↗private traffic.

PRIVACY & LIMITATIONS

A private reader.
Clear boundaries.

This is a personal, self-hosted web gateway. It protects supported browsing through a server you trust; it does not provide complete anonymity or conceal its network presence.

What the local network can observe

In production, HTTPS encrypts the browser-to-gateway connection, including submitted destination URLs, passwords and page contents. Ordinary HTTPS browsing already protects page contents from passive Wi-Fi observers. The local network can still see the gateway IP, potentially its domain, connection timing and approximate traffic volume. Encrypted traffic can still reveal patterns.

The gateway performs its destination DNS lookups through verified DNS-over-HTTPS to Cloudflare, using a fixed public bootstrap address and no plaintext DNS fallback. Passive sniffing on the gateway’s network cannot read those DNS query names. Cloudflare sees the names and gateway IP and controls its own records. The browser/OS lookup of the gateway domain, and DNS from other applications, are outside this portal; configure browser and operating-system encrypted DNS separately.

Which connections are encrypted

The default self-hosted deployment uses HTTPS from browser to reverse proxy, verified HTTPS from reverse proxy to backend, and verified HTTPS from backend to every destination, image, stylesheet and redirect. The current Pulsar/Coolify deployment uses this verified HTTPS configuration on every application hop. The gateway and VPS operators can inspect activity. HTTP destinations are rejected. Backend DNS uses HTTPS too. No TLS interception, custom certificate authority or insecure certificate bypass is used.

Loopback development mode uses HTTP and is explicitly unencrypted. Do not expose that mode remotely. Encryption does not hide the endpoint IPs, possible TLS server names, or traffic timing and volume.

The gateway is a trusted intermediary

Destination websites generally see the gateway server’s IP address. The gateway processes plaintext URLs and page contents in memory. Its operator, a privileged host administrator or anyone who compromises it could inspect activity or instrument the process. DoH cannot hide destinations from the gateway’s own host. Hosting providers and other systems may keep separate records.

The app does not log browsing URLs, query strings, passwords, cookies, authorization headers or page contents. Sessions, navigation handles and the current page are transient server-memory data, cleared at sign-out or within one minute of session expiry and lost on restart. Temporary rate counters include the connecting peer’s IP. Proxy/APM/DNS logs, crash dumps, swap and other host records need separate operator controls.

Local profiles and unlocking

Profiles, bounded recent pages and bookmarks persist as AES-256-GCM ciphertext in browser-managed localStorage. A password-derived key and decrypted data exist in tab memory only while unlocked. Lock unloads the viewer and attempts server sign-out. Refresh requires the password again. No plaintext password, encryption key or session token is saved in Web Storage; the browser manages the HttpOnly authentication cookie. Server-side password verification remains necessary to prevent an open proxy.

Local encryption protects stored data when locked. It cannot protect an unlocked tab, extensions, compromised devices or a malicious gateway operator; stolen ciphertext permits offline password guessing. The browser may internally store or back up data in files, and may delete or evict it. The app creates no separate profile files and no persistent server profile store. Password changes may require an explicit local-data reset.

Profiles organise history and bookmarks; they are not separate cookie jars. Destination cookies, logins and forms remain unsupported. Accounts, cookies, fingerprinting, information you provide and identifying URL tokens can still identify you in general; disabling these features here is not an anonymity guarantee.

Source inspection and “invisibility”

Unauthorised visitors receive the password gate and public information, while browsing APIs, content and portal controls require server authentication. An authorised browser can inspect delivered code, pages and unlocked local data. Public source can reveal the portal’s purpose. Obfuscation cannot make a browser application secret, erase records held elsewhere or conceal its network presence.

A web proxy, not a VPN

Only supported pages opened inside this portal use the gateway. Other tabs, applications and device traffic keep their ordinary route. A conventional VPN typically tunnels wider device network traffic; it also requires trust in its operator and does not automatically prevent identification through accounts or fingerprinting.

An intentionally limited reader

Ordinary HTML, basic styles, raster images and links are supported. Remote JavaScript, destination cookies/authentication, forms, WebSockets, video/audio, SVG, downloads, fonts and CSS imports are unsupported. Remote content is isolated in an opaque-origin sandbox and can still display deceptive text. Some pages will misrender or omit assets; security protections take priority over compatibility.

Return to the portal ↗