Privacy Statement — siteaccess.io
Effective date: 2026-07-21 Last updated: 2026-07-21
siteaccess.io ("we", "us", "the Service") provides secure remote network access built on the open-source Tailscale and Headscale software. We take your privacy seriously and we respect it. We are privacy-first by design: we collect only what the Service needs to run, monitor, troubleshoot, and secure it; we keep logs for a short time; and we will never knowingly sell or share your personal information, metadata, usage analytics, or any other information with any third party. This statement explains, honestly and specifically, what that means — including what other systems we rely on can see, because being straight about that is the point.
1. The short version
- Your network traffic is end-to-end encrypted and we cannot read it. Connections use WireGuard encryption between your own devices. When traffic is relayed through our servers, we relay only encrypted data — we do not hold the keys and cannot see its contents.
- We do not run your login. You sign in through your organization's own identity provider (for example Microsoft Entra ID or Google). That provider — not us — handles your password and multi-factor authentication and logs the sign-in under its own policy. We receive only the basic identity details it returns.
- We keep operational logs for 30 days, then they age out. We do not keep long-term logs of your activity.
- We do not sell your data, and we do not share it with third parties for advertising or their own purposes. The only outside services involved are the technical providers listed in Section 5, each used solely to deliver the service.
2. Who this covers
This statement covers people who use siteaccess.io to connect to their organization's network ("end users") and the administrators who manage a siteaccess.io tenant. Your employer or the organization that gave you access may have its own privacy policy governing your use of its network; this statement is about what we do.
3. What we collect, and why
We collect only what is necessary to operate the service:
| What | Why | Example |
|---|---|---|
| Identity details from your provider — a stable user identifier, and (where your provider permits) your email, username, and display name | to create your account and connect you to the right organization's network | sub identifier, you@yourcompany.com |
| Group membership — only if your organization configures it | to apply your organization's access rules | group:engineering |
| Device / node metadata — device name, the internal network address we assign it, its cryptographic public keys, and last-seen time | to route your connection and let your organization manage its devices | laptop-01, assigned tailnet IP |
| Operational logs — connection and request records that include network (IP) addresses, timestamps, and technical details | to keep the service running, investigate problems, and detect abuse | access and connection logs |
We do not collect the contents of your traffic, your browsing history, your files, your passwords, or directory data from your organization beyond the basic identity details above. We do not use tracking cookies or advertising trackers, and we do not build advertising profiles.
4. How long we keep it
- Operational logs: 30 days. Connection, access, and authentication event logs are retained for approximately 30 days and then age out automatically. We keep this window short deliberately — long enough to troubleshoot and investigate a security incident, no longer.
- Account and device records: kept for as long as your account or device is active, and removed when your organization deprovisions you or the device, or on request (Section 8).
5. The technical providers we rely on (subprocessors), and what they can see
We use a small number of technical providers strictly to deliver the service. We do not sell or hand your data to anyone for their own use. Each of these can see only what is described:
- Your identity provider (e.g. Microsoft Entra ID, Google Workspace, or another your organization chooses). Your organization operates this, not us. When you sign in, your provider authenticates you and records the sign-in in your organization's own logs — controlled by your organization's administrators and retained under that provider's policy (for reference, Microsoft Entra retains sign-in logs for roughly 7–30 days depending on license; Google Workspace for about 6 months). We receive only the identity claims your organization allows us to receive. Their handling of your data is governed by that provider's own privacy terms and your organization's configuration.
- Cloudflare — used only as our authoritative DNS provider, configured "DNS-only." Cloudflare answers domain-name lookups for our service but does not route, decrypt, or inspect your VPN or application traffic. It can see DNS lookup metadata (which hostnames are resolved) for a short analytics window.
- Let's Encrypt — issues the TLS certificates that secure our service. As required for all publicly trusted certificates, certificate details are published to public Certificate Transparency logs; we use wildcard certificates so that individual customer names are not exposed in those public logs.
- Our relay (DERP) servers — relay encrypted traffic between devices when a direct connection is not possible. They handle only encrypted data and cannot read your traffic.
We host the core service (the Headscale control server, the Authentik identity broker, and the Traefik gateway) on infrastructure we operate, and we have turned off the optional "phone-home" telemetry those components ship with by default (update checks, usage analytics, and avatar lookups), so no user or usage data is sent from them to their vendors.
6. About the Tailscale client and its logging (honest disclosure)
siteaccess.io uses the open-source Tailscale client on your device, connected to our own control server (not Tailscale's). You should know: by default, the Tailscale client attempts to send its own operational/diagnostic logs to Tailscale's logging service, and this happens even when the client is pointed at our control server. These logs are about the client's own operation and connection attempts, not the contents of your traffic.
Because the client runs on your device, we cannot disable this for you. If you do not want the client to send any diagnostic logs to Tailscale, you can turn it off — our connect instructions and Help page show how (setting TS_NO_LOGS_NO_SUPPORT / --no-logs-no-support). We disclose this rather than hide it, because you deserve to know what your device does by default.
7. What we never do
- We will never knowingly sell your personal information — to anyone, for any price.
- We will never knowingly share your personal information, metadata, usage analytics, or any other information with a third party for their own purposes or for advertising.
- We do not read the contents of your network traffic.
- We do not track your browsing or build advertising profiles.
- We do not monetize your data. Our business is the access service, not your information.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to certain processing. Because your access is usually provided by your organization, some requests are best directed to them (your administrator manages your account and device records). For anything we control directly, contact us at privacy@siteaccess.io and we will respond as required by applicable law. We will verify your identity before acting on a request.
9. Security
We protect the service with end-to-end encryption of traffic, TLS on all web endpoints, least- privilege access to administrative systems, and short log retention. No system is perfectly secure, but we design to minimize the data at risk in the first place.
10. Children
siteaccess.io is a business service and is not directed to children.
11. Changes to this statement
We may update this statement as the service evolves. We will change the "Last updated" date and, for material changes, provide a more prominent notice. Continued use after an update means you accept the revised statement.
12. Contact
Questions or privacy requests: privacy@siteaccess.io.