Privacy Policy

Last updated: September 2026

1. Overview

This Privacy Policy explains how AirLane ("we") collects, uses and protects your information when you use the AirLane client, website (airlane.cloud and its subdomains) and cloud services.

AirLane is "local-first": proxying, policies, rule evaluation and traffic processing all run on your device. We cannot see your proxied traffic.

2. Data we collect

Anonymous identity: creating an anonymous account generates a random identity ID and stores SHA-256 hashes of the access token and login code — never plaintext. No email required.

Full account: your email address (for sign-in and account notifications). When signing in via Google or other providers, we receive the email and basic profile they return.

Device info: when pairing a client device we store its name, platform, client version and last-seen time.

Cloud data: features you enable (Mesh group memberships, config snapshots) are stored at your direction.

Human verification: anonymous account creation uses Cloudflare Turnstile, processed by Cloudflare under its own privacy policy.

3. Data we do not collect

We do not log proxied traffic contents, visited websites or DNS query details.

Rule evaluation, policy decisions and traffic forwarding run locally; decision logs stay on your device by default.

We never upload local config files without your explicit action.

4. Storage & third-party services

Account and identity data is stored in a Supabase-hosted PostgreSQL database.

The website is hosted on Vercel; access logs are handled under Vercel's privacy policy.

Sign-in may use Google OAuth, subject to Google's terms and privacy policy.

Human verification uses Cloudflare Turnstile.

5. Cookies & local storage

We use browser localStorage for your sign-in session and anonymous access token — not for tracking or advertising.

The site does not use third-party advertising cookies.

6. Your rights

You can view your identity ID, device list and quota usage in the account center.

You can end an anonymous session at any time (deleting the cloud identity and its data) or contact us to delete a full account.

Anonymous login codes are held only by you; we cannot recover a lost code.

7. Data retention

Anonymous access tokens may expire after 90 days of inactivity; the login code can reactivate the identity at any time.

Full account data is kept while the account is active; associated data is removed within a reasonable period after deletion.

8. Changes

We may update this policy from time to time. Material changes will be posted on this site. Continued use constitutes acceptance.

9. Contact

Questions about this policy: [email protected].

Terms of Service →