Privacy Policy
Last updated: 21 August 2026
Siber VPN is operated by GENESIS RACK INSTALLATION LLC ("we", "us"). This policy explains, plainly, what the Siber VPN app does and does not do with data. The short version: there is no account, nothing you do online is recorded, and the app sends us the things listed in section 3: the anonymous connection counters in section 6, and anonymous product analytics you can switch off in Settings.
1. No account, no sign-up
Siber VPN requires no registration. We do not ask for and do not collect your email address, phone number, name, or any account credentials. There is no login and no user profile — nothing here is tied to who you are.
Some identifiers do leave the device, and we would rather spell that out here than let you find it out from the Data safety section of our store listing: ad networks request an advertising ID (section 2), and the anonymous analytics carry a random install identifier that is regenerated if you reinstall (section 6). Neither one is linked to an account, because there is no account.
2. No logs
We do not log your browsing history, the contents or destinations of your traffic, your DNS queries, your original IP address, connection timestamps, or session duration.
One consequence of the Russia split-routing deserves to be spelled out, because it is easy to miss: while the VPN is connected, DNS lookups for Russian domains are sent to Yandex Public DNS (77.88.8.8) over plain UDP, directly rather than through the tunnel. That is what keeps Russian sites and their CDNs fast and working. It also means that, for Russian domains, Yandex and your internet provider can see which domain you asked about, coming from your real IP — even with the VPN on. Lookups for everything else go through the tunnel over encrypted DNS. We do not run that resolver and we do not receive those queries; we are telling you about it because you cannot see it from inside the app.
The app shows ads, and ad networks request an advertising ID. It also includes PostHog for anonymous product analytics, which you can switch off in Settings. None of these record what you browse: neither the ad networks, nor analytics, nor the connection counters in section 6 see the sites you open through the tunnel — so there is nothing about your activity to store or hand over.
3. Data the app stores on your device only
The app keeps a small amount of information on your device to function — for example your language choice, your selected location, and local counters used to show connection status. None of it is an account or an identifier, and all of it is deleted when you uninstall the app. It stays on your device, with three exceptions, all described in section 6: the anonymous connection counters, anonymous product analytics, and the advertising ID that ad networks receive.
4. Configuration delivery
To stay reachable, the app may download its server configuration from public file-hosting services. Like any website request, those services can see standard request information such as your IP address; the app itself attaches nothing about you to those requests. This happens only to retrieve configuration, not to track you.
5. Encryption
How your traffic reaches our server depends on which of three channels the app picks, and we should be precise about it. One channel (Reality) is encrypted at the transport layer. The other two (gRPC and WebSocket) are not — they are deliberately plain, because a channel that is not TLS at all cannot be detected by the TLS-fingerprinting methods used to block VPNs, and that redundancy is the point of having three. On those two channels your provider can see which servers you connect to, and the contents of anything you open over plain HTTP. Anything you open over HTTPS stays protected by that site’s own encryption, as it would without a VPN. Two more things you cannot see from inside the app, so we have to tell you: you do not get to choose which channel is used — the app picks whichever is working — and when it has to fall back, the fallback is one of the plain ones. We do not inspect or record the contents of any of it. One exception, and it is deliberate: traffic that matches the app’s Russian direct-routing rules does not go through the tunnel. It connects directly, so those sites see your real IP rather than the server’s. Note that Russian sites which are themselves blocked inside Russia are matched earlier and do go through the tunnel. This split is what helps keep Russian banks, government services and local sites reachable while the VPN is on, and it is the same rule described for DNS in section 2 and for ads in section 6.
6. Anonymous diagnostics
To detect when servers stop working — for example when they are blocked in a particular country — the app sends small, anonymous counters through the VPN tunnel: how many connection attempts succeeded, connected, and were actually usable, together with the server location, app version, and a country code. Because they are sent through the tunnel, our collector sees the server’s address, not yours, and your IP address is never stored.
These counters contain no account, no device identifier, and nothing about what you browse or do online. In aggregate they tell us only whether connections are working.
Separately, the app uses PostHog for anonymous product analytics. It records five events, and we would rather list them all than round the number down: that a connection was confirmed working (region, and how long it took); that a connection failed (the reason, which step it failed at, and the region); that a tunnel came up but could not reach the internet (region, cause, HTTP code); that the ad system finished starting up (whether it succeeded, and a country code); and that a full-screen ad was shown (its format — app open or interstitial — and, for the one shown right after connecting, that it was that one; banners are not reported). Events carry a random install identifier and the usual device and app attributes (model, OS version, language, time zone, app version) — no account, no personal profile, no advertising ID, and never a server address, a key, or anything about what you browse.
One more SDK deserves naming, because it is analytics rather than ad serving and it did not arrive by our choice: the Yandex Mobile Ads adapter bundled through CAS.ai brings AppMetrica with it. It registers itself in the app and can report installation and usage signals to Yandex. We do not call it ourselves and it is not one of the five events listed above, so the Settings switch — which controls our own analytics — does not turn it off. If you would rather this SDK were not in the app at all, that is a fair objection, and we are recording it here rather than leaving it undisclosed.
Ads are served through CAS.ai, a mediation platform that routes each ad request to a number of ad networks and real-time bidding exchanges. The partners built into this version of the app include Google AdMob, Meta Audience Network, Yandex Mobile Ads, Unity Ads, ironSource, Vungle, InMobi, Mintegral, Bigo Ads, Amazon, AppLovin, Chartboost, Tapjoy, BidMachine, Pangle, PubMatic, Kidoz, Maticoo, Display.io, YSO Network and Monetrix. This list is not exhaustive and it changes: CAS adds and removes partners without an app update, and in a real-time auction the winning buyer can be a demand platform whose name never appears in the app at all. We list who we can verify is there, not everyone who could end up bidding. They receive the advertising ID and general device data (model, OS version, language, approximate region derived from your IP). They do not receive, and cannot see, the sites you open through the tunnel. Which IP they see depends on where each request goes, not on which network sent it. While the VPN is connected, an ad request follows the same destination-based split-routing as the rest of your traffic: requests that match the Russian direct-routing rules — including the Yandex advertising and AppMetrica endpoints we have observed — connect directly and see your real IP, while requests routed through the tunnel see the VPN server’s IP. That is the same rule that lets Russian banks and government sites keep working, and we add no ad-specific exceptions to it. While the VPN is off, every request sees your real IP, like any other app on your phone. You can reset the advertising ID or turn off ad personalisation in Android settings.
7. Diagnostics you send us
If you choose to email us feedback from within the app, the message includes basic technical details you can see before sending (app version, device model, Android version, and connection counters). It contains no identity information and no server addresses. Sending feedback is entirely optional.
8. Children
Siber VPN is intended for users aged 13 and over. We do not knowingly collect data from children under 13.
9. Changes
We may update this policy to reflect changes in the app. Material changes will be posted here with a new date.
10. Contact
Questions? Email support@siber-vpn.cc.