Privacy Policy
This Privacy Policy explains what data is processed when you use the
Nafanya VPS application (the “App”). The App is a client that provides a
convenient interface for connecting to the user's own servers on iOS, Android,
macOS and Windows. By default, the App contains no information about which
server to connect to: to establish a connection, the user must import a
configuration themselves — via a https:// link (a list of
configurations, opened from the browser through a deeplink) or manually by
pasting a vless:// link. Without an explicitly imported server, no
connection is established. We follow the principle of collecting only the
minimum data necessary.
The data controller is sole proprietor Dmitriev Maksim Aleksandrovich (“we”). For any data-related questions, contact t.me/nafanya_support.
In short
- The App is a client that provides an interface for connecting to servers that the user selects and imports.
- We do not log your traffic, visited websites or online activity.
- We do not sell or share your data with third parties and do not use it for advertising.
- Server configurations and settings are stored only on your device.
- The App contains no ads, no advertising identifiers and no cross-app tracking.
- The nafanya.wtf website uses anonymized Yandex Metrica analytics with Webvisor disabled — no session recording. See “Website analytics” for how to opt out.
What data is processed
1. Data stored only on your device
The following data is stored locally in the device’s secure storage and is never sent to our servers:
- connection configurations you import (
vless://links and server lists obtained via ahttps://link); - the server you selected;
- your settings: kill switch, custom DNS, routing settings (iOS), split tunneling and the list of selected apps, local-network sharing (Android).
You can delete this data at any time within the App or by uninstalling the App.
2. Data required to operate the connection
- Device IP address. When a connection is established, your IP address is technically visible to the server you connect to (a server that you select and import). This is required to route traffic. We do not keep connection logs and do not link your IP address to your identity.
- Configuration import. When you import a configuration, the App processes a
vless://link (a single configuration) or downloads, via ahttps://link, a server list provided by a third-party resource, along with its validity period. Choosing and trusting such a resource is at the user's discretion.
3. Crash diagnostics (anonymized)
In case of an error or failure in the App, anonymized technical data about the failure is sent via Google Firebase Crashlytics. It helps us find and fix problems and includes: device model, operating system version, App version, time and circumstances of the failure, the call stack, and a technical installation identifier generated by Crashlytics. This data does not identify you personally and contains no content of your traffic. Diagnostics are not sent in debug builds.
4. Update checks
To notify you about available updates, the App uses Google Firebase Remote Config and compares the current version with the latest one. No personal data is collected for this.
5. Website analytics for nafanya.wtf (cookies)
This section is about the website nafanya.wtf, not the App. The site runs the Yandex Metrica web analytics counter (counter ID 112451027), operated by YANDEX LLC (16 Lev Tolstoy St., Moscow 119021, Russia). It helps us understand how many people reach the site and which client builds they download, so we can improve the product. The legal basis is the website visitor's consent.
Yandex Metrica collects anonymized technical data about your visit:
- IP address (used for regional attribution and stored in anonymized form);
- browser and operating-system type and version, language, screen resolution, device type;
- the addresses of the site pages you view, the referrer and UTM tags;
- visit date, time, duration and page depth;
- clicks on the client download buttons — the
client_downloadgoal with parameters: platform (Android, iOS, Windows, macOS), the specific button, the source type (store or direct link) and the page language; - an aggregated click map for the page (click coordinates only, no page content).
To do this, Yandex Metrica cookies (_ym_uid, _ym_d,
_ym_isad and similar) and browser local-storage entries are saved in your
browser. They exist only to tell one visit from another and avoid counting the same
visitor twice.
Webvisor is disabled. We do not record or replay your sessions and do not track cursor movement, scrolling, keystrokes or the contents of input fields. We do not send your personal data to Metrica, do not use it for advertising or retargeting, and do not combine website data with App data. Yandex's processing is governed by the Yandex Privacy Policy and the Yandex Metrica Terms of Use.
How to opt out. You can stop this collection at any time:
- install the official Yandex Metrica opt-out add-on;
- block or delete cookies in your browser settings — the site keeps working;
- use private browsing or any tracker blocker.
Opting out does not restrict access to the site or to the App downloads.
What we do not do
The items below describe the App; website analytics are covered in the section above.
- We do not log the content of your traffic, DNS queries, visited sites or apps.
- We do not sell, rent or share personal data with third parties.
- We do not use the connection to display ads or alter content in other apps.
- We do not track you across other apps and websites; no advertising identifiers are used. The nafanya.wtf website analytics (see “Website analytics for nafanya.wtf”) operate only within this site, do not follow you to other services, and are not used for advertising or retargeting.
- We do not request access to contacts, photos, camera, microphone, location or Bluetooth.
Third-party services
The App uses Google services (Firebase Crashlytics and Firebase Remote Config). Their processing of data is governed by the Google Privacy Policy. The connection technology is built on the open-source Xray Core; the list of open-source components is available on the Licenses page. The nafanya.wtf website additionally uses Yandex Metrica (YANDEX LLC) — see “Website analytics for nafanya.wtf (cookies)”.
Encryption
The connection is encrypted using standard modern cryptographic protocols (based on the Xray Core engine with TLS and AES-family encryption). Communication with import links uses the secure HTTPS/TLS protocol.
Retention periods
- Configurations and settings are stored locally until you delete them in the App or uninstall the App.
- Anonymized crash data is stored in Firebase Crashlytics for the period set by Google (typically up to 90 days).
- We do not create or keep user-linked connection logs.
- Anonymized website analytics data is stored in Yandex Metrica for the period set by Yandex (visit data is typically kept for up to 25 months).
Your rights
Depending on your jurisdiction (including the GDPR for EU users and the CCPA for California users), you may have the right to access, correct, delete and restrict the processing of your data, as well as the right to object to processing. To exercise these rights, contact t.me/nafanya_support.
Data deletion
To delete local data it is enough to remove the imported configuration inside the App or uninstall the App.
Children
The App is not intended for individuals below the age at which, under the laws of their country, they can independently consent to data processing. We do not knowingly collect data from children.
Changes to this Policy
We may update this Policy from time to time. The current version is always available on this page; the last updated date is shown above.