Privacy Statement — siteaccess.io

Effective date: 2026-07-21 Last updated: 2026-07-21

siteaccess.io ("we", "us", "the Service") provides secure remote network access built on the open-source Tailscale and Headscale software. We take your privacy seriously and we respect it. We are privacy-first by design: we collect only what the Service needs to run, monitor, troubleshoot, and secure it; we keep logs for a short time; and we will never knowingly sell or share your personal information, metadata, usage analytics, or any other information with any third party. This statement explains, honestly and specifically, what that means — including what other systems we rely on can see, because being straight about that is the point.

1. The short version

2. Who this covers

This statement covers people who use siteaccess.io to connect to their organization's network ("end users") and the administrators who manage a siteaccess.io tenant. Your employer or the organization that gave you access may have its own privacy policy governing your use of its network; this statement is about what we do.

3. What we collect, and why

We collect only what is necessary to operate the service:

WhatWhyExample
Identity details from your provider — a stable user identifier, and (where your provider permits) your email, username, and display nameto create your account and connect you to the right organization's networksub identifier, you@yourcompany.com
Group membership — only if your organization configures itto apply your organization's access rulesgroup:engineering
Device / node metadata — device name, the internal network address we assign it, its cryptographic public keys, and last-seen timeto route your connection and let your organization manage its deviceslaptop-01, assigned tailnet IP
Operational logs — connection and request records that include network (IP) addresses, timestamps, and technical detailsto keep the service running, investigate problems, and detect abuseaccess and connection logs

We do not collect the contents of your traffic, your browsing history, your files, your passwords, or directory data from your organization beyond the basic identity details above. We do not use tracking cookies or advertising trackers, and we do not build advertising profiles.

4. How long we keep it

5. The technical providers we rely on (subprocessors), and what they can see

We use a small number of technical providers strictly to deliver the service. We do not sell or hand your data to anyone for their own use. Each of these can see only what is described:

We host the core service (the Headscale control server, the Authentik identity broker, and the Traefik gateway) on infrastructure we operate, and we have turned off the optional "phone-home" telemetry those components ship with by default (update checks, usage analytics, and avatar lookups), so no user or usage data is sent from them to their vendors.

6. About the Tailscale client and its logging (honest disclosure)

siteaccess.io uses the open-source Tailscale client on your device, connected to our own control server (not Tailscale's). You should know: by default, the Tailscale client attempts to send its own operational/diagnostic logs to Tailscale's logging service, and this happens even when the client is pointed at our control server. These logs are about the client's own operation and connection attempts, not the contents of your traffic.

Because the client runs on your device, we cannot disable this for you. If you do not want the client to send any diagnostic logs to Tailscale, you can turn it off — our connect instructions and Help page show how (setting TS_NO_LOGS_NO_SUPPORT / --no-logs-no-support). We disclose this rather than hide it, because you deserve to know what your device does by default.

7. What we never do

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to certain processing. Because your access is usually provided by your organization, some requests are best directed to them (your administrator manages your account and device records). For anything we control directly, contact us at privacy@siteaccess.io and we will respond as required by applicable law. We will verify your identity before acting on a request.

9. Security

We protect the service with end-to-end encryption of traffic, TLS on all web endpoints, least- privilege access to administrative systems, and short log retention. No system is perfectly secure, but we design to minimize the data at risk in the first place.

10. Children

siteaccess.io is a business service and is not directed to children.

11. Changes to this statement

We may update this statement as the service evolves. We will change the "Last updated" date and, for material changes, provide a more prominent notice. Continued use after an update means you accept the revised statement.

12. Contact

Questions or privacy requests: privacy@siteaccess.io.