The privacy design
Privacy as an absence, not a feature.
The strongest privacy guarantee any service can offer is not a clever control panel. It is the absence of a place where your data could have been kept.
No activity logs
We do not record the sites you visit, the content of your traffic, or your DNS queries. There is no store in the service that holds them, so there is nothing to leak, subpoena, or sell.
No connection logs
Your original IP address, the VPN address you are assigned, when you connected, and how long you stayed are not written down. Session data that has to exist while a session runs does not survive it.
No third-party sharing
Our Google Play Data safety declaration states that no user data is shared with third parties, and we do not sell personal information. If an advertising or analytics component is ever added, that declaration and our privacy policy are updated before it ships, not after.
Device identifiers, explained
The one data type our listing declares is "Device or other IDs". It lets the app behave correctly on your device and lets us defend the service against abuse. It is not a browsing record, and we would rather explain it than dodge it.
Nothing kept "just in case"
Diagnostic data is aggregated and anonymised before it is useful to us, and it carries no identifier that ties it back to a person. If we ever need more to solve your specific problem, we will ask you first.
No account to compromise
Version 1.0.0 ships with no accounts and no in-app purchases, so there is no password of yours to store and no payment record to protect. If that changes, the change will be announced, not slipped in.