Legal
Privacy Policy
Last updated: April 13, 2026
Overview
This Privacy Policy explains what data TLSOps processes, why it is processed, and where responsibility sits across two separate contexts: the self-hosted TLSOps appliance that runs on your hardware, and the TLSOps website and licensing infrastructure used for purchases, license delivery, and license validation.
TLSOps is designed so that your network traffic, DNS activity, and device-level policy data stay on your hardware. The website and licensing service process a much smaller set of account, billing, and security-related data needed to operate the product.
1. Self-Hosted Appliance
TLSOps is a self-hosted application. All network routing, DNS filtering, parental controls, and per-device policy enforcement run on hardware you own or control. TLSOps does not operate a remote control plane, does not receive your DNS query logs, and does not receive device inventory or browsing history from your appliance.
The appliance stores its own telemetry and configuration data locally in an encrypted SQLite database on the appliance host. That local data is accessible through the appliance dashboard and is not transmitted to TLSOps servers as part of normal operation. Retention of locally stored telemetry depends on your active plan and current entitlements.
For data processed locally by your appliance on hardware you control, you are responsible for that environment, including local access control, backups, and any legal obligations that apply to your use of the appliance on your own network.
2. Data TLSOps Processes
2.1 License Validation and Entitlements
When the appliance validates or refreshes a license, it contacts the TLSOps licensing service over HTTPS. The validation flow includes a product identifier, a hardware-bound appliance instance identifier, and a hardware-reset-allowed flag. No DNS query logs, routed traffic contents, or device inventory are included in or returned from this request.
To operate licensing and entitlements, TLSOps stores license-related records such as a hashed license key, plan name, plan status, expiry timestamp, hardware binding information, checkout email identifier, the Stripe customer identifier associated with the subscription, and the IP address of the most recent successful validation request.
2.2 Website, Checkout, and License Delivery
Subscription purchases on the TLSOps website are processed by Stripe. When you complete a checkout session, Stripe collects and processes payment information under Stripe's own privacy and security terms. TLSOps does not receive or store raw card numbers.
Following a successful purchase, TLSOps may process your email address, Stripe customer and subscription identifiers, checkout session identifiers, purchased plan details, and license-delivery status in order to provision and deliver your license key, operate the subscription, and provide customer support.
2.3 Support and Operational Communications
If you contact TLSOps by email, TLSOps will process the information you include in your message, along with the associated email metadata, to respond to your request, troubleshoot issues, and maintain basic support records.
3. Why TLSOps Uses This Data
TLSOps uses website and licensing data to:
- create and maintain subscriptions and license records
- validate licenses and enforce plan entitlements
- deliver license keys and transactional service emails
- prevent fraud, abuse, and unauthorized use of the licensing system
- respond to support requests and account-related inquiries
- comply with legal, accounting, tax, and security obligations
Where applicable law requires a legal basis for processing, TLSOps generally relies on contract performance, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is specifically required.
4. Service Providers
TLSOps uses a limited number of service providers to operate the commercial side of the product. These may include:
- Stripe for checkout, subscription billing, and payment-related events
- Supabase for hosted licensing and subscription records
- SMTP or email delivery providers for transactional license-delivery emails and support-related communication
These providers process data on their own infrastructure and under their own terms and privacy commitments. Depending on the provider and your location, data may be processed in countries other than your own, subject to the safeguards and legal mechanisms used by the provider under applicable law.
5. Cookies and Similar Storage
TLSOps does not use advertising analytics, behavioral tracking, or third-party pixel scripts on the website. The website uses only limited, strictly necessary cookies or similar storage needed for checkout, security, and post-purchase license-delivery flows.
6. Retention and Deletion
Appliance telemetry stored locally on your hardware follows the retention limits associated with your active plan and is removed locally as it ages out or when your appliance falls back to lower retention limits.
Website, billing, and license records are retained for as long as reasonably necessary to operate the subscription, provide support, maintain security, prevent fraud, comply with legal obligations, and resolve disputes. When data is no longer needed for those purposes, TLSOps will delete it or anonymize it where reasonably practicable.
To request deletion of website or license-account data that TLSOps controls, contact support. Some data may need to be retained where required for billing, tax, fraud prevention, legal compliance, or dispute handling.
7. Your Rights
Depending on your location and applicable law, you may have rights to request access to personal data, correction of inaccurate data, deletion, restriction of processing, objection to certain processing, and data portability. You may also have the right to lodge a complaint with your local data protection authority.
To exercise privacy-related rights or make a privacy inquiry, contact support. TLSOps may request reasonable information to verify the request before acting on it.
8. Security
The appliance database is encrypted at rest using SQLCipher. Communication between the appliance, website, and licensing service uses TLS. Stripe handles payment data within PCI-oriented infrastructure. TLSOps also uses access controls and service-level security measures appropriate to the size and nature of the service, but no system can be guaranteed to be completely secure.
9. Contact
Questions about this policy or privacy-related requests can be sent to the support inbox.