Privacy Policy
Updated: 2026-04-19
The short version: we can't see your traffic. Here are the details.
What we don't know
- Your traffic — end-to-end encrypted between the client and whichever server you use.
- Your keys — kept in iOS Keychain / Apple Keychain, never on our servers.
- Which sites you open, what you download, who you talk to.
- What passes between your devices via iCloud sync — Apple encrypts that on their side.
What we do know (minimum)
- Your IP at session start — only when establishing a connection to our API. Not logged, retained less than 5 seconds.
- Your Apple ID via iCloud — if you enable sync, Apple knows which servers you saved. We don't.
- Your device token — only appears if you sign up for our future paid hosting. Until then, it doesn't exist.
Where data goes
Nowhere except:
- Your iCloud — for sync between iPhone and Mac.
- Local core — sing-box runs inside the Network Extension on your device.
Firebase, Amplitude, ad SDKs, Google Analytics — zero of any. Auditable directly in source.
Diagnostics and crash reporting
We run self-hosted Sentry for crash logs. It's opt-in — nothing is sent by default. Even when enabled:
- Events are sanitized: no URLs, no IPs.
- Stored on our infrastructure, not Sentry Inc.
- Can be turned off in Settings any time.
iCloud / CloudKit
We use Apple CloudKit Private Database for device sync. Apple-standard end-to-end encryption. Apple's Privacy Manifest for iCloud applies in full.
Cookies and localStorage on the site
kvn-lang— cookie, saves your language choice.kvn-theme— localStorage, saves light/dark preference.
No site analytics in the MVP. No third-party cookies.
Contact
- GitHub: open an issue
- Telegram: @kvn_app
- Email: privacy@replio.run
Changes
Material changes announced in Telegram and GitHub releases 14 days before they take effect. Revision history lives in Git.