itzgee.com

questions

Straight answers.

What this is, how access works, where your data lives, and the things this design deliberately does not protect you from. Every answer points at the page that proves it — because the rest of this site would rather show you than tell you.

section 01

the basics

What is itzgee.com?

The public face of a private, self-hosted network. Two servers we run in the UK — Coventry and Maidenhead — joined by an encrypted tunnel, running a rack of open-source applications for photos, files, passwords, bookmarks and more. The people who use them are invited, one at a time. This site documents how it's built and shows what's running right now.

the origin story →

Why does a private network have a public website?

Because "trust me, it's private" is worth nothing. Almost everything claimed here is checkable from where you're sitting: /security fetches this site's own security headers using your browser while you watch, /mesh reads the live tunnel probe, and every application links to the upstream source you can read yourself. A site that shows the project running doesn't need to declare what it is.

What itzgee.com is not.

Not a cloud service you can buy. Not a VPN you can subscribe to. Not an email or hosting provider. Not open to public signup. And not a promise of enterprise reliability — one person maintains all of this by hand, which means no committee ever decides your data is now training material, and equally no on-call rota at three in the morning.

section 02

access & accounts

Can I sign up?

Not yet, and not to everything. Network accounts are being built — enough to raise a support ticket and track a store order. Access to the applications is a separate door and always will be: granted per application, per person, by invitation. Not a velvet rope — two servers hold a finite amount of storage, and every account is backup space and support time that comes from somewhere.

Why passkeys, and what if I lose my device?

There's no password anywhere in the login path — there never was one. A passkey lives on your device and is unlocked by fingerprint, face or PIN, so there's nothing to phish and nothing for a leaked credential list to match against. Lose the device and a fresh enrolment link is issued once it's established you're you; most people have theirs synced across their own devices anyway. The password manager is the deliberate exception — it keeps its own master password, so your passwords aren't locked behind the identity layer if that's ever down.

Does any of it cost money?

There's no bill for an account or for access to an application — what you get is included, not sold. Running costs come out of one pocket, and chipping in is entirely optional.

what it costs to keep on →

What am I agreeing to?

Two documents. The terms of use cover the deal — what we provide, what we don't promise, and how an account ends. The acceptable use policy is the shorter list of what you can't do with the network, and it's the one we point at if access ever has to be withdrawn.

the terms of use →

section 03

the apps

What runs on the network?

A rack of open-source applications, each in its own isolated container behind the same single sign-on — Immich for photos, Vaultwarden for passwords, FileBrowser for files, and several more besides. Each one carries a live status light and a link to the code it's actually running.

the full rack →

Are these your own apps?

No, and that's the point. Every application is an existing open-source project, run as published — what's built here is the infrastructure underneath: the servers, tunnels, identity layer and monitoring. If you can run them yourself, you probably should, and the upstream links are on this site precisely so you can go and do it. The reason this network exists is that self-hosting properly — patched, monitored, recoverable — is an ongoing job rather than an afternoon.

section 04

your data

Where does my data live, and who can read it?

On servers we run in two UK data centres, Coventry and Maidenhead. In fairness, Cloudflare's proxy fronts the public routes, so a request may cross its global edge before reaching the UK — the stored data itself doesn't leave. Access to data inside the applications is limited to what running the service requires: repairing a container, restoring a file. Not browsing out of curiosity.

the full policy →

Do you sell it, or train models on it?

No, and no. There's no advertising business, no data-broker relationship, and no profile of you to sell because none is ever built. Analytics is self-hosted and cookieless — it counts page views, sets no cookie, and sends nothing to Google, Meta or any ad network, because none of them is in the loop to send to.

How do I get my data out, or delete it?

Every application has its own export, and they're open-source projects using standard formats — photos are files, documents are Markdown, passwords export into something every other manager imports. You don't need anyone's cooperation to take your own data out, which is also why an abandoned upstream project would mean migrating rather than losing anything. For what the website holds rather than an app — account record, support history — open a ticket or email [email protected]. UK GDPR gives you the right to a copy and to deletion.

section 05

how it's built

How is it put together?

Two servers we run in UK data centres, joined by WireGuard tunnels doing two different jobs. A backbone joins the servers so they behave like one system. An exit routes a trusted device's whole connection out through one of the two servers and filters its DNS on the way, refusing advertising and tracker domains before the device ever connects to them. No tunnel has a login surface to attack. Every application sits in its own isolated container, with one reverse proxy as the single doorway.

both tunnels, in depth →

Does it go down?

Sometimes. Everything does. Rather than make a reliability claim on a page like this, the honest answer is status.itzgee.com — monitored live from our own second server in Maidenhead, and publishing what it finds either way. The status lights on this site read from that same feed.

live uptime →

Why should I trust one person with my photos?

Don't take it on trust. The applications are invitational precisely because "why trust this" shouldn't come down to a feeling. What's offered instead is checkable: three independent scanners audit this site live and you can run them yourself, the applications are open source and linked to their code, and uptime is published by a machine that isn't the one being measured. If what you actually want is a private network of your own, that's a fair conclusion — the last section covers it.

section 06

security

How is it secured?

Six layers, in order of contact — from a hardened edge that refuses plain HTTP, through a strict Content Security Policy with no inline code anywhere, to one passwordless identity provider fronting every application. Three independent scanners currently grade the site A+, and the panel at the top of /security is your own browser fetching those headers while you watch, so it isn't something you have to believe.

all six layers →

Have you had a breach?

No.

What are you not protecting me from?

Worth stating plainly. Your own device — if your laptop or phone is compromised, an encrypted tunnel doesn't save you. Your passkey's platform account: whoever can sign into that can sign in here. The exit tunnel makes your traffic private from the local network and your ISP; it doesn't make you anonymous, and it doesn't hide you from a site you've logged into. Nothing here defends against a legally compelled disclosure. And two servers with one maintainer is not high availability — this is built to keep your data private and intact, not guaranteed reachable at 3am.

section 07

the utils tools

What are qr., ip. and time.?

Three small utilities anyone can use, no account and no cost. qr. generates QR codes and also scans them — a scanner that shows you the destination before you visit it is a real defence against a malicious code stuck over a real one. ip. tells you what your connection reveals about you, with a DNS leak suite alongside it. time. is a clock and time-zone tool.

all three →

Do they track me?

No advertising, no third-party script, and even the fonts are served from our own servers. One thing worth being straight about: on ip. the geolocation lookups are made by your own browser directly against the IP data provider, so that provider sees your request rather than us sitting in the middle of it. It's disclosed under sub-processors.

section 08

getting in touch

I want in — what now?

There's no application form, and adding one would misrepresent how access works. What you can do is register for network updates — when something significant changes, everyone on that list hears about it. Name and email, nothing else.

Can I get something like this for myself?

Possibly, later. A pre-configured, managed private server — the same design as this one, set up and looked after for you — is a future product being worked towards separately. It doesn't exist yet and there's nothing to buy. If that's what you actually want, the honest advice today is to self-host from the list on /apps, or register for network updates so you hear when there's something real to look at.

How do I get in touch?

[email protected] reaches a person. If you hold a network account, a support ticket keeps the whole thread in one place. Found a security weakness? Same address — report it privately, and good-faith research is welcome. And if you'd rather just watch, the status page publishes live uptime, measured from the second server rather than the one being measured.