BlakTail

Privacy and data handling

Software statement · 23 August 2026

BlakTail is self-hosted. The organisation operating this console controls its deployment and is responsible for its privacy contact, hosting, retention, backups, support access, and legal obligations.

What this deployment processes

  • Account name and email, authentication records, sessions, IP address and user agent, organisation membership, and role.
  • Device names and identifiers, WireGuard public keys, tailnet addresses, endpoints, routes, ACLs, credential hashes and expiry, and administrator audit events.
  • Short-lived relay registrations containing a node identifier and public socket address. Relays forward opaque WireGuard ciphertext; they cannot decrypt tunnel contents.

What BlakTail does not add

No advertising, third-party analytics, tracking pixels, remote fonts, or public-DNS forwarding. The console uses authentication cookies. Runtime logs must never contain private WireGuard keys, raw join keys, node tokens, passwords, or tunnel payloads.

Location and retention

BlakTail is designed for Australian hosting, but the operator must verify the actual locations of databases, logs, backups, DNS, and support systems. Revoked nodes, expired join-key records, and audit events currently have no automatic deletion schedule. Relay registrations expire after 120 seconds idle.

Your choices and contact

Contact the organisation that gave you access to this console to request access, correction, export, deletion, or to make a privacy complaint. That operator must publish its real legal name, contact, retention periods, and subprocessors before public launch.

Maintainers and operators: see the complete deployment data-handling statement.