Privacy Policy for Sifaro

Allion LLC — Last updated: August 29, 2026

This Privacy Policy explains how Allion LLC ("we", "us", "our") handles information in the mobile application Sifaro VPN (the "App"). By downloading or using the App, you agree to the practices described below.

1. Summary

Sifaro VPN does not log what you browse. We do not record the websites you visit, your DNS queries, or the addresses you reach through the tunnel. We keep the minimum needed to run the service: an anonymous account identifier, your subscription status, and the total amount of data your account transfers. The free tier is funded by advertising, described in section 5. We do not sell your personal information.

2. Who We Are

Sifaro VPN is operated by Allion LLC, a company registered in the United States, and we are the data controller for the information described here. For any privacy question, or to exercise any right in this policy, email ehsan@allionapp.com.

3. What We Do Not Collect

We would rather be specific than reassuring, because a vague promise is worth nothing:

  • We do not log your browsing activity. Our servers run without access logging, so the destinations you reach through the tunnel are never written to disk.
  • We do not log DNS queries. DNS resolution is routed through the tunnel to prevent leaks to your local network, and is not recorded.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising outside the advertising partner named in section 5.
  • We do not ask for your name, postal address, or phone number.

4. What We Collect, and Why

  • Anonymous account identifier. A random value that ties your device to your subscription and to the credentials issued for you. It is not derived from your name or email. Kept while your account exists.
  • Subscription status. Received from Google Play or the App Store so we know whether to enable premium features. We receive a purchase token and a status, never your payment card. Kept for the duration of the subscription, plus any period tax law requires.
  • Connection metadata. Which server you were issued credentials for, when they were issued, and total bytes transferred. This is what stops one person's configuration being shared by thousands, and what lets us size capacity. Kept up to 30 days, then aggregated.
  • Approximate country. Derived from your IP address at the moment of a request, to choose nearby servers and apply the correct privacy rules. We do not build a location history and we do not store it.
  • Crash data. Firebase Crashlytics, so we can fix what breaks. Kept 90 days.
  • Push notification token. If your device allows notifications, Firebase Cloud Messaging issues a token that we store with your anonymous account identifier so the app can receive service messages. Deleted when your account is deleted, and turning notifications off in your device settings stops its use.
  • Time zone. Your device's time zone accompanies free-tier requests so the correct free-time policy is applied for your region. We use it in the moment and do not build a history from it.
  • Advertising identifier. Free tier only, and only where you have consented. See section 5.

5. Advertising (Google AdMob)

The free tier is funded by advertising supplied by Google AdMob, a service of Google LLC. If you consent, AdMob and its partners may use your device's advertising identifier to select and measure ads. If you decline, you will still see ads, but they will be non-personalised.

We show the consent form required in your region — the IAB Transparency and Consent Framework message in the European Economic Area, the United Kingdom and Switzerland, and the opt-out message in US states with applicable privacy laws. You can reopen it at any time from Settings > Privacy options. On iOS, Apple's App Tracking Transparency prompt is shown before any tracking identifier is used, and can be changed in Settings > Privacy & Security > Tracking.

Google's handling of this data is described here:

A subscription removes advertising from the app entirely.

6. Analytics

We use Google Analytics for Firebase, Crashlytics and Remote Config. These record events such as app opens, connection attempts and errors, tied to an app-instance identifier rather than to you. They never receive the contents of your traffic, the sites you visit, or the address the internet sees for you.

7. Legal Bases (EEA, UK, Switzerland)

  • Contract — the account identifier, subscription status and connection metadata are necessary to provide the service you asked for.
  • Consent — personalised advertising, and any use of your advertising identifier, happen only if you agree in the consent form shown on first launch. You may withdraw consent at any time from Settings > Privacy options.
  • Legitimate interests — crash and performance data, and aggregate capacity figures, to keep the app working and the network correctly sized.

8. Who We Share With

  • Google (AdMob, Firebase) — advertising and analytics data as described above.
  • Google Play and Apple — subscription purchase validation.
  • Hosting and network providers — traffic in transit, which is encrypted.
  • Law enforcement — only what we actually hold, and only on a valid legal order. We cannot produce browsing records, because we do not keep them.

9. Your Rights and Choices

Wherever you live, you may ask us to access, correct, or delete your data, and to receive a copy in a portable format. In the European Economic Area, the United Kingdom and Switzerland you may also object to or restrict processing, withdraw consent at any time, and lodge a complaint with your supervisory authority.

In California and other US states with comprehensive privacy laws, you may request access and deletion, and opt out of the sale or sharing of personal information — the in-app privacy options screen is the mechanism for that opt-out. We will not discriminate against you for exercising any right.

Email ehsan@allionapp.com from the address associated with your account, or include your account identifier from Settings > About. We respond within 30 days.

10. Deleting Your Data

Uninstalling the app removes everything held on your device. To delete server-side data, email us as above; we complete deletion within 30 days. Deleting your data revokes any credentials issued to you. Records we must retain for tax or fraud purposes are kept for the period the law requires and for nothing else.

11. Children's Privacy

Sifaro VPN is not directed to children, and we do not knowingly collect personal information from anyone under 13 — or under the higher age of digital consent that applies where they live. If you believe a child has provided us information, contact us and we will delete it.

12. International Transfers

We operate servers in many countries, and our providers are largely in the United States and the European Union. Where data leaves the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.

13. Diagnostic reports

Sifaro never sends a diagnostic report on its own. A report exists only if you build one and press send. This is separate from the standard app analytics described in section 6, which record app events but never the contents of a report or of your traffic.

If you contact us about a problem, the app can help you send a diagnostic report. Reaching it takes a deliberate act: five taps on the version number in Settings, then a button. Before anything is sent, the app shows you the complete report, word for word, in the exact form it would be sent. You can read it, edit the note you attach, copy it somewhere else instead, or leave without sending. Nothing is transmitted until you press send.

What a report contains

  • The app version and build number, and your operating system version.
  • Your device's time zone and language setting.
  • Which server you were connected to, and for how long.
  • The measured speed of your connection, if you ran that check.
  • The IP address the internet saw for you, if you ran that check — this may be the address of our server, or, when something has gone wrong, your own.
  • Whether any of our servers had recently failed to respond for you.
  • Anything you type into the note field.

What a report never contains

  • Any record of which websites, apps or services you used. We do not keep such a record anywhere, so there is none to include.
  • Your name, email address, phone number, or payment details.
  • The contents of your traffic.

How reports are handled

A report is stored on our server against the anonymous device identifier your app already uses, so that a reply can be matched to the report that prompted it. It is read by a person looking into your problem. It is not used for advertising, not sold, not shared, and nothing in the product reads it automatically.

Reports are deleted automatically thirty days after they are sent. This is enforced by the server itself on a schedule, not by anyone remembering to do it.

Your choices

Sending a report is entirely optional and the app works identically if you never send one. To have a report you already sent deleted before the thirty days are up, contact us and we will remove it.

14. Sharing your connection

Sifaro has a feature that lets one person share their own internet connection with people they invite. If you have never turned it on, nothing in this section applies to you. It is off unless you switch it on, and the app shows you what it means before the switch.

If you share your connection

Traffic from the people you invite leaves the internet through your connection. That is what the feature does, and it has consequences you should understand before you turn it on:

  • The people you invite can see your internet address. Their traffic exits from it, so any website that reports a visitor's address reports yours to them. An address can be looked up, and it will usually give the city and the internet company you use. We cannot prevent this; it is how the feature works, not a setting we chose.
  • What they do looks like what you did. To the sites they visit, and to your own internet provider, their activity is indistinguishable from yours. It is recorded against your connection.
  • Nothing limits how much of your connection they use while sharing is on. You can stop at any time.

For these reasons, access is by invitation only, and each invitation is yours to withdraw. Invite only people you are willing to be responsible for.

What is blocked, whatever anybody asks for

Some traffic never leaves your connection, and this cannot be switched off in the app: the mail ports (25, 110, 143, 465, 587, 993, 995), file sharing (6881–6889), IRC (6667), and every address on your own home network. Your router, printer and other devices are not reachable through the tunnel.

What we can see

To send each connection to the right place, our server necessarily knows where that connection is going at the moment it is made. It does not see the contents, and it does not write the destinations down: our servers run without access logging, so nothing about where anybody went is stored.

What we store about sharing

  • That your device is offering to share, and which of our servers it is attached to.
  • The country your device reports, and nothing more precise. This is shown to people deciding whether to use your connection.
  • The credentials issued to the people you invited, so that access can be withdrawn.
  • The volume of data transferred, for abuse prevention and billing. Not what it was.

Withdrawing access

When you withdraw an invitation or stop sharing, new connections stop almost immediately. The credential itself is removed from the server within a few minutes by a scheduled cleanup, so a transfer already running may continue until then.

If you use somebody else's connection

The app shows you which country the person is in, and names nothing else about them. But your traffic leaves the internet through their connection, so the address you appear to come from is theirs, and an address can be looked up. They cannot see what you do, and they do not see your address. The limits above apply to you as well: mail, file sharing and their home network are not reachable through their connection.

15. Changes to This Policy

If we change this policy in a way that materially affects you, we will say so in the app before the change takes effect. The date at the top always reflects the current version.

16. Contact Us

Questions about this Privacy Policy or a request about your data can be sent to:
Allion LLC — Email: ehsan@allionapp.com