Privacy

This is the complete list: not a general statement that we value privacy, but what is actually stored and what is absent.

Updated 29 August 2026 · service and Troywell VPN for iOS/Android

What we store

Email address, email verification and password
Email is used for registration, sign-in, recovery and essential messages. The password is stored only as an irreversible verifier, never as plaintext.
Apple or Google sign-in identifier
When you choose social sign-in, we link the provider’s opaque subject and verified email to the account. The sign-in token is verified but is not retained as a password.
Subscription and purchase history
Plan, Premium status and expiry, store, product identifier and transaction fingerprint are used to verify, restore and protect a purchase. We do not receive card numbers or bank credentials.
Active sessions and devices
Opaque session and installation identifiers, platform, device label and access fingerprint support sign-in, remote revocation and the five-device limit.
Aggregate traffic and quota period
We count total bytes for an account to enforce the 3 GiB monthly free allowance and the ten-second disconnect grace. This does not require browsing history or packet contents.
Your Telegram numeric identifier and username
May remain for existing website accounts that used Telegram. The Troywell mobile app offers Apple on iOS and Google on Android.
Password-reset and subscription emails
The recipient and message are encrypted while queued, then retained for 30 days after delivery or permanent failure and deleted automatically.
Action log: what you changed and when
Sign-in, security, subscription and device operations. It uses an internal account identifier rather than an email address or username.

What we do not store

None of the following is written to the database, logs, metrics or backups.

  • Websites you visit
  • IP addresses and domains you connect to
  • DNS queries
  • Traffic contents
  • Connection history or duration
  • The address from which you connect to a VPN node
  • Bank-card numbers and other payment credentials

Keys

The Reality private key and local Hysteria token never leave the node; they enter neither the central database nor backups. Device access material is stored encrypted.

// Mobile client

Troywell VPN on iOS and Android

Sign-in is required from first launch and VPN is unavailable without a verified account. Email registration is built into the app; Apple is also offered on iOS and Google on Android when enabled by the server. A free account receives 3 GiB per month and up to five devices; Premium removes the limit and advertising. No advertising SDK is active in the current build. This policy and the store declarations will be updated for the actual vendor before advertising is enabled.

What stays on the device

Session tokens, installation identifier and managed VPN configuration
Used to avoid asking for a password on every launch, account for the device and retrieve servers available to the account. Secrets are kept in protected system storage.
Selected server and protocol, favourites, ping results and speed-test history
Stored only on the device to restore your choices and show measurement history. They are not sent to an app analytics service: the client contains neither an analytics backend nor an analytics SDK.

Where the app connects

This is the complete list of first- and third-party destinations used by the client, excluding websites you choose to open through the VPN.

Troywell VPN API

When

During registration, sign-in, email verification, session refresh, VPN profile retrieval, quota checks, purchases and account deletion.

What it sees

The API receives the account data listed above and ordinary HTTPS connection data, including the source IP. Passwords and store tokens are excluded from error messages.

Apple and Google

When

When Apple sign-in is selected on iOS or Google sign-in on Android, and when Premium is purchased or restored through a store.

What it sees

The provider processes sign-in and the store transaction under its own terms. Troywell VPN receives verified identity and purchase proof, but not bank-card details.

Selected VPN node

When

Only while the VPN connects and operates.

What it sees

The node necessarily sees the source IP and destinations to which it forwards traffic, but Troywell VPN does not write them to its database, logs, metrics or backups. HTTPS content remains encrypted between you and the destination website.

Cloudflare

When

For the public-IP check, an explicit speed test and DNS-over-TLS to 1.1.1.1 inside the tunnel.

What it sees

A direct check exposes the device public IP; with VPN and DNS connected it exposes the node address. The speed test sends randomly generated bytes, never files or device contents.

Google gstatic.com

When

Only when you start a server ping test.

What it sees

The request passes through the node being tested, so Google sees that node address, not the saved profile or subscription link.

Permissions

  • VPN: the system permission creates a tunnel after your action; connecting is impossible without it.
  • Notifications: requested in the context of a quota warning. The app says that the free allowance is exhausted and the connection will end in 10 seconds; background APNs/FCM delivery is not currently used.

Deleting app data

Signing out removes local session tokens and blocks VPN until the next sign-in. Deleting the account in the app stops VPN, clears local account state and asks the server to delete the account. Uninstalling the app also removes its local data.

Deletion

You can delete the account inside Troywell VPN or through the public account deletion page. Fresh identity confirmation is required before the irreversible action. The account, sign-in identities, active sessions, devices, VPN access and associated entitlement are removed. Cancel an App Store or Google Play subscription separately in the store to stop future charges.

The action log remains because a hash chain protects it from retrospective changes, and deleting entries would break that protection. It contains neither Telegram details nor username, only an internal identifier that points to nothing after account deletion.