Homport documentation
Privacy
Your shares use your own Windows PC and Cloudflare account. Homport does not operate a developer backend for the desktop app.
What this notice covers
This notice explains how the Homport desktop app handles information when you connect a Cloudflare account, share a local web app, or run diagnostics. The website and the services you connect have separate considerations below.
Homport does not send app usage analytics, automatic crash reports, or your share configuration to the app developer. Information still travels to Cloudflare to provide the features you choose.
Information on your PC
- Share configuration
- Homport stores a local manifest containing machine and resource identifiers, hostnames, local ports, sharing settings, and the email addresses you allow for private shares. This file is not encrypted as a credential store. Homport uses it to display and manage your shares and recognize resources it created.
- Credentials
- Cloudflare authorization and connector credentials are stored separately using Windows Data Protection (DPAPI), tied to your Windows user. A temporary credential file restricted to that user passes the connector token to cloudflared. Homport cleans up temporary token files after startup and checks for leftovers on later launches. Credentials are not put in the manifest or process command line.
- Preferences and diagnostics
- Local preferences support features such as the startup offer and Keep awake. Local status and logs help diagnose the connector, your app, its address, and sign-in protection. Sensitive values are filtered from logs and diagnostic reports.
Windows account protection matters: these measures do not protect against every program running as you or an administrator on the same PC.
Information sent to Cloudflare
Homport opens Cloudflare sign-in in your browser and requests authorization for the selected account. It does not ask you to enter a Cloudflare password or an email one-time code inside Homport.
To create and manage shares, Homport sends configuration such as resource identifiers, hostnames, tunnel settings, and allowed email addresses to Cloudflare. Private sharing stores the allowed addresses in Cloudflare Access policies. Visitors enter their email address and one-time code on the Cloudflare sign-in page.
Traffic to a shared app passes through Cloudflare and the cloudflared connector on your PC. Cloudflare processes that traffic under its service terms and privacy practices. Your local web app may also collect or store visitor information independently of Homport.
Read Cloudflare’s Privacy Policy for its handling of account and end-user information. The Cloudflare account owner controls the relevant account settings and is responsible for how they share their app.
Diagnostic reports you choose to copy
Copy diagnostic report puts a report on your Windows clipboard; it does not send it to the developer. A report can include app and connector versions, timestamps, hostname, local port, sharing mode and status, check results, error codes, and up to 200 recent log lines.
Homport filters credentials, full email addresses, and one-time codes. A report can still describe your setup. Review it before sharing it, and remove any details you do not want the recipient to see. Clipboard history or synchronization, if enabled in Windows, is controlled by your Windows settings.
Removing information and access
- Remove a person
- Save the updated People list to remove that email address from the share’s allowed list. This changes access for that share; it does not erase records independently held by Cloudflare or the person’s email provider.
- Turn off a share
- After successful cleanup, Homport removes that share’s address, routing entry, private Access app and policy, and local share record. The app running on your PC stays running.
- Lock now
- Stops this PC’s connector and keeps its shares offline until you unlock. It retains the configuration and credentials needed to resume.
- Sign out
- Removes local OAuth authorization and attempts to revoke it with Cloudflare. It does not delete shares or the stored connector credential. Existing shares can continue running; a locked PC stays locked.
- Remove this machine
- Cleans up Homport-owned shares and the connector for this machine, removes its local manifest and saved credentials, and revokes OAuth authorization at the end. If cleanup fails, follow the app’s recovery instructions and retry. Other resources, your domain, your Zero Trust organization, and the email sign-in method stay in your Cloudflare account.
Uninstalling from Windows does not remove your shares on Cloudflare. Use Remove this machine first.
Homport does not set a retention period for records held by Cloudflare, Microsoft, your email provider, or the local app you share. Consult those providers and the Cloudflare account owner about records they control.
These pages and external services
This website is hosted on Cloudflare Pages. We use Cloudflare Web Analytics to understand visits and page performance. Its browser script reports page-view and timing metrics to Cloudflare; it is not used for advertising or tracking visitors across websites. The site has no account sign-in or submission form, and our own code does not use cookies or browser storage. Cloudflare processes request information, including IP addresses and traffic data, to deliver and protect the website. Hosting data handling is separate from the desktop app; see Cloudflare’s Privacy Policy for its practices. This is not a promise that the hosting service keeps no logs.
Following a link to Cloudflare opens its website. Purchases and updates through Microsoft Store are handled by Microsoft; see the Microsoft Privacy Statement.
For practical steps to control your shares and prepare a diagnostic report, see Homport support.
Privacy questions and support messages
For privacy questions, or to ask about information you have sent to Homport support, email support@homport.dev.
If you email support, your email address, message, and any attachments you choose to include are received through the support email service so Homport can respond to your request. Sending a message is optional; do not include passwords, tokens, or one-time codes. A support email is separate from the desktop app, which does not upload information automatically.