Privacy Policy
Effective: August 2026
ODVPN is built so that we cannot know what you do with the service, not merely that we promise not to look. This policy explains the architecture that makes that true.
What we don't collect
- Traffic logs. We never inspect, record, or store what you browse, download, or stream through the VPN tunnel.
- Your identity. Authentication is handled by Sign in with Apple, which provides a private relay identifier. We don't receive your name, email address, or Apple ID.
- Device identifiers. We don't collect IDFA, device serial numbers, or fingerprinting data.
What we do store
- A session ledger. For each connection event we record: your client IP address, session timestamps, AWS region, and instance ID. This is linked to your anonymous Apple relay identifier and used for billing and abuse prevention. These records auto-delete after one year.
- Purchase records. Apple handles payment. We receive a transaction ID and the product purchased (e.g. "90 minutes") to credit your balance. We never see your payment method or billing address.
How authentication works
You sign in with Apple. Apple provides ODVPN with a unique, private identifier (not your real Apple ID or email). This identifier is used only to look up your minute balance. If you delete your account, this identifier and all associated billing records are deleted.
How sessions work
When you tap Connect:
- A fresh EC2 instance launches in your chosen AWS region.
- The instance generates ephemeral EAP credentials (username + password) valid only for this session.
- Your device connects via IKEv2 using those credentials.
- When you disconnect (or the session times out), the instance self-terminates and the credentials are destroyed.
There is no shared server, no persistent disk, and no way to reconstruct what happened on an instance after it's gone.
Third-party services
- Amazon Web Services (AWS). VPN instances run on AWS EC2. AWS processes the network traffic while your session is active. AWS's data processing terms apply to their infrastructure. We don't enable VPC Flow Logs or any traffic capture.
- Apple App Store. Purchases and account management are handled by Apple under their own privacy policy.
We use no analytics SDKs, no crash reporting services, and no advertising networks.
Data retention
- Session ledger: auto-deleted after one year via DynamoDB TTL. Deleted immediately if you delete your account.
- Session infrastructure: destroyed within 15 minutes of disconnect. No backups, no snapshots.
Your rights
You can delete your account and all associated data from within the app (Settings → Delete Account). This removes your billing ledger, minute balance, and the anonymous identifier. The action is immediate and irreversible.
Children
ODVPN is not directed at children under 13. We don't knowingly collect information from children.
Changes to this policy
If we change this policy, we'll update the effective date at the top. Material changes will be communicated through an in-app notice before they take effect.
Questions? odvpn@stormacq.net