Privacy Policy
Localport is built on a simple promise: your traffic is yours. We collect the minimum information needed to run the service, we hold it for the shortest time we reasonably can, and we apply the GDPR, the UK GDPR, the CCPA, and the other data protection laws that apply where you live. While a tunnel is active, the traffic flowing through it does not leave the region you selected for that tunnel, and the account and operational data we store to run the service is held in the European Union. This policy is the detail behind those promises.
Last updated: September 2, 2026
1. Who We Are
Localport is a product operated by Masteren Labs, a sole proprietary concern based in India ("Masteren Labs," "Localport," "we," "us"). When you use Localport, we act as the controller of the account, billing, and operational data described below. Two kinds of data are different: the records a team accumulates for its own use, described in Section 5, which we process on the team's behalf, and whatever you choose to route through a tunnel, which stays your responsibility. When you expose your own application through Localport, that application and its users remain yours. We do not act as a controller for the content of your traffic.
2. Scope
This policy covers https://localport.io, the Localport dashboard, our APIs, the Localport CLI, our edge network, tunnel domains, billing flows, and support channels. It does not cover third-party sites or services you connect to or link from Localport. Those are governed by their own notices.
3. What We Collect
Account
Your email, name, the login method you chose, and session state. If you verify your email, we record that. If you sign in through a third-party identity provider such as Google, we receive your email address and name from that provider and nothing more than the sign-in requires. If a team admin invites you, we receive your email address from them in order to deliver the invitation.
Teams and members
Team names, member roles, invitations, ownership, and account status.
Tunnel configuration
The names, identifiers, kinds, regions, subdomains, reserved ports, custom domains, IP allowlists, access grants, and access tokens you create. We store hashes of tokens. The raw value is shown to you once at creation and is not retained on our side.
Operational records
Connection counts, bytes transferred, request counts, session start and end times, edge region, the version of the agent that opened a tunnel, disconnect reasons, and other connection metadata needed to run the service, enforce plan limits, and respond to abuse. We do not record the contents of your requests or responses as part of normal operation.
Remote access credentials
Remote access is built on client certificates (mutual TLS): a device in a fleet can be reached only by someone presenting a certificate your team trusts. We store what is needed to issue and verify those credentials, never the credentials themselves. That means the certificate authorities your team relies on, the metadata of every certificate issued or recognised (issuer, subject, serial, expiry, status), revocation entries, and setup keys, stored as hashes. The private key of a client certificate is created on your own device, in the dashboard or by the Localport agent, and never reaches us; we receive only a signing request. Where we operate an authority on your team's behalf, its signing key is held encrypted and used only to issue your team's certificates. If you register your own certificate authority, we store its public certificate and the address of its revocation list. If a certificate is issued to a CI job through OIDC, we verify the short-lived token your CI platform minted and store no secret from it. A certificate issued to a person names a random account identifier, never their email address, so the credential itself carries no contact details. The record of who reached what is your team's access log, described in Section 5.
Billing
Your plan, subscription status, renewal date, the customer and subscription identifiers given to us by the payment provider, invoice references, bandwidth and usage totals, and billing contact details. Card numbers and CVV codes never reach our servers. They go directly to the payment provider.
Website and product events
When you visit our website or dashboard, our servers see the standard metadata any web request carries. Website page views are measured server side against a pseudonymous identifier; no analytics script runs in your browser and no tracking cookie is set. Inside the dashboard we record how you move through the product and events tied to your account, such as signing in, creating a tunnel, changing a plan, and errors you hit, so we can tell whether the product works and where it breaks. This measurement exists to operate Localport. We do not run advertising trackers and we do not profile you for ads.
Support
If you write to us, we keep your message, our reply, and anything you attached.
4. Tunnel Traffic
Tunnel traffic is what flows through Localport between the public internet and your client or service. We treat it as transit. We do not log payloads, build search indexes over them, sell them, hand them to advertisers, or use them to train models.
How much of a request our infrastructure ever sees depends on the tunnel mode you pick:
- TCP and TLS passthrough. Bytes are forwarded. We do not have the keys and we do not inspect the payload.
- HTTP. The edge reads the routing information needed to send the request to the right tunnel. The body is forwarded.
- HTTPS termination and remote access. The edge holds the TLS certificate so it can provide HTTPS or verify client certificates. A request is decrypted in the edge's memory only long enough to be forwarded, is re-encrypted on the connection to your agent, and is never written to disk.
In every mode, the connection between the Localport agent on your machine and our edge is itself encrypted with TLS, so traffic between you and Localport never travels unprotected. We record only the operational metadata listed in Section 3: counts, sizes, timestamps, and addresses. This is the minimum we need to bill, to keep the platform up, and to push back on abuse.
Localport does not provide malware scanning, antivirus inspection, content filtering, web application firewall services, or moderation of what you send through your tunnel. We do not detect, classify, sanitize, or block hostile traffic aimed at your service. You are responsible for what runs behind your tunnel.
If you visit a service running behind a tunnel
Someone else's application served through a Localport address belongs to the person or team operating it, and they decide what it does with your data. On our side, your visit appears only as the connection metadata described above and, where the service uses remote access, as an entry in the operating team's access log. For anything the application itself collects, contact its operator.
5. Your Team's Records
Some of what we store exists for your team rather than for us. These records give a team visibility into its own account, and we hold them on the team's behalf, under the team's control, for as long as the team's plan provides.
Audit log
Teams on plans that include it get an audit log of the administrative actions their own members take: who invited a member, who rotated a token, who changed an access grant, and when. An entry names the member who acted, the change they made, the outcome, and the IP address and browser the request came from. It carries nothing from your traffic.
The log belongs to the team, and it is a rolling window, not a permanent archive. Only your admins can read it, your plan sets how far back it reaches, older entries age out for good on the schedule in Section 9, and the whole log is deleted with the team. After 90 days we strip the network address from an entry; everything else remains, so the trail stays complete without holding personal data longer than it is needed. We store the log, serve it to your admins, and make no other use of it.
Access log
Teams using remote access get an access log: who reached which device, from where, and whether the connection was allowed or refused. An entry records the identity presented, the certificate used, the device reached, the source IP address, and the time. Traffic is never inspected, so no entry records what was sent. This is the team's record of who reached its infrastructure, readable by its admins for the window the plan provides.
Our role
For the records in this section, your team decides who may read them and how they are used; we process them to store them, serve them back, and enforce the retention your plan sets. We do not read them to profile your members and we do not use them for advertising. Teams that need a signed Data Processing Addendum for their own compliance can request one at privacy@localport.io.
6. How We Use Data
- Run the service. Sign you in, create tunnels, route traffic, charge subscriptions, and send service email.
- Keep the platform healthy. Measure load, diagnose outages, investigate abuse, and defend the network.
- Enforce plans. Count bandwidth and tunnels, apply limits, and handle overages.
- Give your team visibility. Store the audit log and access log described in Section 5 and serve them back to your admins.
- Talk to you. Answer support requests and send security and billing notices.
- Comply with law. Respond to lawful requests, defend ourselves in disputes, and preserve records we are required to keep.
We may occasionally send product news. Every such email carries a one-click unsubscribe, and opting out never affects security, billing, or account email. We do not use your account data, your tunnel metadata, or your traffic for advertising. We do not sell personal data. We do not feed your traffic into machine learning systems.
7. Cookies and Local Storage
The marketing website sets no cookies. The dashboard uses strictly necessary cookies to keep you signed in; interface preferences such as your theme live in your browser's local storage and stay on your device. Neither site sets advertising or cross-site tracking cookies, so there is no cookie banner because there is nothing to consent to.
8. Who We Share With
We share personal data only where it is needed to run Localport or where the law requires it. The categories are short:
- Infrastructure providers that host our servers, databases, and edge network.
- Our payment provider, which acts as the merchant of record for checkout, subscriptions, tax, and invoices, and receives your payment details directly.
- Email delivery for one-time codes, account, billing, security, and support email.
- Professional advisers such as accountants, lawyers, and auditors, where their work requires it, bound by confidentiality.
- Law enforcement and authorities when required by valid legal process, or to protect rights, users, and the public.
- An acquirer in the event of a merger, financing, restructuring, or sale of the business.
If you sign in with an identity provider such as Google, you authenticate with them directly. They learn that you use Localport because you chose them for sign-in; we send them nothing else about you.
We do not share data with advertising networks. We do not enrich your profile from third-party data brokers.
9. Retention
- Account and team data is kept while your account is open.
- Tunnel configuration is kept while it is in use and removed shortly after deletion, subject to backup rotation.
- Connection and session records are kept for security, abuse investigation, and billing disputes. The IP address in them is removed within twelve months, and per-session usage detail is deleted within six months.
- Audit log entries are readable for the window your plan provides and are permanently deleted after 400 days at the latest. The IP address on an entry is removed after 90 days. The whole log is deleted with the team.
- Access log entries follow the same bounds: readable for your plan's window, permanently deleted after 400 days at the latest.
- Short-lived abuse counters, such as failed connection attempts, are deleted within 30 days.
- Billing and tax records are kept for as long as tax law requires, typically up to seven years.
- Support correspondence is kept while it is useful and then removed on normal business retention.
- Backups are overwritten on their normal rotation.
When data is no longer needed, we delete it, aggregate it, or strip identifiers.
If your account or team is suspended for suspected abuse, fraud, security risk, or breach of the Terms, we will hold the account, its data, and related records under the retention periods above while we investigate, while a dispute or chargeback is open, and for as long as we may need them to defend ourselves, cooperate with law enforcement, or respond to a regulator. Suspension does not, on its own, trigger deletion.
10. Security
We use encryption in transit, hashed or encrypted credentials at rest, scoped access for engineers, isolated tenancy at the network layer, and monitoring across the platform. Production access is limited and audited. Where applicable law requires us to notify affected users of a security incident, we will do so on the timeline that law sets.
No service over the internet is perfect, and the controls described in this section are not a representation that the service or any data within it cannot be compromised. You are responsible for the security of anything you choose to expose, including patching, authentication, monitoring, and incident response. If you believe you have found a vulnerability in Localport itself, write to security@localport.io and give us a fair opportunity to respond before disclosing it elsewhere.
11. Data Residency and International Transfers
While a tunnel is active, its traffic stays in the region you selected. Each tunnel is anchored to an edge in the region chosen at creation, the client establishes its session with that edge, and the bytes that flow between the public internet and your service pass through that edge only. We do not relay an active tunnel's traffic through another region, we do not mirror it to another region, and we do not copy it into the systems that run the dashboard, billing, or backups.
The personal data we hold to run Localport is stored in the European Union. This includes your account, your teams, your billing records, your tunnel configuration, and the operational records described in Section 3, including the records relating to tunnels you choose to run in any region. Where we store this data does not change with the region a tunnel uses. Backups are stored in the European Union as well.
A limited number of the service providers we rely on, such as our payment processor, our email provider, and any identity provider you use to sign in, may process the data they need outside the European Union. Localport is operated from India, and our personnel may access data held in the European Union in order to operate and support the service. Where personal data is transferred across a border, we rely on the legal mechanisms recognised under applicable law, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply. We do not transfer personal data to a jurisdiction that lacks an adequate level of protection unless one of those mechanisms is in place or the transfer is otherwise lawful under the law that protects you.
12. Your Rights Under Privacy Law
We honour the rights given to you by the data protection law that applies where you live. If your processing falls under the GDPR or the UK GDPR, that includes the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where consent is the legal basis. Our lawful bases include contract performance, legitimate interests in operating and securing the service, compliance with legal obligations, and your consent where consent is required.
If you are a California resident covered by the CCPA, you have the rights to know, delete, correct, and limit the use of sensitive personal information, and the right to non discrimination for exercising those rights. Localport does not sell personal information, does not share it for cross context behavioural advertising, and does not process sensitive personal information for inferring characteristics about you. Because we do not sell or share personal information, a Global Privacy Control signal asks for a protection you already have; we honour it by default.
To exercise any of these rights, email privacy@localport.io from the address on your account. We may ask you to verify your identity before we act. We will respond within the timelines that the applicable law requires. You also have the right to complain to the data protection authority in your country, although we would prefer that you write to us first so we can put the issue right.
We are required to keep some records, including those related to billing, fraud, security, and legal matters. Those will remain on file for the periods set out in Section 9, even after the rest of your data is removed.
13. Children
Localport is not intended for anyone under 18, and we do not knowingly collect data from minors. If you believe a child has signed up, write to privacy@localport.io and we will remove the account.
14. Account Deletion
You can schedule account deletion from the dashboard. There is a short grace period, currently 24 hours, during which you can change your mind and cancel the deletion. After that, the account, its teams (where you are the sole owner), tunnels, and tokens are removed.
- Cancel any active paid subscription before deleting. Deletion does not refund a paid period that is already running.
- Billing, tax, fraud, security, audit, legal, and backup records may be retained as described in Section 9.
- Deletion is final once the grace period closes.
15. Changes
We will update this policy when the service or the law changes. Material changes will be announced by email, by dashboard notice, or on this page. The "Last updated" date at the top is the authoritative version.
16. Contact
Masteren Labs (sole proprietary concern, India)
Privacy: privacy@localport.io
Security: security@localport.io
Grievance: grievance@localport.io
Support: support@localport.io
Website: https://localport.io
Company: masterenlabs.com