Privacy Policy

Updated: 2026-04-19

The short version: we can't see your traffic. Here are the details.

What we don't know

  • Your traffic — end-to-end encrypted between the client and whichever server you use.
  • Your keys — kept in iOS Keychain / Apple Keychain, never on our servers.
  • Which sites you open, what you download, who you talk to.
  • What passes between your devices via iCloud sync — Apple encrypts that on their side.

What we do know (minimum)

  • Your IP at session start — only when establishing a connection to our API. Not logged, retained less than 5 seconds.
  • Your Apple ID via iCloud — if you enable sync, Apple knows which servers you saved. We don't.
  • Your device token — only appears if you sign up for our future paid hosting. Until then, it doesn't exist.

Where data goes

Nowhere except:

  • Your iCloud — for sync between iPhone and Mac.
  • Local core — sing-box runs inside the Network Extension on your device.

Firebase, Amplitude, ad SDKs, Google Analytics — zero of any. Auditable directly in source.

Diagnostics and crash reporting

We run self-hosted Sentry for crash logs. It's opt-in — nothing is sent by default. Even when enabled:

  • Events are sanitized: no URLs, no IPs.
  • Stored on our infrastructure, not Sentry Inc.
  • Can be turned off in Settings any time.

iCloud / CloudKit

We use Apple CloudKit Private Database for device sync. Apple-standard end-to-end encryption. Apple's Privacy Manifest for iCloud applies in full.

Cookies and localStorage on the site

  • kvn-lang — cookie, saves your language choice.
  • kvn-theme — localStorage, saves light/dark preference.

No site analytics in the MVP. No third-party cookies.

Contact

Changes

Material changes announced in Telegram and GitHub releases 14 days before they take effect. Revision history lives in Git.