Last updated: September 16, 2026
This policy and these terms cover HTTP Tweak on Android and iOS, and the web panel.
1. Overview
The operator of HTTP Tweak ("we," "us," or "our") is responsible for the personal data described in this policy. The mobile VPN application can be used without creating a panel account. A panel account is optional and provides access to configuration-management, API, community, and tutorial features. The Android app also offers an optional PRO subscription through Google Play. This policy explains what data we process, why we process it, when we share it, how long we keep it, and the choices available to you.
2. Information we process
- Panel account and authentication data: Username, protected account credentials, account status, resource limits, and account activity timestamps. Password Recovery Keys are shown only when issued or replaced; replacing or using a key invalidates the previous key.
- Device and entitlement data: A device identifier, device public key or key hash, security or integrity status, current subscription tier and expiry, purchase-to-device association, and device or entitlement activity timestamps. This data supports device authentication, abuse prevention, purchase restoration, and enforcement of the active-device allowance.
- Google Play purchase history: When you purchase or restore PRO, we receive and store a Google Play purchase token (encrypted at rest, with a separate hash used for lookup), product and base-plan identifiers, subscription state, expiry, automatic-renewal status, acknowledgement status, whether it is a test purchase, and verification timestamps. We do not receive or store your full payment-card or bank-account details. Google Play handles checkout and payment processing.
- Apple App Store (iOS): Apple processes iOS payments. We send purchase evidence to Apple for verification and store transaction identifiers, product, environment, expiry and renewal/verification status to verify and restore PRO access and prevent fraud. We do not receive card details. Records are retained as needed for verification, support and legal obligations.
- Google AdMob: The free Android and iOS apps use Google AdMob. It may process device, network and advertising data according to your privacy choices. We do not provide VPN traffic to advertising services. Depending on consent and SDK settings, AdMob may process IP addresses and approximate location, device identifiers, ad views and interactions, and crash or performance data for advertising, analytics and fraud prevention. Where available, you can review or change your choices through Privacy choices in the app.
- Panel content: Configurations, server and tweak details, access-control settings, and other content you choose to create, import, or manage in the panel. The mobile app does not upload your locally stored configurations to the panel unless you use a feature that sends them to the service.
- API account data: Client or Business API account status, quota and usage information and, for Business API users, the business name, contact email, optional website, and quota-request details you provide. API credentials are shown when issued or rotated and are then retained only in protected form.
- Business API request data: Parameters submitted to the Business API are used to generate the requested response and are not added to your saved panel configurations. Limited diagnostic information may be processed when needed to troubleshoot or secure the service.
- Community submissions: The country, group name, description, and join link you choose to submit to the public community directory.
- Mobile app telemetry: Connection success or failure, related configuration identifiers, tunnel type, app version, approximate country, and a pseudonymous device identifier. This telemetry does not include browsing activity, traffic contents, or precise location. These reports also include event timestamps, server and tweak identifiers, and network type. They are associated with a device identifier and are not anonymous. We use them to measure connection reliability and investigate service failures, not to record browsing activity.
- Website and API technical data: IP address, browser or device information, access logs, API route and response details, app version, and security signals such as rate-limit or integrity-check failures. We may use pseudonymous identifiers when raw identifiers are not needed.
- Approximate country: We may use a country code supplied by our network provider to localize features and produce regional service statistics. We do not use this feature to collect precise location.
- Cookies and local preferences: Strictly necessary session, security, and preference data used to authenticate users and operate the panel. We do not use advertising cookies.
3. Information we do not collect from VPN traffic
We do not collect browsing history, traffic destinations, DNS queries, or the contents of traffic passing through a VPN connection. Connection telemetry reports service events such as success or failure, not what you browse, access, or transmit. The app may offer optional servers made available by the platform, and users may also add or import their own servers. A platform-provided server may use infrastructure operated by us or by an independent provider. Third-party servers remain subject to their operator's privacy and security practices.
4. How and why we use information
Android and iOS send connection statistics to our server to help maintain service reliability.
We process information to provide requested features; authenticate accounts and devices; verify, acknowledge, restore, and synchronize Google Play subscriptions; apply subscription benefits and active-device limits; manage configurations, APIs, tutorials, and communities; secure the service and prevent purchase fraud or token reuse; enforce our Terms; respond to support and legal requests; measure reliability and performance; and improve the service. Where applicable, our legal bases include performing the service you request, our legitimate interests in operating and securing the service, your consent when requested, and compliance with legal obligations.
Optional PRO purchases are processed by Google Play on Android and by Apple App Store on iOS. We share purchase evidence with the relevant store and retain purchase and entitlement records as needed for verification, restoration, support, fraud prevention and legal obligations.
Automated security controls may rate-limit, challenge, or block requests based on abuse, authentication, or integrity signals. If you believe a security restriction was applied incorrectly, you may contact us for review.
5. Sharing and international processing
We do not sell personal data or provide VPN traffic to advertising services. Advertising SDK data processing is described above. We may also disclose data in the following circumstances:
- To infrastructure, hosting, communications, platform-integrity, and security providers that process data for us under appropriate restrictions.
- To Google Play and Google APIs as necessary to process, verify, acknowledge, restore, and synchronize a PRO purchase, including cancellation, renewal, grace-period, account-hold, expiration, refund, and revocation events. Google's handling of checkout and payment information is governed by its own policies.
- Cloudflare processes connection data as our reverse proxy and security provider. Confirmed abusive IP addresses may be placed in a Cloudflare-managed firewall list so requests can be blocked before reaching our application.
- When you direct us to publish or share content, such as a community submission or shared configuration.
- When reasonably necessary to comply with law, respond to valid legal process, protect rights and safety, or investigate abuse.
- As part of a merger, acquisition, reorganization, or transfer of the service, subject to applicable law.
Our providers may process data in countries other than your own. Where required, we use appropriate safeguards for international transfers.
6. Data retention
We keep personal data only for as long as needed for the purposes described above, to meet legal obligations, or to establish or defend legal claims. In particular:
- Account, device, API, configuration, and community data are retained while the related account, device, content, or feature remains active and as needed to operate the service. Devices that have no active subscription and remain inactive for at least 1 year may be automatically deleted.
- Google Play purchase and entitlement records are retained while needed to verify or restore access, synchronize subscription state, resolve billing or support disputes, prevent fraud or token reuse, and meet accounting, legal, or audit obligations. Relevant records may remain after cancellation, expiration, refund, revocation, or replacement of a linked device for those purposes.
- Cloud-export shares are removed after 7 days of inactivity, and protected configuration exports are removed after 1 month of inactivity.
- Panel configurations older than 3 months may be removed automatically only when they contain no servers and no tweaks.
- Raw mobile analytics event files are normally removed within 3 days after processing; failed event batches may be retained for up to 14 days. Aggregated or de-identified statistics may be kept longer.
- Technical logs are retained for a limited period based on operational, security, and legal needs. IP-address security-signal records follow the configured analytics retention period, which is 365 days by default.
- IP addresses selected for temporary Cloudflare security blocks are retained until the block expires or is removed. Permanent blocks remain until an administrator removes them. The local synchronization record is deleted after Cloudflare confirms removal.
Deleting an account removes associated data from active systems, subject to legal requirements, security needs, and routine backup cycles.
7. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal data. No online service or storage system can guarantee absolute security, so you should also protect your account and recovery credentials.
8. Your rights and choices
You can update certain account information or delete your account from the panel. You can manage or cancel PRO through Google Play; canceling stops future renewal but does not itself delete purchase-verification records. Depending on applicable law, you may also request access to, correction of, deletion of, or a copy of your personal data; object to or restrict certain processing; withdraw consent where processing is based on consent; and lodge a complaint with the Philippine National Privacy Commission or another competent data-protection authority. Some requests may be limited where retention or processing is required by law or necessary to protect legal rights, prevent fraud, or maintain transaction records.
On iOS, manage or cancel PRO through Apple subscriptions. Canceling does not itself delete purchase-verification records.
9. Children
The service is not intended for children under 13. Users below the age of legal majority in their jurisdiction must have permission from a parent or legal guardian. If you believe a child provided personal data contrary to these requirements, please contact us.
10. Changes to this policy
We may update this policy as the service or legal requirements change. We will update the date above and provide additional notice when required by law.
11. Contact and privacy requests
To ask a privacy question, exercise a privacy right, or report suspected misuse of personal data, contact the operator of HTTP Tweak at [email protected].