NetCloak VPN Privacy Policy
1. Introduction
NetCloak VPN (“NetCloak”, “we”, “us”, or “our”) is operated by NeuEra Apps. This Privacy Policy explains what we collect, why, how long we keep it, and who else sees it when you use our Android application (the “Service”). NetCloak is an Android application only; there is no version for any other platform.
NetCloak is free. It is supported by advertising, although how often an advertisement appears is a setting we control remotely and it can be, and at the time of writing is, set to zero.
This policy describes what the software actually does. Where a limit or a setting is named, it is the setting in force when this version was published, and it can change.
IMPORTANT: NetCloak VPN is intended for users aged 18 and older. By using our Service, you confirm that you are at least 18 years of age.
2. Information We Collect
There is no account, so there is nothing you tell us about yourself. What exists is the record needed to run one VPN session at a time.
What We Collect:
- Your IP address: to carry traffic to your device, our server has to know where to send it. While you are connected, your public address is the endpoint of your WireGuard connection. It also appears in our operational logs, which we use for rate limiting and for dealing with abuse. See §7 for how long those logs are kept.
- The session record: while a session exists we store, on our server:
- the WireGuard public key your device generated for that session
- the address we assign you inside the tunnel, which is a private 10.8.x.x address and is not your own public address
- when the session was created and when it expires, and when it was last active
- how many times it has been extended
- the anonymous identifier carried by your access token
- how many bytes have passed through it, and the fair-use ceiling that applies
- which connection mode you chose
- An advertising identifier: Google AdMob uses your device’s advertising ID when it serves an advertisement. You can reset or delete it in Android settings.
- Device permissions the app needs to work:
- internet access and network state
- the VPN service permission, for the WireGuard tunnel
- a foreground service, to keep the tunnel running
- notifications, on Android 13 and later, for session warnings
- the advertising ID, for AdMob
What We DO NOT Collect:
- Your name, or any personal identification
- An email address or a password — there is no account to hold them
- Your browsing history, the sites you visit, your DNS queries or any traffic content
- Precise device location or GPS data
- Payment information, because nothing is sold
- Analytics of how you use the app — the app carries no analytics SDK, no crash-reporting SDK and no advertising SDK other than AdMob
We want to be exact about one thing an earlier version of this policy got wrong: the session record does hold the times a session was created, last active and due to expire. Those times are how the service knows when to end it.
3. How We Collect Information
- When you connect: your device asks our server for a session, and the session record described in §2 is created. Your public address becomes the endpoint of the tunnel.
- While connected: the app asks our server how much time is left, about every 30 seconds, and shows you the answer.
- On your device only: the app watches its own tunnel. It reads when the tunnel last completed a WireGuard handshake, and whether your device has a working network outside the VPN. If the tunnel has stopped responding, the app ends the session and tells you, rather than showing a connection that is not carrying anything. All of this is worked out on the device. None of it is sent to us or stored.
- Configuration over DNS: the app finds its server list and its own settings in DNS TXT records at
servers.netcloak.appandconfig.netcloak.app, looked up over DNS-over-HTTPS through Cloudflare (1.1.1.1). As with any DNS query, that tells Cloudflare which record was asked for, from your network address. We use no other remote-configuration service.
We do not use cookies or similar tracking technologies in the application.
4. How We Use Your Information
We use what we collect only to:
- provide and maintain the VPN service
- create, extend and end time-bounded sessions, and keep one session per user at a time
- tell you how much time is left, and warn you when a session is running low
- apply rate limits and the fair-use ceiling, so one user cannot exhaust a server
- investigate and stop abuse of the service
- comply with legal obligations
5. Information Sharing and Disclosure
Service Providers:
- Contabo GmbH, a hosting company based in Germany, provides the servers the VPN runs on
- Cloudflare operates the DNS-over-HTTPS resolver the app queries for its configuration
- Google Play distributes the app, under its own terms
There is no payment processor, because nothing is sold.
Advertising Partners:
Google AdMob serves the advertisements, and Google’s User Messaging Platform collects and records your consent choice. When the app asks for a reward that Google verifies, it attaches a random single-use number and the anonymous identifier from your access token to the advertisement request, and Google then calls our server to confirm the reward was earned. That exists so a session extension cannot be granted to an automated request that never watched anything. Server-side enforcement of it is currently switched off.
Analytics Providers:
None. The app sends no usage analytics to anyone.
Legal Requirements:
We may disclose information to government authorities or law enforcement officials when required by law or to:
- comply with legal process
- protect our rights and safety
- prevent illegal activities
What can be disclosed is limited by what exists. Session records are deleted when the session ends, and operational logs are deleted on the schedule in §7.
Business Transfers:
In the event of a merger, acquisition, or sale of assets, information may be transferred to the acquiring entity.
With Your Consent:
We may share information for other purposes with your explicit consent.
WE DO NOT SELL YOUR PERSONAL DATA TO THIRD PARTIES.
6. Data Security
- The VPN tunnel is WireGuard, encrypted with ChaCha20-Poly1305. We cannot read what passes through it.
- Calls between the app and our API use HTTPS/TLS, with certificate and hostname verification.
- Your access token is held on your device in Android Keystore-backed encrypted storage.
- Requests are rate limited: 5 a minute per address for creating or extending a session, 30 a minute for checking session status.
- Sessions and their WireGuard peers expire automatically, and are reclaimed when they go idle.
- We keep the software patched and follow secure development practices.
No service can promise perfect security, and a VPN does not make you anonymous. It moves the point at which your traffic enters the public internet; it does not hide what you do once it gets there.
7. Data Retention
- Session records: deleted when the session ends. A session ends when its time runs out, when its tunnel has gone idle, when it was created but never connected, when you start a newer session, when a server is under capacity pressure, or when a peer is left behind by a failure.
- Operational logs, including IP addresses: kept for no more than two days, then deleted. An earlier version of this policy said thirty days; that was never the retention this service ran with.
- On your device: the encrypted access token, and preferences such as your chosen mode, the advertisement counter, your theme and endpoint selection. Clearing the app’s data or uninstalling it removes them.
- Legal compliance: we may retain specific data longer where the law requires it.
8. International Data Transfers
Your information may be transferred to and processed in:
- the United States, where NeuEra Apps operates
- the countries in which our hosting provider, Contabo GmbH, a German company, runs the servers you connect to
- any country in which Google or Cloudflare processes the advertising, consent and DNS requests described above
We rely on appropriate safeguards for these transfers, in line with applicable law.
9. Your Privacy Rights
Depending on where you live, you may have the following rights:
- Access: ask what personal data we hold about you
- Deletion: ask us to delete it
- Portability: ask for it in a portable format
- Object to Processing: object to particular uses
- Withdraw Consent: withdraw consent at any time, including your advertising consent
Be aware of what this means in practice here. We hold no account and no name, and the identifier in your token is anonymous, so in most cases we have no way to connect a request to a particular person’s data. Session records are deleted as soon as the session ends, and logs within two days, so there is usually nothing left to produce or erase by the time a request reaches us.
To exercise these rights, contact us at hello@neuera.app. We will respond within 30 days.
Regional Rights:
- EU Residents: rights under GDPR
- California Residents: rights under CCPA/CPRA
- Canadian Residents: rights under PIPEDA
- Brazilian Residents: rights under LGPD
10. Children’s Privacy
NetCloak VPN is not intended for anyone under 18. The app asks you to confirm your age when you first open it, and we do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it.
11. Third-Party Services
The Service relies on:
- Google AdMob: rewarded video advertisements
- Google User Messaging Platform: collecting and recording your advertising consent
- Contabo GmbH: the servers the VPN runs on
- Cloudflare: the DNS-over-HTTPS resolver the app queries
- Google Play: distribution of the app
Each has its own privacy policy governing its use of information.
12. Advertising
Advertisements are rewarded videos served by Google AdMob. Watching one extends your session; the reward is granted at Google’s own threshold for that advertisement, not at a fixed number of seconds we set.
Before personalised advertising, the app asks for your consent through Google’s User Messaging Platform, and you can change or withdraw that choice later from the app’s privacy options. AdMob uses your device’s advertising ID, which you can reset or delete in Android settings.
How often an advertisement appears is a setting we publish remotely, and it can be zero. At the time this version was published it is zero, so the app is showing no advertisements at all. That is a current setting, not a promise; when it changes, advertisements will appear again without the app needing an update.
You can read about Google’s advertising practices at www.google.com/policies/privacy/partners/.
13. Changes to This Privacy Policy
We may update this Privacy Policy. When we do:
- we update the version and date at the top of this page
- the previous version stays available in the version history
- the app tells you, and asks you to accept the updated policy before you continue using the Service
14. Our Privacy Commitments
- We do not log your traffic: no browsing history, no DNS queries, no content. The tunnel is encrypted and we cannot read inside it.
- We collect the minimum to run a session: everything we hold is listed in §2, field by field.
- Short retention: session records go when the session goes; operational logs last no more than two days.
- No account: no name, no email, no password. Authentication is an anonymous token.
- No tracking SDKs: no analytics, no crash reporting, no advertising SDK beyond AdMob.
- What the VPN hides, and from whom: the sites you visit see our server’s address instead of yours. Our own server necessarily sees your address, because that is how the tunnel reaches you.
- Encrypted configuration lookups: the app fetches its settings over DNS-over-HTTPS.
- Strong, current encryption: WireGuard with ChaCha20-Poly1305.
- We never sell your data: not to advertisers, not to data brokers, not to anyone.
15. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
Email: hello@neuera.appService Operator: NeuEra Apps
Country of Operation: United States of America
Last Updated:
Version: 2026-09-15