Privacy
1. The short version
V Seti is a switch. When it is on, some apps go out through our node and all other traffic goes direct and stays untouched. To do that we need to know exactly two things: that you have a valid account, and which node you are assigned to. We need nothing else, and we collect nothing else.
We keep no traffic logs, no history of the addresses you reached, and no count of your megabytes. We do not know which sites or apps you open, when, or for how long. We do not sell data, we do not pass it to advertising networks, and this site runs no analytics or tracking scripts of any kind: the page you are reading makes no request to any third-party server.
Below is the full list of what does get written down — including what any server on the internet writes down simply because a connection arrived. We would rather state that plainly than leave it out: a policy that promises more than the system is built to do is not a promise, it is an inaccuracy.
2. What we collect
This is the complete list. If something is not on it, we do not have it — there is no field for it in the database.
- The device's public key. On first launch the app generates a key pair on the device. The secret half stays in the device's key store and never leaves it; only the public half reaches us. In return we issue an install identifier — a random string that says nothing about you — and store the platform (iPhone or Android) and the date the key is valid until alongside it.
- An Apple identifier, if you sign in with Apple. A stable string issued by Apple that does not contain your name. If you chose to have Apple relay your email address, we receive the relay address and never see the real one.
- An email address, only if you provide one. It exists to get you back into your account. Neither first launch nor daily use depends on it. Of the recovery message itself we keep only a hash of the link: what is in the database cannot be used to sign in.
- A hash of your recovery code on Android, where the account is the device key. The code itself is shown once and is not stored; it cannot be reconstructed from the hash.
- Subscription status — tier, end date, trial flag — and referral links: who invited whom, so both sides can be credited.
- The node and egress address assigned to you. One row per install: which node and which address you correspond to right now. Without it there is nowhere to route the connection. On reassignment that row is overwritten — there is no assignment history.
- An activity date — a date, with no time on it. Updated at most once a day, and used for exactly one thing: counting how many installs are active. There is no precise "last seen" here.
- Payment records: the method, the payment reference at the payment service, the amount, the status, and how many days it added. We never see or store card details — those stay with the payment service.
- Node reachability reports — when you tap "something's off" in the app and, if you allowed it, when the app could not confirm the route by itself. A report carries: which node, whether the connection established, how many bytes passed before it stalled, Wi-Fi or cellular, the port, and your carrier's autonomous system number — which names an entire network of millions of subscribers, not your address. The handshake time is rounded to a band rather than kept as measured. There is no install identifier in the row, and the timestamp is the server's, truncated to the hour. A row says "this node stopped responding on this carrier's network", never "this person's connection stopped".
- Aggregate node metrics — how much passed through a node in an interval and how many forwardings it held. That is the node's own counter: it has no link to an install, an account or an address.
- The server's system log. Our servers, like every server on the internet, see the address a connection arrives from, and the system log records the fact of the connection: time, address, result. It is not a traffic log — where you went next does not appear in it, and no content does. Those entries stay on the server, are not exported anywhere, are not matched against accounts, and are overwritten as the log fills. The account database has no address field in any table.
- Whatever you write to us yourself — a support email and anything you choose to attach to it.
3. What we do not collect
- Traffic logs. Not permanent, not temporary, not "while we debug".
- Any history of addresses, domains, DNS queries or connections.
- A per-user byte counter.
- A history of which nodes and addresses you were assigned before.
- Phone numbers. Never asked for, anywhere.
- Your name, date of birth or identity documents.
- Precise location or device sensor data.
- Advertising identifiers, browser fingerprints, or cookies on this site.
- The contents of messages, files or any other traffic — it passes through and is not retained.
This is a property of how the product is built rather than a promise about the future. Tiers differ by which services are routed, not by how many megabytes you use, so there is no per-user byte counter here — no reason to keep one, and no mechanism that would. For the same reason there is no table in which a connection could be tied to a person: the columns do not exist, and adding them would mean rewriting the database rather than changing a setting.
4. Why we need it
The install identifier and public key are what let a node accept the connection at all. The Apple identifier or email address is what stops you losing a paid tier when you change phones. Subscription status decides which set of services you receive. Reports are how we work out why the app behaved differently than it should. None of it is used for advertising, scoring or profiling, and we make no automated decisions that characterise you in any way.
5. Who we share it with
We do not share personal data with third parties for their own purposes. We do not sell it, rent it or trade it — not to advertising networks, not to data brokers, not to analytics providers.
We use a small number of contractors that process data only on our instructions and only for the tasks listed:
- hosting providers, whose servers run the nodes and the account database;
- a payment service that takes the payment and holds the payment details — we never see or store card numbers;
- an email service that delivers account-recovery messages, if you gave us an address.
That is the entire list. No third-party analytics, advertising or tracking library is built into the app, and there is none on this site either: it is markup plus a single stylesheet, it sets no cookies, and it keeps no visitor log.
6. How long we keep it
- Your account and everything attached to it — installs, node assignment, referral links, payment records — for as long as the account exists. All of it is tied to the account in the database and is deleted with it in one act, not by a separate procedure that could be forgotten.
- Node assignment — the current one only; on reassignment the previous value is overwritten rather than accumulated.
- Database backups roll over within 30 days. That is the last place a deleted record still exists for a while.
- Reachability reports and aggregate node metrics are tied neither to you nor to an install. We keep them for as long as they are useful for understanding the state of the network. For the same reason they cannot be produced on request, they cannot be deleted on request either: there is nothing in them that denotes you.
- System log entries on the servers are overwritten as the log fills and are copied nowhere.
- The payment service keeps its own records under its own rules and its own accounting obligations. Those are its data, not ours: deleting your account here does not affect them.
7. Your rights
You can ask for a copy of what we hold, correct it, delete your account entirely, or take your data in a machine-readable form. Deletion is available inside the app and needs no correspondence. Write to support@vseti.io if that is easier; we answer within 30 days and usually much sooner.
One honest caveat: those rights reach what can be connected to you. Reachability reports and aggregate metrics are not connected to you — they carry no install identifier and no address — so neither we nor anyone else can find "your" rows in them.
Withdrawing consent or deleting data does not affect the lawfulness of what was done before that point.
8. Government requests
We respond to legally valid requests from the jurisdiction the operator is subject to, and only to those. Even then we can produce only what exists — and connection and traffic histories do not. We do not create such logs on request and we do not switch them on "temporarily".
In practice that means: about an account we can say that it exists, what tier it is on, and which node it is assigned to right now. What you opened, when, and how much of it — nobody can say, including us, because it is written down nowhere.
9. Children
The service is not directed at children under 13, and we do not knowingly collect their data.
10. Changes
If this document changes we update the date at the top, and we show material changes in the app before they take effect.
11. Contact
support@vseti.io for anything about this document.