an ICMP echo to the tunnel's gateway, or a DNS query to the resolver you configured, which also produces the latency readout), and, when protection on untrusted networks is on and the tunnel fails to come up, a single connection attempt to your endpoint's own address and port, to tell a network that blocks the tunnel from a server that is not answering. Neither ever contacts a third party, and neither runs while the tunnel is working.
The diagnostics report
Settings has a Show Diagnostics action that assembles a plain-text summary of the app's state and the recent connection history. It is shown to you in full before anything happens to it, and it is only copied to the clipboard if you ask for it — Tunl never transmits it. Tunnel names are replaced with placeholders ("tunnel 1"), and endpoints, IP addresses and keys are left out entirely, so the report stays safe to paste into an email.
Notifications
If you turn on Notify me when a tunnel is in trouble, macOS asks for notification permission at that moment, not at first launch. The notifications are generated on your Mac and name only the tunnel involved; nothing is sent to any server.
Diagnostic logs
Tunl writes diagnostic messages to the standard macOS logging system (Console), to help diagnose problems on your own machine. Anything that could identify you or your servers — tunnel names and endpoint host names — is marked private, so it is redacted from logs unless you deliberately enable private-data logging for debugging. These logs are never collected or transmitted.
Purchases
Tunl Premium is sold as an Apple In-App Purchase. Apple, not the developer, processes your payment and subscription under Apple's Privacy Policy. The developer receives only anonymous, aggregated sales reports from Apple and never your payment details or identity.
Permissions Tunl requests
- VPN configuration / Network Extension — required to create and run the WireGuard tunnel. This is the core function of the app.
- Access to files you choose — only to read a
.conffile when you import one, or write one when you export. Tunl has no broad file access.
The app is sandboxed and requests no other entitlements.
Your rights (GDPR)
Even though Tunl holds no data about you on the developer's side, you remain in full control of the data on your device:
- Access & portability — your configurations are
yours; export any tunnel to a standard
.conffile at any time. - Erasure — remove a tunnel to delete it and its stored statistics and history, or use Settings → Privacy → Clear Statistics and History to erase all stored usage totals and connection history. Deleting the app removes everything it stored.
- Rectification — edit a tunnel's configuration in the app whenever you like.
- No automated decision-making or profiling takes place.
Since no personal data is transmitted to or held by the developer, there is no data to request from, or have erased by, the developer.
Third-party code
Tunl bundles WireGuardKit (MIT, WireGuard LLC) to implement the WireGuard protocol. It makes no independent network calls.
Children
Tunl is not directed at children and collects no personal information from anyone.
Changes
Any future change to this policy will be published with the app update that introduces it and reflected in the "Last updated" date above.
Contact
Questions or privacy requests: [email protected]
"WireGuard" is a registered trademark of Jason A. Donenfeld. Tunl is an independent client and is not sponsored by or affiliated with the WireGuard project.