1. Who operates Tenelk
Tenelk is operated by PAN HAO, an independent software developer. Privacy questions and requests can be sent to support@tenelk.cloud.
2. Information we collect
Depending on the feature you use, Tenelk may process:
- Account information: email address, account identifier, language, and subscription status.
- Purchase information: plan, amount, currency, transaction reference, renewal status, and refund status. We do not store full payment-card details.
- Software information: app version, operating system, device category, activation state, and limited technical diagnostics needed to operate or troubleshoot the software.
- Support information: messages, attachments you choose to send, and records required to resolve the request.
- Website information: essential server logs used for security and reliability. The initial website does not use advertising trackers.
3. Tenelk VPN Chrome extension
Tenelk VPN applies an account-authorized proxy connection only to Chrome. Before login or connection, the extension asks you to confirm that website requests selected by Rules or Global mode will be transmitted through the Tenelk service to provide the connection you requested. Local Direct mode clears the Tenelk browser proxy setting.
- Account session: access tokens and short-lived proxy credentials are kept in Chrome session storage and are cleared when that browser session ends. A rotating refresh token is kept in Chrome local storage, restricted to trusted extension contexts, so the extension can restore your sign-in after Chrome restarts. It is replaced when renewed and removed when you sign out, the session becomes invalid, extension data is cleared, or the extension is uninstalled. Access and refresh tokens are sent only to Tenelk Account for sign-in, renewal, authorization, lease issuance, and revocation. Short-lived proxy credentials are sent only to the Tenelk gateway and Account validation service to authenticate the active lease. Successful validation may be cached under a keyed hash in volatile memory for up to 30 seconds and never beyond lease expiry. The extension does not request your account password.
- Account response: the Tenelk Account response may contain identity fields such as username, display name, and locale. The extension decodes that response transiently, immediately keeps only the product and access authorization it needs, and does not store, return, or display those identity fields.
- Installation identifier: a random, non-hardware identifier is stored locally to bind and rotate the account session for this extension installation. It remains after sign-out and is removed when extension data is cleared or the extension is uninstalled.
- Local settings and diagnostics: Chrome local storage contains the connection mode, rule-domain list, cached account-managed route catalog and selection, disclosure time, connection status, errors, counters and timestamps, exit-check region, latency and time, route-health measurements and failure counts, and recent automatic-switch timestamps and reasons. These records remain until overwritten, extension data is cleared, or the extension is uninstalled.
- Proxy authentication: website-access and web-request permissions are used only to answer a proxy authentication challenge when its host, port, and realm match the active Tenelk lease. They are not used to collect website passwords.
- Route health: the background worker requests only each account-managed gateway's fixed health path and stores aggregate latency, status, consecutive failure count, and timestamps locally. It does not send visited URLs, browsing history, account tokens, or proxy credentials with this check.
- Connection proof: the extension may request Cloudflare Trace without cookies after connection or when you ask it to verify the route. It stores only the observed region code, latency, and check time, and does not retain the returned IP address.
- Browsing data: to route HTTPS traffic, the service processes the destination hostname or IP address and port needed to establish a CONNECT tunnel, then relays encrypted tunnel bytes without decrypting page content. For unencrypted HTTP traffic, the service transiently relays the full request URL, request headers and body, and response headers and body, which may include page or form content. The browser-gateway process relays this traffic in memory and does not write the destination, request, or response content to application logs or persistent storage. Tenelk does not use it for advertising, analytics, profiling, or sale.
- Abuse prevention: the gateway processes the connecting client IP address and an in-memory failure counter to limit repeated failed proxy authentication. This limiter state is not written to persistent storage.
Disconnecting or signing out first disables proxy authentication and asks Chrome to clear the local browser proxy, then asks the service to revoke the current short-lived lease. A local cleanup failure is shown to the user. If only the service request fails, the credential expires at the end of its maximum 10-minute lifetime. The extension contains no advertising and does not collect payment-card details.
Chrome Web Store Limited Use
Tenelk VPN's use and transfer of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Information accessed through extension permissions is used only to provide or improve the user-facing browser proxy connection, including its maintenance and security. It is transferred only when necessary to provide or improve that feature, comply with applicable law, protect against malware, spam, phishing, fraud, or other abuse, or, after obtaining the user's explicit prior consent, as part of a merger, acquisition, or sale of assets. It is never sold or transferred to advertising platforms, data brokers, or information resellers, and is never used or transferred for personalized advertising, creditworthiness, lending, or unrelated profiling. It is not made available for human review except with the user's explicit consent to review specific data, when necessary for security or legal compliance, or after aggregation and anonymization for internal operations.
4. Tenelk Tab Chrome extension
Tenelk Tab replaces Chrome's new-tab page with a local-first surface for search, shortcuts, Daily Focus, recent activity, voice search, image search, language choice, and visual preferences. It contains no advertising, analytics, telemetry, or remotely executed code.
- Local settings and activity: Chrome local extension storage contains shortcuts, theme, accent color, language choice, shortcut visibility and source, optional background image, footer and card preferences, Daily Focus items for the current local day, and activity opened from Tenelk Tab. It does not store a search-provider preference. Versions with workspace features, including v0.6.0, also store website categories and folders, note titles and bodies, countdown titles and dates, reusable text, the selected category, and widget visibility, order and size. These records are not sent to Tenelk and are not synced across devices; already-open tabs in the same browser can receive local changes. Notes, countdowns and reusable text remain until you delete them or remove extension data. Hiding a widget does not delete its data. Daily Focus starts a new list when the local date changes. Removing the extension or clearing its extension data deletes its local records.
- Clipboard and calendar: Quick copy writes only the reusable text you choose to copy to the device clipboard. It does not read existing clipboard contents or clipboard history; if writing is unavailable, you can select the text manually. Calendar navigation and countdown calculations run on the device and do not access personal calendar services. These features do not request location, calendar, task-service or weather access.
- Search and destinations: only after the search form is submitted, Tenelk Tab sends the query to the Chrome Search API. Chrome uses the user's current default search provider; Tenelk Tab neither reads nor changes that provider. Opening a typed URL or shortcut sends the ordinary web request to that destination.
- Voice search: voice recognition begins only after the user presses the microphone button. Audio is handled by the browser's speech-recognition service under the browser vendor's terms. Tenelk Tab does not record or store the audio.
- Image search: an image file or public image URL is sent directly to Google Lens only after the user selects, drops, or submits it. It is not sent through Tenelk servers. A background image is handled separately, compressed locally, and kept only in Chrome extension storage.
- Most visited: the optional Chrome
topSitespermission is requested only when the user selects “Most visited.” The list returned by Chrome is displayed in memory and is not copied into Tenelk Tab's saved state. The user can switch back to custom shortcuts or revoke the permission at any time.
Chrome Web Store Limited Use
Tenelk Tab's use and transfer of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Permission-derived information is used only to provide or improve the user-facing new-tab features described above. It is not sold, transferred to advertising platforms or data brokers, used for personalized advertising or unrelated profiling, or made available for human review except with the user's explicit consent to review specific data, when necessary for security or legal compliance, or after aggregation and anonymization for internal operations.
4A. Android CONNECT Beta
The separately labelled Android CONNECT Beta uses Android’s VPN service, not Chrome extension permissions, to send supported traffic through official Tenelk HTTPS CONNECT gateways. It supports TCP destinations on ports 80 and 443. Customer DNS requests use proxied DNS-over-HTTPS; UDP, QUIC and other TCP ports are unsupported and rejected rather than sent directly. Establishing a connection requires processing the destination hostname or IP address and port. HTTPS page content remains encrypted within the tunnel; unencrypted HTTP traffic remains unencrypted application data when relayed.
Account, subscription, device and connection authorization information is processed to provide access as described above. External crash telemetry is disabled in this beta. Diagnostic status is displayed on the device, and first-party servers process service error information for operation and troubleshooting. This release has no automatic diagnostic upload or log export feature. The Chrome-specific session storage, browser permissions and Chrome API disclosures above describe the extensions, not the Android app. See the Android Beta release notes for current requirements and limits.
5. How we use information
- Provide accounts, software access, subscription status, and customer support.
- Protect users, prevent abuse, investigate errors, and maintain service reliability.
- Process purchases, cancellations, refunds, and legally required financial records.
- Comply with applicable law and enforce the Terms of Service.
6. Service providers
Tenelk may use carefully selected providers for identity, hosting, email, and customer support. Creem acts as merchant of record for subscription checkout and processes buyer identity, payment, tax, renewal, cancellation, refund, and dispute information under its own terms and data-protection obligations. Tenelk receives the account-bound transaction and subscription facts needed to activate and manage access, but does not receive or store full payment-card details.
7. International processing
Tenelk serves international users and uses infrastructure in more than one country. Information may therefore be processed outside your country. We apply reasonable contractual, access-control, and security measures appropriate to the service and provider.
8. Retention
We keep information only for as long as needed for the purposes above. Account and support records are deleted or de-identified when no longer required, subject to fraud-prevention, dispute, tax, accounting, and other legal retention duties.
9. Your choices and rights
You may request access, correction, deletion, or a copy of information associated with your account. You may also object to or restrict certain processing where applicable. Send requests to support@tenelk.cloud. We may need to verify your identity before completing a request.
10. Security
We use access controls, encrypted transport, limited provider permissions, and operational safeguards designed for the information involved. No system is completely secure; please contact support if you believe your account or information has been compromised.
11. Children
Tenelk is not directed to children under 16. If you believe a child has provided personal information, contact us so we can review and delete it where required.
12. Changes
We may update this policy as the product, providers, or law changes. Material changes will be identified by a new effective date and, when appropriate, an in-product or email notice.
tenelk