Privacy
1. The short version
V Seti is a switch. When it is on, some apps go out through our node and all other traffic goes direct and stays untouched. To do that we need to know exactly two things: that you have a valid account, and which node you are assigned to. Everything else on the list below exists only because without it we could not take a payment or tell that a node stopped answering.
We keep no traffic logs, no history of the addresses you reached, and no count of your megabytes. We do not know which sites or apps you open, when, or for how long. The app sends us nothing about any of that — not once, and not under any setting. We do not sell data and we do not pass it to advertising networks.
The vseti.io website is a separate thing, and it is described separately in section 4: it counts visits, the way nearly every website does. The app has nothing to do with that counter.
Below is the full list of what does get written down — including what any server on the internet writes down simply because a connection arrived. We would rather state that plainly than leave it out: a policy that promises more than the system is built to do is not a promise, it is an inaccuracy.
2. What we collect
This is the complete list. If something is not on it, we do not have it — there is no field for it in the database.
- The device's public key. On first launch the app generates a key pair on the device. The secret half stays in the device's key store and never leaves it; only the public half reaches us. In return we issue an install identifier — a random string that says nothing about you — and store the platform (iPhone or Android) and the date the key is valid until alongside it.
- An Apple identifier, if you sign in with Apple. A stable string issued by Apple that does not contain your name. If you chose to have Apple relay your email address, we receive the relay address and never see the real one.
- An email address, only if you provide one. It exists to get you back into your account. Neither first launch nor daily use depends on it. Of the recovery message itself we keep only a hash of the link: what is in the database cannot be used to sign in.
- A hash of your recovery code on Android, where the account is the device key. The code itself is shown once and is not stored; it cannot be reconstructed from the hash.
- How many days are left — one date — and who invited whom, so both sides can be credited. Plus a device fingerprint: a one-way digest of a value the operating system itself supplies, kept apart from accounts. It answers one question — has this device already been credited — and no other.
- The node and egress address assigned to you. One row per install: which node and which address you correspond to right now. Without it there is nowhere to route the connection. On reassignment that row is overwritten — there is no assignment history.
- An activity date — a date, with no time on it. Updated at most once a day, and used for exactly one thing: counting how many installs are active. There is no precise "last seen" here.
- Payment records: the method, the payment reference at the payment service, the amount, the status, and how many days it added. We never see or store card details — those stay with the payment service.
- Node reachability reports — when you tap "Support" in the app and, if you allowed it, when the app could not confirm the route by itself. A report carries: which node, whether the connection established, how many bytes passed before it stalled, Wi-Fi or cellular, the port, and your carrier's autonomous system number — which names an entire network of millions of subscribers, not your address. The handshake time is rounded to a band rather than kept as measured. There is no install identifier in the row, and the timestamp is the server's, truncated to the hour. A row says "this node stopped responding on this carrier's network", never "this person's connection stopped".
- Aggregate node metrics — how much passed through a node in an interval and how many forwardings it held. That is the node's own counter: it has no link to an install, an account or an address.
- The server's system log. Our servers, like every server on the internet, see the address a connection arrives from, and the system log records the fact of the connection: time, address, result. It is not a traffic log — where you went next does not appear in it, and no content does. Those entries stay on the server, are not exported anywhere, are not matched against accounts, and are overwritten as the log fills. The account database has no address field in any table.
- Whatever you write to us yourself — a message sent from Support inside the app, an email to hello@vseti.io, and anything you choose to attach to it. The in-app conversation is stored on our own servers so you can see the reply where you asked the question; it goes when your account goes, along with everything else.
3. What we do not collect
- Traffic logs. Not permanent, not temporary, not "while we debug".
- Any history of addresses, domains or DNS queries — that is, of where you went.
- A connection log attached to a person. The server's system log in section 2 is a short, self-overwriting window that we match against nothing.
- A per-user byte counter.
- A history of which nodes and addresses you were assigned before.
- Phone numbers. Never asked for, anywhere.
- Your name, date of birth or identity documents.
- Precise location or device sensor data.
- Advertising identifiers, browser fingerprints, or cookies.
- The contents of messages, files or any other traffic — it passes through and is not retained.
This is a property of how the product is built rather than a promise about the future. What you have is days, not an allowance of megabytes, so there is no per-user byte counter here — no reason to keep one, and no mechanism that would. For the same reason there is no table in which a connection could be tied to a person: the columns do not exist, and adding them would mean rewriting the database rather than changing a setting.
4. The vseti.io website
Everything above is about the app and the nodes. The website works differently, and it is more honest to describe it on its own than to bury one line of it in a list about something else.
The website counts visits. The counter is our own, not an advertising network's. It records which page was opened, where the visit came from, the country of the connecting address, the screen size and the browser language. Nothing else.
It sets no cookies. The visit id lives in the tab's own memory and disappears with it: tomorrow is a different visit, and there is nothing to join the two together.
The app sends nothing here. The counter sees browsers, not installs: there is no field in it that could tie a visit to an account, a device or a node. Nor will there be — these are two separate systems, not one system with two doors.
We do not sell what the counter records, and we pass it to nobody. Everything said about the app — the traffic logs, the addresses, the megabytes — stays true whether you ever opened this website or not.
The install page links to the App Store, where the app is hosted. The store page is served by Apple's own servers, and the visit to it is not part of our counter: we do not learn whether you went there or what you did there. Until the app is actually in the App Store, the iPhone button says "soon" and offers to take an email address — so we can write when it is there. That address goes to our own server (api.cfgnode.com), sits in a single waiting list, and is used for nothing else: not mailings, not advertising, not the counter. You can ask to be removed from the list at any time by writing to hello@vseti.io. The Android installable file is served from this site itself, and downloading it looks to the counter like an ordinary page visit.
5. Why we need it
The install identifier and public key are what let a node accept the connection at all. The Apple identifier or email address is what stops you losing your remaining days when you change phones. The end date decides whether the connection works right now. The device fingerprint is what makes an invitation credit a person rather than a reinstall. Reports are how we work out why the app behaved differently than it should. None of it is used for advertising, scoring or profiling, and we make no automated decisions that characterise you in any way.
6. Who we share it with
We do not share personal data with third parties for their own purposes. We do not sell it, rent it or trade it — not to advertising networks, not to data brokers, not to analytics providers.
We use a small number of contractors that process data only on our instructions and only for the tasks listed:
- hosting providers, whose servers run the nodes and the account database;
- a payment service that takes the payment and holds the payment details — we never see or store card numbers;
- an email service that delivers account-recovery messages, if you gave us an address.
That is the entire list. No third-party analytics, advertising or tracking library is built into the app. There is none on the website either: the visit counter there is our own, it sets no cookies, and what it records is set out in section 4.
7. How long we keep it
- Your account and everything attached to it — installs, node assignment, referral links, payment records — for as long as the account exists. All of it is tied to the account in the database and is deleted with it in one act, not by a separate procedure that could be forgotten.
- Node assignment — the current one only; on reassignment the previous value is overwritten rather than accumulated.
- Database backups roll over within 30 days. That is the last place a deleted record still exists for a while.
- Reachability reports and aggregate node metrics are tied neither to you nor to an install. We keep them for as long as they are useful for understanding the state of the network. For the same reason they cannot be produced on request, they cannot be deleted on request either: there is nothing in them that denotes you.
- System log entries on the servers are overwritten as the log fills and are copied nowhere.
- The payment service keeps its own records under its own rules and its own accounting obligations. Those are its data, not ours: deleting your account here does not affect them.
8. Your rights
You can ask for a copy of what we hold, correct it, delete your account entirely, or take your data in a machine-readable form. Deletion is available inside the app and needs no correspondence. Write to hello@vseti.io if that is easier; we answer within 30 days and usually much sooner.
One honest caveat: those rights reach what can be connected to you. Reachability reports and aggregate metrics are not connected to you — they carry no install identifier and no address — so neither we nor anyone else can find "your" rows in them.
Withdrawing consent or deleting data does not affect the lawfulness of what was done before that point.
9. Government requests
We respond to legally valid requests from the jurisdiction the operator is subject to, and only to those. Even then we can produce only what exists — and a history of where you went does not. We do not create such logs on request and we do not switch them on "temporarily".
In practice that means: about an account we can say that it exists, how many days it has, and which node it is assigned to right now. What you opened, when, and how much of it — nobody can say, including us, because it is written down nowhere. The only thing about connections that exists at all is the system log from section 2: a short, self-overwriting window of addresses and times, with not one byte of what went through them.
10. Children
The service is not directed at children under 13, and we do not knowingly collect their data.
11. Changes
If this document changes we update the date at the top, and we show material changes in the app before they take effect.
12. Contact
hello@vseti.io for anything about this document.