Original language: English.
Privacy Policy
This policy explains what personal data Tunnel collects across tunnelpowered.com and the Tunnel dashboard, why we collect it, who we share it with, how long we keep it, and the rights you have. It is written to be read, not to be survived.
Last updated: July 26, 2026
1.Who we are
Tunnel ("Tunnel", "we", "us") operates the website tunnelpowered.com, the Tunnel dashboard at app.tunnelpowered.com, and the related services (together, the "Services"). Tunnel helps businesses measure and improve how AI assistants such as ChatGPT, Claude, Gemini and Perplexity present them.
Tunnel is a product of "STILL BETA TECH" SRL, a company registered in the Republic of Moldova, at MD-2093, str. Mihai Viteazul 28, s. Hulboaca, mun. Chișinău, Republic of Moldova. For the purposes of the GDPR, that company is the data controller of the personal data described in this policy.
You can reach us about anything in this policy at contact@tunnelpowered.com.
2.Which laws we comply with
We are operated from Moldova and we sell into the European Union, so more than one regime applies to us at the same time. Rather than claim a vague "GDPR compliant" badge, here is the actual list:
- Regulation (EU) 2016/679 — the GDPR — for anyone in the European Economic Area, and the UK GDPR together with the Data Protection Act 2018 for anyone in the United Kingdom.
- Law No. 133/2011 of the Republic of Moldova on the protection of personal data — our home jurisdiction. It is replaced by Law No. 195/2024, which transposes the GDPR into Moldovan law and takes effect on 23 August 2026. We already operate to the GDPR standard, so that transition does not reduce any right described here.
- The California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and the comparable comprehensive state privacy laws in Virginia, Colorado, Connecticut and Texas, for residents of those states.
- The US CAN-SPAM Act and EU rules on marketing email — every newsletter we send carries a working one-click unsubscribe, and unsubscribing takes effect immediately.
Two commitments up front, so you do not have to read the rest of the policy to find them: we do not sell personal data, and we do not use tracking or advertising cookies.
3.Personal data we collect
We only collect data you give us or that is generated by your use of the Services:
- Account data — email address, name, and a password (stored only as a cryptographic hash), plus your chosen plan.
- Business and website data — the website URLs you register, your company name, and the content of those websites, which is by nature already public.
- Free scan requests — the email, name, company and website URL you submit in the free AI visibility scan form. This creates an account for you, which becomes active only after you confirm your email address.
- Newsletter subscription — your email address, subscription status, and the date you subscribed or unsubscribed.
- Billing data — if you buy a paid plan, your plan and invoicing details. Card payments are handled by a payment processor; we never store full card numbers.
- Identity verification data — only if you ask to be human-verified. See the section on identity verification below; this is the most sensitive data we handle and it has its own rules.
- Support communications — messages you send us and our replies.
- Technical data — IP address, browser type and request timestamps in server logs, used for security and rate limiting.
We do not build advertising profiles about you, and apart from an identity document you choose to send us for verification, we do not collect special categories of personal data.
4.How and why we use your data (legal bases)
Under the GDPR every use of personal data needs a legal basis. Ours are:
- Performance of a contract — creating and running your account, monitoring and optimising your registered websites, processing payments, and sending transactional email (email confirmation, scan results, service and billing notices).
- Consent — sending you our newsletter, and processing an identity document if you request human verification. You can withdraw consent at any time without affecting your account.
- Legitimate interests — securing the Services (rate limiting, abuse and fraud prevention), debugging, and improving the product using aggregate usage information. You can object to any of this at any time.
- Legal obligations — keeping the records we are required to keep, such as tax and accounting records, and responding to lawful requests from authorities.
5.Content we crawl and republish
The core of the product is reading a website you register and republishing a machine-readable version of it — structured data, an llms.txt file, a knowledge-base record — at stable public endpoints so AI assistants and agents can retrieve it.
We do this only for websites you register and confirm you own or are authorised to manage, on the basis of our contract with you. We honour robots directives on third-party sites, and we do not crawl a site into the knowledge base because someone else told us about it.
Website content is usually not personal data, but it can contain some — a founder's name, a staff photo, a direct email address. Where it does, you are the source of that content and remain responsible for having the right to publish it; we process it as your processor for the purpose of producing the machine-readable version. If a person asks us to remove their personal data from a published record, we will remove it and tell you.
A listing is removed from the public knowledge base when you delete the website or your account. Ask us and we will confirm removal.
6.Identity verification
Human verification is optional. It exists so that a business can prove a real, accountable person stands behind a listing, and it is the reason the verified badge means anything.
If you request it, we may ask you for an identity document or another proof of your role in the business. We ask for it only when you request verification, we use it for nothing except confirming your identity, we do not share it with AI platforms or any other third party, and we delete the document once verification is decided — keeping only the outcome (verified or not), the date, and who reviewed it.
The public record shows only that a named person was verified and when. It does not publish your document, your document number, or your date of birth.
7.How the Services interact with AI platforms
To measure your AI visibility we send queries about your business — built from your company name, website URL and your website's public content — to third-party AI platforms (currently OpenAI, Anthropic, Google and Perplexity). These queries describe your business, not you personally; we do not send account credentials, billing details or verification documents to AI platforms.
Each AI platform processes those queries under its own terms and privacy policy.
8.When an AI agent queries our knowledge base
Our public knowledge base can be read by anyone — through plain HTTP, through our MCP server, or through our A2A endpoint — with no account and no credentials. We keep a log of those reads, because whether anyone actually uses the registry is the central question about this product and we would rather measure it than assume it.
What we record: the time, which of the three interfaces was used, which kind of read it was, whether the caller identified itself, whether we answered completely, how fresh the answer was, and how long it took. We also record a salted, truncated HMAC of the IP address, so that ten reads from one caller can be told apart from one read by ten callers.
What we do not record: the IP address itself, and the text of the query. We store the *shape* of a request — that a search term was present and roughly how long it was — never its content. A registry that kept a transcript of every question asked of it would be a different and worse product than the one we are building.
Our legal basis is legitimate interest (Article 6(1)(f) GDPR): operating and protecting a public API against abuse, and measuring whether the service is used at all. The data is pseudonymous at rest, most callers are software rather than people, and where a read does come from a person's browser we classify it as such and exclude it from the measurement it was collected for. There is no profiling, no advertising, no enrichment, and no sharing of this log with anyone.
We keep these records for 180 days, after which they are deleted automatically by a nightly job. If you operate an agent and want its reads removed sooner, write to us — but note that for anonymous reads we hold no identifier that could link a row back to you, which is the point of storing a hash instead of an address.
9.Who we share data with
We do not sell your personal information, and we do not share it for cross-context behavioural advertising (as those terms are defined by the CCPA/CPRA). We share personal data only:
- With service providers (processors) that host our infrastructure, deliver our email and process payments — bound by contracts that limit their use of your data to providing that service to us.
- With AI platforms, as described in the section on AI platforms above.
- When required by law, or to establish, exercise or defend legal claims, or to protect the Services and their users from fraud or abuse.
- In connection with a merger, acquisition or asset sale, in which case this policy continues to apply to your data and we will notify you of any change of controller.
If you are on a paid plan and need a data processing agreement (DPA) for your own compliance file, ask us at contact@tunnelpowered.com and we will provide one.
10.International data transfers
Our service providers and the AI platforms we query may process data outside the European Economic Area, including in the United States. Where personal data of EEA or UK residents is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or the provider's certification under the EU–US Data Privacy Framework.
11.How long we keep data
- Account and website data — for as long as your account exists, then deleted or anonymised within a reasonable period after deletion, except where law requires longer retention.
- Newsletter data — until you unsubscribe. After that we keep your email on a suppression list solely so we do not email you again.
- Free scan records — kept to enforce the one-scan-per-email limit and, if you create a full account, merged into it.
- Identity documents — deleted once verification is decided. Only the outcome and its date are kept.
- Server logs — kept for a short period for security purposes, then deleted or anonymised.
- Billing records — for the period required by tax and accounting law.
12.Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS), hashed passwords, access controls and rate limiting on public endpoints. No method of transmission or storage is completely secure; if we become aware of a personal data breach that puts your rights at risk, we will notify you and the competent authority as required by law.
13.Your rights in the EEA and the UK
If you are in the EEA or the UK, you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data deleted
- Restrict or object to our processing, including any based on legitimate interests
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time — for example, unsubscribe from the newsletter — without affecting processing already carried out
- Lodge a complaint with your local data protection supervisory authority
To exercise any of these, email contact@tunnelpowered.com. We will verify your identity and respond within one month.
14.Your rights in the Republic of Moldova
Under Law No. 133/2011 you have the right to be informed about processing, to access your data, to have it corrected or deleted, to object to processing, and to complain to the National Centre for Personal Data Protection (Centrul Național pentru Protecția Datelor cu Caracter Personal). From 23 August 2026, Law No. 195/2024 extends this to broadly the same set of rights as the GDPR, including data portability.
In practice we apply the list in the previous section to everyone, wherever you live. It is simpler for us and better for you.
15.Your rights under US state privacy laws
If you are a resident of California or another US state with a comprehensive privacy law — such as Virginia, Colorado, Connecticut or Texas — you have the right to:
- Know what personal information we collect, use and disclose about you
- Access and obtain a copy of your personal information
- Correct inaccurate personal information
- Delete your personal information
- Opt out of the sale or sharing of personal information — we do not sell or share personal information, so there is nothing to opt out of
- Not be discriminated against for exercising any of these rights
You may exercise these rights yourself or through an authorised agent by emailing contact@tunnelpowered.com. We will verify the request and respond within 45 days, extendable once by a further 45 days where permitted.
16.Email we send you
We send two kinds of email: transactional (email confirmation, scan results, service and billing notices — necessary to provide the Services) and newsletter email you subscribed to. Every newsletter includes a working one-click unsubscribe link, and unsubscribe requests take effect immediately.
17.Cookies and local storage
The landing site uses no advertising or third-party tracking cookies. The Tunnel dashboard uses browser storage strictly to keep you signed in. Because we use only strictly necessary storage, no cookie consent is required; if we ever add analytics or marketing cookies we will ask for your consent first and update this policy.
18.Children
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
19.Changes to this policy
We may update this policy. We will post the new version on this page and update the date above; for material changes we will also notify you by email or through the dashboard before they take effect.
20.How to contact us about privacy
For any question or request about this policy or your personal data:
"STILL BETA TECH" SRL — Privacy
MD-2093, str. Mihai Viteazul 28, s. Hulboaca, mun. Chișinău, Republic of Moldova
tunnelpowered.com