Privacy Policy
Effective date: August 5, 2026 · Applies to: openlawsvpn.com and openlawsvpn client (iOS & Android), relay (Android), and other apps and clients
Short version: The openlawsvpn apps do not collect, store, or transmit personal data to openlawsvpn servers. In direct mode, your VPN traffic goes directly to your own AWS endpoint. This website uses optional analytics and advertising measurement only when you consent — see section 6.
1. What we collect
Nothing. The app does not collect any personal information, usage analytics, crash reports, or telemetry. There are no SDKs in the app that phone home.
2. Data stored on your device
The following data is stored locally on your device only:
- VPN profiles (.ovpn files) — stored in app-private storage with restricted permissions (mode 600 on Linux; excluded from Android Auto Backup on Android).
- Connection logs — held in memory while the app is open; cleared when the process ends. Never written to disk.
No data from any client is accessible to other apps or synchronized to any cloud service.
3. Data transmitted
The only network traffic initiated by the apps is:
- VPN tunnel traffic — encrypted and routed directly to your organization's AWS Client VPN endpoint. openlawsvpn servers are never in the data path.
- SAML authentication — your identity provider's login page opens in a system browser (a separate process). The app receives only the resulting SAML token; it never sees your credentials or the login page content.
- Demo endpoint (openlawsvpn client) — a publicly accessible, read-only demo VPN endpoint is available for app review and testing. It uses the SAML/SSO profile at demo/saml-client.ovpn. No user data is stored on this endpoint.
- Relay mode (optional) — if you use the relay feature, only the data required by its nature to deliver VPN auth to the remote agent transits the openlawsvpn relay service. This data is not stored beyond the duration of the session (60-second TTL). Direct connections never touch openlawsvpn servers.
4. Logging
Direct connections — the app connects directly to your AWS endpoint. No openlawsvpn infrastructure is involved and no connection data is logged by us.
Relay mode (optional) — relay traffic passes through the openlawsvpn relay service (AWS API Gateway). Standard access logs are retained for 30 days in AWS CloudWatch for security and abuse-prevention purposes. These logs may include your IP address, timestamp, and request metadata. They are not sold or shared with third parties and are deleted automatically after 30 days.
5. Third-party services in the apps
The app does not integrate any third-party analytics, advertising, crash-reporting, or data-processing services.
6. Website analytics and advertising
When you visit openlawsvpn.com, we ask for your permission before loading optional measurement services. These services are not part of the mobile or desktop apps.
- Google Analytics — helps us understand aggregated website visits and which pages are useful.
- Google Ads — helps us measure whether visits from our advertising campaigns reach the website.
- GoatCounter — provides lightweight website visit statistics.
We use Google Consent Mode in basic mode: Google Analytics, Google Ads, and GoatCounter are not loaded until you opt in. You may accept all optional measurement, reject it, or choose categories separately. Your choice is saved in local storage for up to 180 days and can be changed any time through the Privacy choices button on the website.
If you enable analytics or advertising measurement, the relevant provider may receive technical information from your browser, such as pages viewed, referring URL, browser and device information, approximate location inferred from IP address, and campaign identifiers. Google processes this information under its Privacy Policy. We do not enable personalised advertising unless you separately consent to it.
Our legal basis for these optional services is your consent. You can withdraw consent at any time using the privacy controls described above; withdrawing consent does not affect the lawfulness of processing before withdrawal.
7. Website language preference
The website can offer an available language based on your browser's language setting. We do not automatically change the language. If you select a language, that functional preference is saved only in your browser's local storage so the website can remember it on your next visit. It is not sent to openlawsvpn or used for advertising.
8. Permissions
Each client requests only the permissions required to operate as a VPN client.
On iOS:
- VPN configuration (Network Extension) — required to create and manage the VPN tunnel. iOS prompts the user to allow VPN configuration on first connection.
- App Group (local IPC) — used only for inter-process communication between the main app and the VPN tunnel extension running on the same device. No data leaves the device through this mechanism.
On Android:
- INTERNET — required to establish the VPN tunnel.
- BIND_VPN_SERVICE / VpnService — required by Android to create a VPN tunnel interface.
- FOREGROUND_SERVICE / FOREGROUND_SERVICE_SPECIAL_USE — keeps the VPN running while the app is in the background.
- POST_NOTIFICATIONS — displays the persistent "Connected" notification and Disconnect action (Android 13+).
- ACCESS_NETWORK_STATE — detects network loss so the app can update its status when the tunnel drops.
On Linux the CLI and GUI require no special permissions beyond the network capabilities needed to create a tunnel interface (CAP_NET_ADMIN+CAP_NET_RAW or run as root).
No location, contacts, camera, microphone, or unnecessary storage permissions are requested on any platform.
9. In-App Purchases (iOS)
The iOS app offers a monthly subscription processed entirely by Apple through the App Store. openlawsvpn does not receive or store your payment information. We receive only a signal from Apple's StoreKit framework indicating whether a valid subscription entitlement is active on your device. No financial data is transmitted to openlawsvpn servers as part of the purchase process.
For questions about billing, cancellation, or refunds, visit Apple's billing support.
10. Children's privacy
The app is not directed at children under 13 and does not knowingly collect information from children.
11. Changes to this policy
If this policy changes materially, the updated version will be posted at this URL with a revised effective date. The app is open source — all changes are visible in the public repository.
12. Contact
Questions about this policy: contact@openlawsvpn.com