Privacy Policy

Last updated: July 21, 2026

1. Overview

The operator of HTTP Tweak ("we," "us," or "our") is responsible for the personal data described in this policy. The mobile VPN application can be used without creating a panel account. A panel account is optional and provides access to configuration-management, API, community, and tutorial features. This policy explains what data we process, why we process it, when we share it, how long we keep it, and the choices available to you.

2. Information we process

  • Panel account and authentication data: Username, protected account credentials, account status, resource limits, and account activity timestamps. Password Recovery Keys are shown only when issued or replaced; replacing or using a key invalidates the previous key.
  • Device and subscription data: A device identifier, device public key, security or integrity status, subscription status and expiry, and device activity timestamps. This data supports device authentication, abuse prevention, and subscription features.
  • Panel content: Configurations, server and tweak details, access-control settings, and other content you choose to create, import, or manage in the panel. The mobile app does not upload your locally stored configurations to the panel unless you use a feature that sends them to the service.
  • API account data: Client or Business API account status, quota and usage information and, for Business API users, the business name, contact email, optional website, and quota-request details you provide. API credentials are shown when issued or rotated and are then retained only in protected form.
  • Business API request data: Parameters submitted to the Business API are used to generate the requested response and are not added to your saved panel configurations. Limited diagnostic information may be processed when needed to troubleshoot or secure the service.
  • Community submissions: The country, group name, description, and join link you choose to submit to the public community directory.
  • Mobile app telemetry: Connection success or failure, related configuration identifiers, tunnel type, app version, approximate country, and a pseudonymous device identifier. This telemetry does not include browsing activity, traffic contents, or precise location.
  • Website and API technical data: IP address, browser or device information, access logs, API route and response details, app version, and security signals such as rate-limit or integrity-check failures. We may use pseudonymous identifiers when raw identifiers are not needed.
  • Approximate country: We may use a country code supplied by our network provider to localize features and produce regional service statistics. We do not use this feature to collect precise location.
  • Cookies and local preferences: Strictly necessary session, security, and preference data used to authenticate users and operate the panel. We do not use advertising cookies.

3. Information we do not collect from VPN traffic

We do not collect browsing history, traffic destinations, DNS queries, or the contents of traffic passing through a VPN connection. Connection telemetry reports service events such as success or failure, not what you browse, access, or transmit. The app may offer optional servers made available by the platform, and users may also add or import their own servers. A platform-provided server may use infrastructure operated by us or by an independent provider. Third-party servers remain subject to their operator's privacy and security practices.

4. How and why we use information

We process information to provide requested features; authenticate accounts and devices; manage subscriptions, configurations, APIs, tutorials, and communities; secure the service and prevent abuse; enforce our Terms; respond to support and legal requests; measure reliability and performance; and improve the service. Where applicable, our legal bases include performing the service you request, our legitimate interests in operating and securing the service, your consent when requested, and compliance with legal obligations.

Automated security controls may rate-limit, challenge, or block requests based on abuse, authentication, or integrity signals. If you believe a security restriction was applied incorrectly, you may contact us for review.

5. Sharing and international processing

We do not sell personal data or use it for third-party advertising. We may disclose data:

  • To infrastructure, hosting, communications, platform-integrity, and security providers that process data for us under appropriate restrictions.
  • Cloudflare processes connection data as our reverse proxy and security provider. Confirmed abusive IP addresses may be placed in a Cloudflare-managed firewall list so requests can be blocked before reaching our application.
  • When you direct us to publish or share content, such as a community submission or shared configuration.
  • When reasonably necessary to comply with law, respond to valid legal process, protect rights and safety, or investigate abuse.
  • As part of a merger, acquisition, reorganization, or transfer of the service, subject to applicable law.

Our providers may process data in countries other than your own. Where required, we use appropriate safeguards for international transfers.

6. Data retention

We keep personal data only for as long as needed for the purposes described above, to meet legal obligations, or to establish or defend legal claims. In particular:

  • Account, device, API, configuration, and community data are retained while the related account, device, content, or feature remains active and as needed to operate the service. Accounts and devices inactive for at least 1 year may be automatically deleted.
  • Cloud-export shares are removed after 7 days of inactivity, and protected configuration exports are removed after 1 month of inactivity.
  • Panel configurations older than 3 months may be removed automatically only when they contain no servers and no tweaks.
  • Raw mobile analytics event files are normally removed within 3 days after processing; failed event batches may be retained for up to 14 days. Aggregated or de-identified statistics may be kept longer.
  • Technical logs are retained for a limited period based on operational, security, and legal needs. IP-address security-signal records follow the configured analytics retention period, which is 365 days by default.
  • IP addresses selected for temporary Cloudflare security blocks are retained until the block expires or is removed. Permanent blocks remain until an administrator removes them. The local synchronization record is deleted after Cloudflare confirms removal.

Deleting an account removes associated data from active systems, subject to legal requirements, security needs, and routine backup cycles.

7. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal data. No online service or storage system can guarantee absolute security, so you should also protect your account and recovery credentials.

8. Your rights and choices

You can update certain account information or delete your account from the panel. Depending on applicable law, you may also request access to, correction of, deletion of, or a copy of your personal data; object to or restrict certain processing; withdraw consent where processing is based on consent; and lodge a complaint with the Philippine National Privacy Commission or another competent data-protection authority. Some requests may be limited where retention or processing is required by law or necessary to protect legal rights.

9. Children

The service is not intended for children under 13. Users below the age of legal majority in their jurisdiction must have permission from a parent or legal guardian. If you believe a child provided personal data contrary to these requirements, please contact us.

10. Changes to this policy

We may update this policy as the service or legal requirements change. We will update the date above and provide additional notice when required by law.

11. Contact and privacy requests

To ask a privacy question, exercise a privacy right, or report suspected misuse of personal data, contact the operator of HTTP Tweak at [email protected].