Privacy
Your findings stay on your machine. Ping, traceroute, port scan, SNMP, ARP, discovery, drift, inventory, incidents, packet captures and the Vault all run locally and are written to a folder on your computer. None of it is uploaded. None of it is sent to us or stored on our servers. We could not show you your own scan results if you asked us to — we have never had them.
And the app makes no outbound calls you didn't ask for. It doesn't phone home on startup. It doesn't check in. Every network call it makes is one you triggered — and every one is listed below, because you'd find them in a packet capture inside of a minute and you should hear it from us first.
What we collect
Your email address. That's the list.
It's how we know a license is yours and not someone else's. It's personal data and we're not going to dress it up as anything else. Alongside it: a random account ID, your tier, when your trial started, and — if you buy — the fact that a payment succeeded and for how much.
That's everything.
The free tier needs no account at all. Nothing is sent for licensing until you start a trial or buy.
What we never ask for
Not "we keep it safe." We never have it:
- No card details. Buying opens Stripe in your browser. The card is typed on Stripe's page, and we're told nothing but "paid." There is no card field anywhere in the app.
- No Social Security or national ID number. No passport or driver's license number.
- No date of birth. No home address. No phone number.
- No password — there isn't one. Sign-in is a one-time emailed code, so there's no password of yours in our database, and none to be reused against you somewhere else.
- No name, unless your email happens to contain one.
- No employer, job title, or company details.
A license needs to know which account paid, not who you are. Anything more would be a liability for us to hold, so we don't hold it. If our database ever leaked, it would spill a list of email addresses and license tiers. Bad — but nothing about your network is in there to spill.
What the tools talk to
A tool can't answer a question about the internet without asking the internet. Nothing here is automatic — each one runs because you ran it:
| What | Talks to | What it sends |
|---|---|---|
| Home / IP info | ipwho.is | Your public IP, to show your ISP and city. Click-to-load — the panel sits empty with a "Look up" button until you press it. Nothing is sent unless you do. |
| DNS | Cloudflare DNS-over-HTTPS | The name you looked up |
| WHOIS | rdap.org | The domain or IP you asked about |
| MAC lookup | api.macvendors.com | Only the 3-byte vendor prefix, for OUIs not in the offline table — never the full MAC, never the device |
| Deputy / Posse (AI) | Anthropic | Your question and tool results — only if you choose the cloud provider and supply your own key (see below) |
| Ping, trace, ports, SNMP, SSH… | Whatever you typed | That's the tool doing its job |
None of these route through us. We don't see them, log them, or receive them.
The one thing Home checks by itself is your own default gateway — a ping to your own LAN, to answer "is my network up?" It never reaches the internet, and if there's no gateway it says so rather than quietly pinging someone else's server to find out.
AI features (Deputy / Posse)
If you turn on the optional AI features and choose the cloud provider, your question plus any relevant read-only diagnostic output (which can include IP addresses, hostnames, and similar network data) is sent directly from your machine to Anthropic's API, using an API key you supply yourself — never to us. Before anything is sent to the cloud, SubnetSlinger scans your message and the tool output for secret-shaped text — private keys, password fields, auth tokens, API keys — and strips it out first. This is a pattern match, not a guarantee: it catches well-known secret shapes, not everything a person could type, so don't rely on it if you're pasting something you consider truly sensitive — use the local Ollama option instead for that conversation. You can instead choose a local model via Ollama so nothing leaves your machine at all. Either way, the AI tools are read-only and never change device configuration.
MCP servers you connect
If you connect a third-party MCP server from the Assistant, that connection and any data it sees is between your machine and that server — a trust decision you make per server, not something we operate or see.
Credential Vault
Passwords and other secrets you store in the Vault are encrypted on your machine (AES-256-GCM) and are never transmitted anywhere by the app.
The Vault's key is also sealed to your Windows user on your device. Copy vault.json to another machine and it will not open — even with the correct passphrase. That's deliberate: a stolen file is useless to whoever stole it. It also means that if the machine is lost or wiped, those secrets are gone for good. There is no recovery, by us or by anyone. Keep anything you can't re-create somewhere else as well.
Your data doesn't follow your license — you carry it
Sign in on a new computer and your Pro license unlocks — on an empty app. There's no cloud sync and no "restore from your account": your account has never held any of your data. It lives on your machine, and only there.
So bring it across yourself. Back up & restore (in the app's File menu) saves your work — inventory, incidents, runbooks, saved maps, watch lists, saved hosts, custom themes, and the activity log — to a single file you can move to a new machine and import. It's your file: keep it on a USB stick, a file share, your own cloud drive, wherever you like. We never see it, and it never touches our servers.
The backup leaves out three things on purpose.
Your Vault secrets don't come across. The Vault is locked to the computer it was created on. Its file won't open on any other machine, even with the correct passphrase — that's what keeps a stolen copy useless. It also means copying it forward just gets you a file that won't open, so set your secrets up again on the new machine.
Your saved SSH host keys don't come across either. Those are the fingerprints the app uses to recognize each server you connect to. On a new computer you want to confirm each server's fingerprint yourself the first time you connect — that's how you'd catch an impostor pretending to be a server you trust. Trusting a copied list would skip that check, so leaving them out is a safety feature, not a loss.
Your license isn't in the backup, and doesn't need to be. Sign in on the new machine and Pro turns back on.
Website
Our hosting provider may collect basic visit analytics on subnetslinger.com (page views, referrer). We do not use ad trackers or sell visitor data.
App
SubnetSlinger the application does not collect analytics, usage tracking, or telemetry. Not because we promise not to look — because it never reaches us.
Account & licensing
When you sign in to activate a Pro license, we store your email address and license status in our licensing service (hosted by Supabase). Payment processing is handled by Stripe; we receive confirmation of purchase, not your card number. Your email is used to send you a sign-in code and a receipt — it is not sold, not shared with advertisers, and not used for tracking, profiling, or marketing you didn't ask for.
You can request account deletion by emailing sheriff@subnetslinger.com.
AISMITH PDX LLC.
Questions? See the Contact page.