Privacy and security
SpanDock is self-hosted. Your telemetry is received, stored and shown on your own machines, and it goes only to the destinations you add. This page describes what stays where, how secrets are kept, and the little that the SpanDock website receives.
Your telemetry stays on your machines
- Telemetry from your tools is received on the local machine and stored in an embedded database on your server (and optionally on clients).
- It leaves your network only when you add a destination such as Langfuse, Grafana Cloud, New Relic or an OTLP endpoint, and then only to that destination.
- Between clients and servers, it travels over an encrypted WireGuard tunnel (no account, no open ports).
- The SpanDock website never receives your telemetry, prompts, code or tool output.
Prompts and tool contents
- Tool profiles keep prompt and tool contents redacted. When SpanDock configures a tool under Integrations, it sets the tool up to report usage, timing, tokens and cost, not what you typed or what the tool read.
- Provider analytics never retrieve prompt or tool payloads. The Langfuse analytics on the Analytics page read cost, tokens, latency and models only.
- The built-in assistant records the text of your questions and its answers in its own telemetry only if you turn on Record chat content. Its saved chats stay on the server machine until you delete them.
Secrets
- Destination secrets, API keys for the assistant and the model proxy, the client's connection details and local keys are kept in the OS credential store: macOS Keychain, Windows Credential Manager, or the Linux Secret Service. On a machine without one, they are kept in a file readable only by your user.
- Settings files are readable only by your user and are written atomically.
- Client tokens, management tokens and API keys are stored only as hashes and shown once.
- Satellites receive destination secrets from the hub in encrypted form. The plain values exist only in memory.
Network exposure
- The dashboard binds to localhost (http://127.0.0.1:8787) and is protected against cross-site requests. It is not reachable from other machines.
- The tunnel exposes only what clients need: receiving telemetry, a health check, and routes limited to the calling client's own data, settings and reports. Configuration, administration, the SQL explorer, the assistant and provider analytics are never available over the tunnel.
- Remote server management over the tunnel needs both an approved client and a management token, and a few actions (resetting the mode, managing tokens, changing the tunnel) stay on the server machine.
- Every client sees only its own data. The client's identity always comes from its authenticated connection, never from the request.
- Destinations must use HTTPS, except localhost.
What the website receives
The SpanDock website at https://spandock.com receives two kinds of data:
- License checks from your hub or standalone install: a random installation ID, the role, the app version, the operating system and architecture, the reason for the check, and counts of active clients, servers and satellites. See Licensing and activation.
- Account and billing data when you sign up and subscribe: your email address, name and sign-in method, and the billing details handled by our reseller and merchant of record.
Other network requests the app makes:
- Update checks download release information and new versions from https://github.com/SpanDock/spandock-releases/releases/latest.
- Model prices are refreshed daily from OpenRouter's public model list, without a key.
- Each machine looks up its public IP address every 10 minutes, to show it on the server's Clients page.
- The assistant and model proxy send requests to the model providers you configure, with your keys.
For the full policy, see the Privacy Policy. Questions: privacy@spandock.com.