The short version
The application you run is yours. The data it stores is yours. Tainer doesn't phone home and we have no backdoor into your instance.
The rest of this page is about the parts we do touch: this website, our Docker Hub listing, support email, and our Discord.
Self-hosted product data
Tainer stores its application state in the data directory you mount (default /app/data). That includes:
- User accounts and password hashes (scrypt).
- Session metadata.
- 2FA secrets, encrypted at rest.
- Site connections and Proxmox API credentials, encrypted at rest.
- Audit log entries.
- Configured identity providers and their (encrypted) client secrets.
This data sits on the host you run Tainer on. Nothing in the shipped image transmits it back to us.
Proxmox credentials
The Proxmox API tokens or passwords you store in Tainer are sensitive. Use a least-privilege API token rather than a root credential where you can. If your data volume is exposed, treat the stored credentials as compromised and rotate them.
Telemetry
Tainer does not send usage telemetry by default. There is no analytics SDK shipped inside the application. If we add an opt-in telemetry feature in the future, we'll document what it sends and how to disable it.
This website
tainer.sh is hosted on Cloudflare. We use Cloudflare Web Analytics to understand traffic at an aggregate level. Cloudflare Web Analytics doesn't use third-party tracking cookies and doesn't fingerprint visitors. Cloudflare Turnstile may be used on some pages to verify visitors aren't bots.
When you sign into a self-hosted Tainer instance, the dashboard sets a session cookie scoped to your instance's hostname. That cookie stays between you and your server. We don't see it.
Third-party services we use
- Docker Hub, to distribute the container image (terms).
- Cloudflare, for DNS, CDN, bot protection, and analytics (privacy policy).
- An email provider, to receive support and security email at [email protected] and [email protected].
- Discord, for community discussion (privacy policy).
When you use those services, you're also subject to their terms.
Email and support
When you email us at [email protected] or [email protected], we keep the message and any attachments for as long as we need them to keep helping you, then delete. Security reports are handled under the process described on /security.
Children
Tainer is operations software for managing Proxmox infrastructure. It isn't directed at, or intended for, anyone under 16.
Changes to this policy
If we change anything material, we'll update the date at the top of this page. Continuing to use Tainer or this website after a change means you've accepted it.
Contact
Privacy questions: [email protected]
Security reports: [email protected]