Tunl

Tunl — Privacy Policy

Last updated: 2026-06-13

Tunl is a WireGuard® VPN client for macOS. It is built so that your data stays on your device and travels only to the VPN servers you configure. This policy explains what that means in practice and what rights you have under the EU General Data Protection Regulation (GDPR) and comparable laws.

Summary

Because the developer never receives any of your data, the developer is not a data controller of any transmitted personal data — there is none. Tunl simply processes your own data, on your own device, at your direction.

What Tunl stores, and where

DataWhere it is storedPurpose
Tunnel configurations, including private keys macOS system VPN preferences (Network Extension, Keychain-backed) Needed to create and run the WireGuard tunnel you imported
Per-tunnel usage totals (bytes sent/received, connected time, last-connected date) Local app storage on your Mac The in-app statistics view
App settings (launch-at-login, Dock icon, auto-reconnect choice) Local app storage on your Mac To remember your preferences

Tunl keeps no browsing history, no DNS logs, no record of the sites or services you reach, and no copy of your keys anywhere off your device.

What Tunl transmits

Diagnostic logs

Tunl writes diagnostic messages to the standard macOS logging system (Console), to help diagnose problems on your own machine. Anything that could identify you or your servers — tunnel names and endpoint host names — is marked private, so it is redacted from logs unless you deliberately enable private-data logging for debugging. These logs are never collected or transmitted.

Purchases

Tunl Premium is sold as an Apple In-App Purchase. Apple, not the developer, processes your payment and subscription under Apple's Privacy Policy. The developer receives only anonymous, aggregated sales reports from Apple and never your payment details or identity.

Permissions Tunl requests

The app is sandboxed and requests no other entitlements.

Your rights (GDPR)

Even though Tunl holds no data about you on the developer's side, you remain in full control of the data on your device:

Since no personal data is transmitted to or held by the developer, there is no data to request from, or have erased by, the developer.

Third-party code

Tunl bundles WireGuardKit (MIT, WireGuard LLC) to implement the WireGuard protocol. It makes no independent network calls.

Children

Tunl is not directed at children and collects no personal information from anyone.

Changes

Any future change to this policy will be published with the app update that introduces it and reflected in the "Last updated" date above.

Contact

Questions or privacy requests: kalle@kalle.works

"WireGuard" is a registered trademark of Jason A. Donenfeld. Tunl is an independent client and is not sponsored by or affiliated with the WireGuard project.