Ownhearth

Security & privacy

Built so we see as little as possible.

This page is for the careful reader. Here's precisely how Ownhearth handles your traffic, your password, and your devices — no hand-waving.

Your traffic never touches us

Ownhearth sets up a direct, end-to-end encrypted WireGuard tunnel between your travel router and your home router. Your internet exits through your own home connection. It does not route through our servers — so we can't see the sites you visit or the data you send, and there's nothing for us to log, sell, or hand over.

Your router password stays on your machine

The setup helper runs on your computer. It connects to your router over your own local Wi-Fi (SSH) using the admin password you type in. That password is used locally to configure your box and is never sent to Ownhearth. We never see it, store it, or transmit it.

The Mac helper is code-signed and notarized by Apple under our developer account, Ye & Zheng Innovations, LLC (the legal entity behind Ownhearth / Aetheria Sphere LLC) — so that's the signer name macOS may show you.

How ongoing management is authenticated

After setup, your routers keep a tiny "phone-home" channel so we can tell if one goes offline and help you recover. Each device gets its own secret at setup and signs every message with HMAC-SHA256 — there's no shared password; the channel is authenticated and replay-protected. It carries connection-health data only, never your traffic.

What we can and can't see

We can see (health only)
  • Whether each router is online
  • Your routers' WireGuard public keys
  • Your home public IP & DDNS hostname
  • Your travel router's current network IP
  • Handshake timing & self-heal counts
  • Total bytes in/out (counters only)
  • Router model & firmware version
We cannot see
  • The sites you visit
  • The contents of your traffic
  • Your router admin password
  • Your card number (Stripe handles payment)
  • Anything once you unplug the routers

Full details are in our Privacy Policy.

No remote-management cloud

Setup happens locally over your own Wi-Fi. We do not use GL.iNet GoodCloud or any third-party remote-control service to reach your routers, and your router doesn't call any outside IP-lookup service — it learns its public IP from our own server.

If we ever disappear

Your VPN keeps running. It's standard WireGuard on hardware you own — it doesn't depend on us to keep working. That's the whole point of owning it.