OkPath Connect

Privacy Policy

Effective

OkPath Connect, which appears on your Home Screen as “OkPath”, is an iPhone and iPad app provided by OKPATH, INC. (“OKPATH”, “we”, “us”). It is a network tool: it connects your device through a VPN to servers that you run yourself or that a provider you choose runs. OKPATH makes the app available to OKPATH team members and invited users through Apple TestFlight. This policy explains what the app does with information, where that information goes, and the choices you have. It covers the app and the VPN connection it creates.

Summary

  • No account, no sign-in. The app does not ask for your name, email address, phone number, contacts, photos or location.
  • No ads, analytics or tracking. The app contains no advertising, analytics or tracking code, and it sends no data to OKPATH.
  • Your traffic goes where your configuration says. While the VPN is on, the app sends your traffic only to the servers in the configuration you add, or directly to its destination where that configuration says so. Traffic that iOS keeps outside the VPN, such as some Apple services, goes directly to its destination. You run those servers or use a provider you choose. OKPATH does not run them and has no access to your traffic.
  • We do not sell, use or disclose your data. OKPATH does not sell, use or disclose any data from the app or your connection, and it receives none.
  • Your data stays on your device. Profiles, settings, logs and diagnostic reports stay on your device unless you choose to share them. Deleting the app deletes them.

What the app does

OkPath Connect is a VPN client. It uses Apple’s Network Extension framework to create a VPN on your device. The configuration you add, which the app calls a profile, decides which servers the VPN connects to, which protocol and encryption it uses, and which traffic goes through it. You get the configuration from your own server or from a provider you choose. OKPATH does not provide servers, accounts or configurations.

Before you can set up the VPN, the app shows a data-use notice, “Before you connect”, that summarizes this policy. You accept it by tapping Continue. You can read it again in the app under Settings > About > Privacy & Data Use.

Connections the app makes

The app connects to the internet only in these cases:

  1. The servers in your configuration. While the VPN is on, the app sends your network traffic, including domain-name (DNS) lookups, through the servers named in your configuration, as its rules specify. Some traffic goes straight to its destination: traffic the configuration sends directly, and traffic that iOS keeps outside the VPN, such as some Apple services.
  2. Downloading and updating your profile. If you add a profile from a link or web address, the app downloads it from that address. Automatic updates are on by default for these profiles. When they are on, the app checks the same address again at the interval set for that profile, which is 60 minutes by default. It checks when iOS gives the app background time, or when you open the app if Background App Refresh is off. Like any web request, these requests show your IP address to that server, which you or your provider run. They also include a header that identifies the app and the version of its network engine, plus a language and region code based on your device’s region setting (for example en_US).
  3. Tests you start. The app’s connection tests contact test servers only when you run them:
    • the latency test for server groups, which by default loads www.gstatic.com through each of your servers;
    • the Network Quality test, which by default uses Apple’s mensura.cdn-apple.com;
    • the STUN test, which by default uses stun.voipgate.com.
    If your configuration contains an automatic server-selection group, the app also runs the latency test on its own while the VPN is on.
  4. Features your configuration turns on. Some optional features contact the addresses set in your configuration, or that service’s standard addresses, but only if your configuration enables them. Examples are downloading lists of routing rules, synchronizing the time and getting certificates.
  5. A one-time check on some iPhones. On iPhones set up for mainland China, iOS asks people to allow each app to use wireless data. To make iOS show that prompt, the app requests Apple’s connectivity-check page (captive.apple.com) after you accept the data-use notice, and stops after the first successful request. The request contains nothing about you beyond what any web request reveals, which is your IP address.

The app never contacts OKPATH. It has no update checker, no analytics and no crash-report upload.

The servers you connect to

The servers in your configuration are run by you or by a provider you choose. OKPATH does not run them, has no access to them or to your traffic, and receives no data from the app.

Like any VPN server, they can see:

  • your device’s IP address;
  • when you connect and how much data you transfer;
  • the addresses and domain names of the sites and services you reach;
  • the credentials in your configuration that identify your connection.

Content that apps and websites already encrypt, such as HTTPS pages, stays encrypted: the servers see where it goes, not what it says. What these servers record and how long they keep it is up to whoever runs them, and their operator’s own privacy policy applies. If you use a provider, read its privacy policy. The same applies to the server you download your profile from.

Information stored on your device

The app stores the following in its private storage on your device:

  • Profiles you add. They contain server addresses and your connection credentials, plus each profile’s name, source address and update settings.
  • Settings. These include the selected profile, the VPN and on-demand options (including any Wi-Fi network names you enter), and the date you accepted the data-use notice.
  • The connection log. While the VPN runs, the app keeps a log of recent connection activity in memory. It can include the names of the websites and services you connect to, and the name and hardware address (SSID and BSSID) of your Wi-Fi network. The log is not written to storage unless your configuration tells the app to write it to a file, or you save or share it yourself.
  • Diagnostic reports. If the app crashes, freezes or runs out of memory, it saves a report on your device. A report can include your device model, iOS version, app version, technical details of the failure and a copy of the active configuration. Reports are never uploaded automatically.
  • Caches and sign-in data your configuration’s features need, such as routing-rule lists, DNS results, or the web sign-in of a network service your configuration uses.
  • The VPN configuration that iOS keeps in Settings for the app, named “OkPath”.

Diagnostic reports and the app’s working files also appear in the Files app, under the “OkPath” location, so you can review or delete them.

The app does not sync any data to iCloud or any other cloud service. If you back up your device with iCloud Backup or a computer, iOS may include the app’s profiles and settings in that backup, as it does for other apps.

Sharing diagnostics with OKPATH

Reports, logs and profiles leave your device only if you share them yourself, for example with Share in the Logs tab or from a report under Tools. When you share a report, you choose whether to add the log and the configuration. Both are off by default.

A configuration contains the credentials for your servers. Send one to OKPATH support only when asked, and never to anyone you do not trust.

Information OKPATH receives

OKPATH receives no data from the app. It holds only the TestFlight information that Apple shares and the support messages you send.

TestFlight

Apple, not the app, shares beta-testing information with OKPATH. It can include:

  • how you were invited and whether you accepted;
  • install and session counts;
  • your device model, iOS version and device language;
  • crash logs collected by iOS;
  • any feedback, screenshots and comments you choose to send through TestFlight.

If OKPATH invited you by email, it has the name and email address it used for the invitation. If you joined through a public link, Apple does not show OKPATH your name or email address. Apple’s TestFlight privacy terms apply to this information.

Support requests

If you contact us, we receive what you send: your email address, your message and any logs or reports you attach. We use it only to answer your request, and we keep it only as long as we need it to resolve your request.

Our VPN commitments

  • OKPATH does not sell, use or disclose any user data from the app or your connection. The app sends OKPATH no data, and OKPATH has no access to your servers or your traffic.
  • The app sends your network traffic only to the servers in the configuration you add, or directly to its destination where that configuration says so. Traffic that iOS keeps outside the VPN, such as some Apple services, goes directly to its destination. It never sends your traffic to OKPATH or to the developers of the open-source software it is based on.
  • OKPATH uses the TestFlight information and support messages it receives only to test the app and answer you, and it does not sell them or disclose them to third parties.

Permissions and why the app asks

  • VPN configuration (required). iOS asks whether to let “OkPath” add VPN configurations, and warns that all network activity may be filtered or monitored when using VPN. iOS shows this warning for every VPN app. The app needs this permission to create the VPN, and it handles your traffic only as described in this policy.
  • Local network (only when needed). iOS may ask to let the app connect to devices on your local network. The app uses this only to reach local addresses your configuration routes to, such as a DNS server on your Wi-Fi network. It does not scan your local network.
  • Camera (optional). The app asks only when you tap Scan QR Code to import a profile. The camera image is processed on your device to read the code, and it is not saved or sent anywhere.
  • Notifications (optional). The app does not ask for this when it starts. iOS asks only if your configuration uses a feature that posts alerts, such as a sign-in link from a network service your configuration uses.
  • Wi-Fi network name (no prompt). When your network changes, the VPN reads the name (SSID) and hardware address (BSSID) of the Wi-Fi network you are on, so that configurations can use Wi-Fi-based rules. This information stays on your device. The app does not ask for your location and does not use location services or GPS.
  • Background App Refresh. The app uses it only to update profiles that have automatic updates turned on. You can turn it off in Settings > General > Background App Refresh.
  • Files. The app sees only the files you choose to open or import in it.

Keeping and deleting your data

  • In the app:
    • delete a profile from your profile list, which opens from the Profile section on the Home tab;
    • delete crash and other reports under Tools;
    • remove cached files in Settings > App > Clear Cache, which appears only when the cache is not empty;
    • delete the network engine’s working data, including caches and diagnostic reports, in Settings > Core > Destroy.
  • VPN configuration: remove it in iOS Settings > General > VPN & Device Management > VPN, where it is named “OkPath”.
  • Delete the app. This removes everything the app stored on your device, including its VPN configuration. Device backups follow your backup settings.
  • Leave the beta. In TestFlight, open OkPath Connect and tap Stop Testing.
  • Information OKPATH holds: the TestFlight information Apple shares and the support messages you send. To get a copy, or to have it corrected or deleted, email privacy@okpath.com. We may need to confirm your identity before we act on a request. Depending on where you live, you may have further rights under local law, including the right to complain to a data protection authority.
  • Information on your servers: whoever runs the servers in your configuration controls what they keep. Ask them, or your provider, about it.

Children’s privacy

OkPath Connect is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has sent us information, contact us and we will delete it.

This website

The pages on this website set no cookies, run no scripts and load nothing from other websites. The service that hosts them may record requests, such as your IP address and the page you asked for, to deliver and protect the site.

Changes to this policy

If we change this policy, we will post the new version at this address and update the effective date above. We will also mention significant changes in the TestFlight notes for the next build.

Contact

OKPATH, INC. is responsible for the information it receives, as described in this policy. Send questions and requests about privacy to:

Email
privacy@okpath.com
Help with the app
Support · support@okpath.com
Mail
OKPATH, INC.
2093 Philadelphia Pike
Claymont, DE 19703
USA