TurnPanel

Privacy

Effective 2026-08-10

TurnPanel is a local-first app. Your conversations, your documents, and the work your agent does for you stay on your computer. This page explains the small amount of information that does reach us, why we want it, and how long we keep it.

The short version

  • We never see your chats, your commands, your files, or anything your agent reads or writes.
  • The desktop app can send anonymous usage statistics. You choose during setup, and you can change your mind at any time in Settings.
  • If you give your machine a public address, what travels over it is relayed without being read. We keep how much traffic there was, never what was in it.
  • Those statistics are tied to a random ID generated on your machine. It is never connected to your email, your account, or your licence.
  • Raw events are deleted automatically after three months. Only daily totals survive, and totals cannot be traced back to anyone.
  • We do not sell your data, and we do not share it.

turnpanel.com

Your account

Signing in stores your email address, and your name and profile picture if you signed in with Google. We use your email to send you the six-digit sign-in code, to tell you when your waitlist request is approved, and to reach you if something about your account needs attention. We do not send marketing email.

Your session is a cookie. It lasts 30 days unless you sign out sooner, and it exists only to keep you signed in — it is not used for advertising or analytics, and there are no third-party trackers, tag managers, or advertising pixels anywhere on this site. Your account record stays until you ask us to delete it.

The waitlist

Joining the waitlist records that your account asked for access, when it asked, and — once someone has looked at it — whether it was approved or rejected and which admin decided. Nothing more.

Downloads

When an approved user downloads a build, we count the download: which platform and which version, and nothing else. In particular the record carries no account ID, no email and no install ID, so there is no way to work back from it to who downloaded. It goes into the same anonymous statistics described below, not into your account.

Cloudflare, which hosts this site, keeps its own short-lived request logs (including IP addresses) as part of serving and protecting it. That is ordinary infrastructure logging and is not something we build on or query.

Linked devices and web access

Linking a device

Linking the desktop app to your account stores three things about that machine: a name for it (the app offers your computer’s own name and you can change it to anything), when you linked it, and roughly when it was last seen. “Last seen” is written at most once every 5 minutes, because its job is to let you recognise a machine in a list — not to follow it. It records that a device was in touch, never what it was doing.

The credential the app holds is stored only as a hash. We cannot read it back, and revoking a device marks the row rather than deleting it, so that credential can never become valid again. The row lasts until you revoke the device or delete your account.

Approving a browser for one of your endpoints, or letting one of your devices call another, mints a short-lived code — again stored only as a hash, alongside the address it was approved for, and gone within 10 minutes.

Web access

Web access gives your machine a public address so you can reach it from a phone or another computer. Turning it on stores the hostname you chose, the licence it belongs to, and when it was issued and when your trial started. The hostname is public by nature: anyone who has the address can try it, and what they get is your app asking them to sign in.

Traffic to that address is relayed to your machine, and the relay does not read it. It moves opaque blocks of bytes between the browser and your computer: not the page, not the request path, not what your agent answered, and nothing derived from any of it. It could not read them without being rewritten to do so.

What it does keep is volume — how many bytes and how many requests an endpoint carried, for the day and in total. That is there because bandwidth is a bill and a runaway endpoint should be visible before it becomes one, and it is the whole of what we can say about your endpoint’s use of it. Those counters belong to the name: release the address, rename away from it, or have the licence revoked, and they are deleted with it.

Desktop app statistics

We want to know things like "how many people are on the current version" and "is anyone actually running the local engine on 8 GB of RAM", because those answers decide what we build and what we keep supporting. We want to know them without knowing anything about you.

It is your choice

You are asked during onboarding, before anything is ever sent. The box is ticked by default, and unticking it there means nothing leaves your machine — not even once. Afterwards it lives in Settings, and you can turn it off or back on whenever you like. Turning it off stops all sending immediately.

The install ID

When statistics are on, the app generates a random identifier and keeps it locally. It is not derived from your hardware, your username, your email, or anything else about you — it is just a random number, and its only job is to stop one machine pinging twice from being counted as two machines. It is never sent to or stored next to your TurnPanel account, your email address, or your licence key, and the database that holds these statistics has no column that could point at any of them.

If you turn statistics off and later turn them back on, the app throws the old identifier away and generates a new one. The two cannot be linked.

Exactly what is sent

This is the complete list. There is nothing else in the message, and the server rejects anything it does not recognise.

FieldWhat it isExample
installIdA random identifier generated on your machine when you turn telemetry on. It is not derived from anything about you or your hardware, it is never sent to or stored alongside your TurnPanel account, and turning telemetry off and on again generates a brand new one.3f2a…-…-…
eventWhich one of these happened: first_run, ping, update, uninstall.ping
osWhich operating system family the app is running on.macos
osMajorThe major OS version only — never the full build number, which is far more identifying.15
archProcessor architecture, so we know which builds to keep shipping.arm64
appVersionThe TurnPanel version you are running, so we can tell how an update is spreading.v26.08.07
channeloptionalWhich release channel the app follows, so we can tell how a build is spreading on each track.beta
prevVersionoptionalOn an update only: the version you updated from, so we can see which upgrade paths people actually take.v26.08.01
cpuFamilyoptionalThe processor family name, not a serial number or any per-machine id.apple m3 pro
cpuCoresoptionalHow many cores that processor has — it tells us what size of local model is realistic for real users.12
ramGboptionalInstalled memory, snapped to a coarse tier (4, 8, 16, 24, 32, 48, 64, 96, 128+ GB) — never the exact figure.32
gpuFamilyoptionalThe graphics chip family, again a family name rather than a device id.apple m3 pro
vramGboptionalVideo memory, snapped to the same coarse tiers as ramGb.16
engineModeoptionalWhether the gateway is running local, hybrid, or cloud. Never which model, which provider, or which prompt.local

There are exactly 4 kinds of message: first_run, ping, update, uninstall. A ping is sent at most once a day, and an update message only when the app notices its own version changed. Memory figures are rounded to a coarse tier before they leave your machine, and rounded again on arrival, so “31.4 GB” becomes “24 GB” and stays that way.

Uninstalls

Windows can run a hook as the app is removed; macOS cannot. A Mac uninstall is inferred from an install that simply stops pinging, never observed. We would rather have a number that undercounts than run anything on your machine after you have asked it to leave.

How long it is kept

Individual events are stored for three months and then deleted automatically — not by a job we have to remember to run, but by the storage itself, which expires them. Once a day we count those events into daily totals: how many active installs, how many on each version, how many with each memory tier. Those totals are what we keep long term, and they contain no identifiers of any kind, not even the random install ID.

Web search

When your agent searches the web, the search goes out through turnpanel.com rather than straight from your machine. That is so the key for the search provider lives on our server instead of inside the app you downloaded, where anyone could read it out of the file.

Your question passes through us on its way to the provider and the answer passes back. It is relayed, not read: the text is never written to a database, never written to a log, and nothing derived from it — no copy, no summary, no fingerprint — is kept after the answer reaches you. What we record is how much searching happened, not what was searched for.

To keep one machine from using up everyone's searches, there is a fair-use allowance, and counting against it needs something to count. When you are signed out, the app generates a second random identifier — separate from the statistics ID above and unconnected to it, to any account, and to your licence — and the allowance belongs to that installation. When you are signed in, the allowance belongs to your account instead, shared across every device you have linked, and the count is kept against your account rather than against a random ID. A signed-in account has a higher allowance, and subscribing raises it again.

Either way, the same four numbers per day are all we store: how many searches, how many queries they issued, how much of the allowance they used, and the date. Never what was searched for — that does not change when you sign in, and there is nowhere it is written down. Your allowance is always shown to you as a percentage, and it resets at midnight UTC (on Monday, for the signed-in weekly allowance). We do look at what the searches cost us at the provider, because we pay that bill — but a cost is a number of requests multiplied by a published rate, and it says nothing about what any of them asked.

TurnPanel (Free)

A TurnPanel account includes a small weekly amount of hosted model use. When you pick that model, the conversation goes out through turnpanel.com to the provider that runs it, for the same reason web search does: the provider key lives on our server rather than inside the app you downloaded.

Your messages pass through us on the way there and the reply passes back. Same rule as search, and it is the important one: it is relayed, not read. Nothing you send and nothing the model answers is written to a database, written to a log, summarised, fingerprinted or kept once the reply reaches you — and we ask the provider to route only to services that do not retain it either.

This one is for signed-in accounts only, so the allowance belongs to your account and is shared across every device you have linked. Three numbers per day are all we store: how many requests, how much of the allowance they used, and the date. Your allowance is shown to you as a percentage and resets Monday at midnight UTC. We do look at what these requests cost us at the provider, because we pay that bill — and a cost is a token count multiplied by a rate, which says nothing about what was in them.

Feedback you send us

The app has a feedback form. Everything about it is something you start: nothing is collected in the background, nothing is sampled, and there is no path by which the app sends us a report you did not press a button to send.

You see exactly what is included before it goes. If you are reporting a bad response, you can attach the conversation it came from — and that attachment is what it sounds like: the messages in that conversation, yours and the model's. The app shows you the whole thing first. If you would rather not include it, send the report without it; a description on its own is a perfectly good report, and it is the only part we require.

You can send a report anonymously, and anonymous means anonymous: we store no account and no email address against it, not hidden but absent. If you leave an address so we can reply, we use it to reply.

Attachments are kept in private storage that has no public address, they are only ever opened by us, and they are deleted automatically after 90 days. The written part of a report is kept for 365 days and then deleted too. If you want something removed sooner, write to privacy@turnpanel.com and we will take it out.

What we never collect

  • The content of your conversations, prompts, or model responses — with one exception, and it is the one above: a conversation you choose to attach to a feedback report, after being shown exactly what it contains. Nothing else sends them anywhere, and nothing sends them without you asking.
  • Commands your agent runs, or their output.
  • Documents you open, their contents, their filenames, or anything derived from them.
  • Which models you run, which providers you configure, or any API key.
  • Your files, your screen, your clipboard, your keystrokes, or your location.
  • Your IP address, in the statistics described above.
  • What travels through your public endpoint — the relay carries it without reading it, and keeps only how much of it there was.

If you use hybrid or cloud mode, your queries go to the provider you chose, under that provider's own privacy policy. They do not come to us, and we are not told that it happened beyond the three-way engineMode field above.

Who else sees any of this

Nobody. We do not sell data, we do not share it with advertisers or data brokers, and we do not hand it to anyone for their own use. The only third parties involved are the infrastructure providers who run the service on our behalf — Cloudflare for hosting, storage, and email delivery, and Google if you choose to sign in with a Google account. We would disclose information if the law genuinely required it, and we would rather tell you than not.

We should be plain about ourselves, too. Running TurnPanel means some of us can see the account-level things described on this page — your email address, your devices and their names, whether your endpoint is connected — because that is what answering “why can’t I reach my computer” requires. Nobody here can see what is on the other side of it: not your conversations, not what passed through your endpoint, and not the contents of anything on your machine. Those are not places we have chosen not to look. They are places this software does not go.

Your choices

  • Turn statistics off. Settings, any time. Nothing further is sent.
  • Start over. Turning statistics off and on again gives you a fresh, unlinkable install ID.
  • Revoke a device. Any linked machine, from Devices, at any time. Its credential stops working immediately.
  • Delete your account. Email us and we will remove your account, your waitlist row, your sessions, and every device you have linked — and hand back your web-access licence, which takes down your public address and deletes the traffic counters that went with it. We cannot delete past statistics on request, because there is nothing in them that says which ones were yours — that is the same property that makes them anonymous.

Contact

Questions, corrections, or a request about your account: privacy@turnpanel.com. A real person reads it.

Changes to this page

We will update this page when what we do changes, and we will move the effective date at the top when we do. If a change means collecting something materially new from the desktop app, we will ask you again rather than quietly widening what the existing setting covers.