Privacy Policy
Pilot version — 2026-09-04. This is the document referenced in the desktop app's Terms of Service. See the note at the bottom about its status.
The short version
We collect what's needed to route traffic, compute earnings, and keep the network safe — nothing about the content of what's routed. We don't sell your data. Contributors' upload bandwidth carries buyers' traffic without either side learning who the other is.
What we collect, and why
What we collect differs depending on which side of the network you're on:
| If you're a buyer | Why |
|---|---|
| Email address | Account identity, login, contact |
| API key (stored as a hash, never in plaintext) | Authenticating your session requests |
| Bandwidth used (bytes, counted by our relay server — never self-reported by your client) | Quota enforcement, billing |
| KYC verification status (verified/unverified) | Raising your bandwidth cap past the unverified limit |
| If you're a contributor | Why |
|---|---|
| A randomly-generated device identifier | Distinguishing your install from others — not tied to your identity unless you link a payout account |
| Public IPv4/IPv6 address, as seen by our own Cloudflare-based network probe | Letting buyers target sessions by rough location; visible to us, never to buyers directly |
| Approximate location (country), derived the same way | Session targeting |
| Measured upload/download speed, connection type | Deciding whether your connection is healthy enough to carry a session |
| Bytes relayed through your connection (counted by our relay server) | Computing what you've earned |
| Terms of Service version and acceptance timestamp | A durable record that you agreed to the terms in effect |
| If you link a payout account: an email address | Identifying who to pay |
What we don't collect
- The content of relayed traffic. Sessions between a buyer and a contributor's node carry TLS-encrypted connections end to end — the relay pipes bytes without ever decrypting or inspecting them. We can't see what's inside, and neither can either side of the network see who's on the other end.
- Browsing history, or anything else outside what's listed above. The desktop app doesn't monitor anything on a contributor's machine beyond the network diagnostics above.
Where data lives, locally
Some of the data above is stored on your own device, not (only) on our servers:
- Buyer console (browser): your API key is stored in your browser's
localStorageso you stay logged in; an admin secret, for the admin panel specifically, is stored insessionStorageand clears when the tab closes. - Desktop app: your device identifier, a payout account key (if linked), and your Terms of Service acceptance are stored in local files in the app's own data directory on your machine.
Who we share data with
We run on Cloudflare's infrastructure (Workers, D1, Pages) — they process data as our infrastructure provider, under their own terms, not as an independent party we've handed your data to for their own use. We don't sell data to anyone, and we don't share buyer or contributor identities with each other — that separation is the architecture, not just a policy.
How long we keep it
Account and usage records are kept for as long as your account is active. Admin action logs (every create/revoke/reissue on a buyer account, and every payout resolution) are kept as an audit trail, not on a fixed deletion schedule during this pilot. If you close your account, email us and we'll delete what we can — some records (e.g. a resolved payout's amount, for our own accounting) may need to be kept regardless.
Your choices
- Contributors: pause sharing any time from the tray icon — it takes effect immediately. Disconnecting a payout account stops tying your node to that account, though the node keeps sharing (if not paused) and simply stops earning until reconnected.
- Everyone: email hello@meowbyte.net to ask what we hold about you, correct it, or ask us to delete your account.
Changes to this policy
We may update this policy as the product changes. Material changes will be reflected here with an updated date at the top.
A note on this document's status
This is a real, substantive privacy policy — written to accurately describe what the system actually collects, not filler — but it hasn't been reviewed by a lawyer. Treat it as a strong starting point, not a substitute for real legal review before this product handles data at a scale or in jurisdictions where that review actually matters (GDPR/CCPA-style specifics in particular aren't addressed here yet).
Contact
Questions about this policy: hello@meowbyte.net