Disclosure Note
This Statement helps configure Apple App Store App Privacy and Google Play Data Safety disclosures. Final answers must be based on the released code, third-party SDKs, server logs, and configuration—not this webpage alone.
“Collection” generally means data transmitted off-device and retained by the operator or a service provider. Data processed transiently only to complete a network request and not retained must be assessed under the platform’s current definitions.
1. Core Commitments
- No logging or retention of URLs, page bodies, chat content, or browsing history;
- no sale of user data;
- no advertising tracking or profiling based on VPN activity;
- no disclosure of VPN traffic to unrelated third parties.
2. Data Categories That May Be Collected
| Category | May be collected | Linked | Tracking | Purpose and typical retention |
| Contact info: registration email | Yes, when registering | Yes | No | Sign-in, security notices, support; while account is active |
| User identifier: account ID | Yes | Yes | No | Account, device, and entitlement identification; while account is active |
| Device identifier: limited device / installation ID | Depending on version | Potentially | No | Guest access, device management, security; generally up to 180 days or account life |
| Purchases: product, transaction ID, subscription state | Yes, when purchased | Yes | No | Entitlement checks, reconciliation, refund support; retained as legally required |
| Usage: launch, selected node / region, connection result and duration | Depending on diagnostics | Potentially | No | Routing, capacity, troubleshooting; generally up to 90 days |
| Diagnostics: crash, performance, error code | Depending on version | Potentially | No | Stability and compatibility; generally up to 90 days |
| Coarse region / network information | Depending on route features | Potentially | No | Regional recommendation, security, connection; generally up to 90 days |
| User content: feedback text, voluntarily uploaded screenshots or logs | Only when submitted | Yes | No | Customer support; generally up to 12 months |
3. Content Not Collected as Persistent Data
| Category | Status | Explanation |
|---|
| Browsing history, URLs, page or communication content | Not collected / retained | Traffic is processed transiently only to establish and carry the VPN tunnel |
| Precise GPS location | Not collected | Route recommendation does not require precise GPS |
| Contacts | Not collected | Not required by the core service |
| Camera and microphone | Not collected | Not required by the core service; voluntary support attachments use the system picker |
| Complete bank or payment-card information | Not received | Handled by Apple, Google, or the payment provider |
| Advertising identifier / ad data | Not used for ad tracking | No cross-app advertising profile |
4. Third-Party Processing Categories
- App stores: purchase, subscription, and receipt validation;
- cloud and network infrastructure: account APIs, routes, and nodes;
- diagnostic services: crash, error, and performance data where actually integrated;
- email / support: service notices and support requests.
Before release, maintain an actual SDK inventory and review each provider’s privacy manifest, required-reason APIs, uploads, and retention behavior.
5. User Controls
- Review account, device, and subscription status in the App;
- disable optional permissions and optional diagnostics in system or app settings;
- initiate account deletion in the App;
- email support for access, correction, deletion, or an explanation.
6. Pre-Submission Consistency Check
- Review actual fields uploaded by the client and all SDKs;
- review server, CDN, load-balancer, and node logs;
- review collection, linkage, tracking, and purposes in App Store Connect;
- align the Privacy Policy and this Statement;
- ensure an app that creates accounts also provides in-app initiation of deletion;
- ensure VPN traffic is not sold or used for unrelated purposes and that the Privacy Policy expressly commits to this.