HostBox Privacy Policy
Last updated: August 27, 2026 · Applies to the HostBox iOS app (Bundle ID: app.hostbox.ios)
Who we are
HostBox is an independent iOS deployment tool for installing and maintaining My T Server (including TeslaMate, TeslaMateAPI, and Companion) on your own VPS and importing its connection details into My T. HostBox is not an embedded My T feature and does not replace Tesla's official services.
How data is handled
- No hosted account system. HostBox does not require an account on servers operated by us.
- VPS connection metadata (host, port, SSH username, and authentication method) is stored on the device. It synchronizes as non-secret metadata to your private iCloud only when you explicitly enable backup.
- SSH passwords and private keys are stored only in the device Keychain and are excluded from HostBox iCloud backup. API tokens, Cloudflare secrets, and Grafana credentials are also excluded and must be re-entered after restore.
- Deployment results and sanitized handoff records are stored on the device. Optional iCloud backup excludes free-form notes, trusted SSH fingerprints, diagnostic logs, and all credentials.
- A Cloudflare API token, if provided, stays in memory for the active deployment and is not written to deployment history, logs, Keychain, or iCloud backup. Cloudflare Access service credentials and My T API/Grafana credentials are deployment results and may be retained in the on-device Keychain, but are excluded from iCloud backup.
- Remote scripts run on your VPS. We do not upload your VPS password to a HostBox-operated cloud service.
SSH commands, logs, and deployment history
- Commands and output entered by the user stay in memory while the App is running so the command page can be revisited. The session is bounded to 200 entries and limited output capacity; it is not kept as long-term history after the App exits and is not uploaded.
- Bounded deployment steps, outcomes, and diagnostics are stored on the device for retry and maintenance. Do not print secrets in commands, and redact diagnostics before copying or sharing them.
- Deleting a server or completion record removes its related on-device Keychain items. Data on the VPS and third-party accounts must be deleted separately by the user.
Handoff to My T
The custom URL used to open My T contains non-secret connection metadata only—never a password, bearer token, or Cloudflare secret. The full connection package is placed only on the same device's local clipboard, expires after five minutes, and requires an explicit HostBox action. My T tests the endpoint and asks whether to overwrite an existing connection or save another name before storing it.
Network access
- Connections to the VPS you specify, including SSH and HTTP health checks. Temporary public-IP mode exposes only the My T API on port 8081; TeslaMate's web UI and Grafana remain on VPS loopback (
127.0.0.1) and require a computer SSH tunnel. - Optional access to the Cloudflare API and public component catalogs, such as the My-T-Companion deployment catalog hosted on GitHub.
- Optional opening of My T through a URL scheme to import connection details.
Data we do not collect
- We do not collect Tesla account credentials.
- We do not perform cross-app advertising tracking or use the advertising identifier for tracking.
- Vehicle and trip data remains in your TeslaMate instance or server and is not uploaded to us by HostBox.
Third parties
The deployed stack may include open-source components such as TeslaMate, TeslaMateAPI, and Grafana, as well as optional services you choose, such as Cloudflare. Their respective privacy policies apply. The HostBox source repository is currently private.
Children
HostBox is intended for adults who administer their own servers and is not directed to children under 13.
Contact
For support or privacy questions, use the My T support page or the support channel listed on the HostBox App Store product page. See the HostBox product page for more information and the launch video.
← Back to HostBox · Download on the App Store · My T Privacy Policy