Developer: One Good Dev
Welcome to .ovpn Hub (the "App"). Your privacy is important to us. This Privacy Policy explains what information the App collects, how it is used, how it may be shared, and the choices you have. This policy is intended to satisfy Google Play disclosure requirements and to help you understand our practices.
By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the App.
1. Who we are and scope
The App is developed and published by One Good Dev. This Privacy Policy applies to the .ovpn Hub mobile application and any in‑app features that link to this policy.
2. Age restrictions
The App is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided personal data, please contact us so we can take appropriate action.
3. Key assurances about VPN connections
- The App does not provide or establish a VPN connection and does not route your internet traffic. This applies equally to OpenVPN (.ovpn) configurations and to V2Ray configurations (VLESS, VMess, Trojan, Shadowsocks, TUIC, Hysteria2): the App displays, tests, and hands them over to a separate client application, and never connects through them itself.
- We do not record, store, or log your VPN browsing activity (the websites you visit, the content you view, or the data you transmit).
- Your device's IP address may be used transiently for diagnostics; we do not retain it beyond what is technically necessary to perform those requests.
4. How the App works (configuration hub)
.ovpn Hub does not operate VPN servers and does not connect you to VPNs. The App aggregates configuration data from public sources and lets you inspect, test, share, and transfer it to a compatible client application. Two kinds of configuration are supported:
- OpenVPN configuration files (.ovpn) — downloaded from public sources and exported to OpenVPN‑compatible applications.
- V2Ray configuration URIs — public configuration links using the VLESS, VMess, Trojan, Shadowsocks, TUIC, and Hysteria2 protocols. The App parses the URI to display its parameters (server, transport, TLS/REALITY status), and can copy it to the clipboard, share it, or hand it to a V2Ray‑compatible client at your explicit action.
- The App works with multiple sources because it is a hub for configurations.
- Example source: VPN Gate (University of Tsukuba) — https://www.vpngate.net
- Important: Public sources and third‑party VPN servers may have their own logging or privacy practices which we do not control. Review the source's privacy information (e.g., VPN Gate Privacy).
- When you use a configuration in another VPN application, your traffic will be routed by that third‑party app/server, not by .ovpn Hub.
5. Information we collect
The App is designed without account registration and without collecting VPN traffic data. Depending on your use, we may process the following categories of information:
5.1 Information you provide voluntarily
- Support communications: If you contact us (e.g., by email), we will process the information you provide such as your email address and the content of your request to diagnose and resolve issues.
5.2 Information collected automatically by the App
- Device information: Device model, OS version, language/locale, app version. Used to ensure compatibility, troubleshoot issues, and improve stability.
- IP address (transient): Used by networking components to download configuration lists or perform diagnostics. We do not retain your original IP beyond the period required to perform the request.
- Network diagnostics data: The App can perform pings to VPN server endpoints to estimate latency. These measurements assess network quality; they do not analyze your content or transmit your data to the developer.
- In‑app interaction data: Firebase Analytics tracks anonymised events such as exports, filters, sorting, health checks, and ad interactions (listed in Section 6) to improve UX and inform product decisions. This constitutes App activity — App interactions under Google Play's Data Safety framework. If you decline consent via the UMP form (EEA/UK), Analytics is disabled.
- Crash diagnostics: Firebase Crashlytics collects crash reports, stack traces, device model, OS version, and free memory to diagnose and fix bugs. This constitutes Diagnostics — Crash data under Google Play's Data Safety framework.
- Local notifications: The App may send local notifications to inform you when a VPN health check is complete. Notifications can be disabled at any time in your device settings.
- Purchase history: If you buy Ovpn Hub Pro, the App sends your purchase receipt to RevenueCat (see Section 6) for validation and entitlement management. Pro is a one‑time, non‑consumable purchase — there is no subscription, no recurring billing, and nothing to cancel. This constitutes Financial Info — Purchase history under Google Play's Data Safety framework. We do not have access to your payment card details; those are handled exclusively by Google Play.
- Presence of a compatible VPN client: To tell you whether a configuration can be opened, the App checks whether a compatible client application is present on your device. On Android this uses targeted package visibility declared in the app manifest — the App can only see the specific clients it declares (for example
com.v2raytun.androidandcom.v2ray.client) and applications that handle the relevant link types; it does not enumerate your installed applications. Whether an OpenVPN‑compatible client was found is sent to Firebase Analytics as a single yes/no property (openvpn_client_installed) so we can measure how many users are blocked at this step. The names of your other applications are never collected. This constitutes App activity — Installed apps under Google Play's Data Safety framework, limited to that single yes/no signal.
5.3 Local storage on your device
We use on‑device storage via Hive CE to cache data such as server lists, favorite servers, ping/speed results, downloaded .ovpn files, V2Ray configuration URIs, and UI preferences. This data remains on your device unless you uninstall the App or clear the App's data. We do not upload this cache to our own servers.
6. Third‑party services and SDKs
- VPN Gate – Purpose: Fetch public VPN server configurations for download and sharing. Privacy: vpngate.net/en/about_privacy.aspx
- Google Mobile Ads (AdMob) – Potential data collected by Google: advertising identifiers (AAID/IDFA), IP address, device and app information, approximate location inferred from IP, ad interaction/engagement data, and crash/diagnostic signals. User controls: Reset or limit ad personalization in device settings. For EEA/UK users, a consent form via Google's UMP is shown where required by law. Learn more: Google Partner Sites Policy
- In‑App Review (Google Play / Apple App Store) – Purpose: Native review prompt after sufficient use. The dialog is rendered by the platform, not the App. We do not receive or store your rating or review text.
- RevenueCat – Purpose: Validate the receipt for the one‑time Ovpn Hub Pro purchase and restore that entitlement across reinstalls. Data collected: an anonymous App User ID (generated by the SDK and cached on device), purchase history (product IDs, transaction IDs, entitlement status), and device information for analytics. Data is encrypted in transit and processed for App functionality and Analytics. RevenueCat does not collect payment card details. Privacy policy: revenuecat.com/privacy
- Google Play Billing – Purpose: Process the one‑time Pro purchase. Payment card information is handled entirely by Google Play; the App never receives or stores it. Privacy: policies.google.com/privacy
- Firebase Analytics – Purpose: Collect anonymised in‑app interaction data. Custom events: ad_shown, ad_dismissed_without_reward, refresh_list, vpn_export, server_opened, config_value_shared, ta_key_downloaded, bulk_check_started, single_check, find_best_server, filter_applied, sort_applied, vpn_tab_selected, onboarding_funnel, connect_funnel, vpn_aidl_bind, vpn_aidl_connect, vpn_aidl_disconnect, vpn_aidl_error, vpn_connected. One user property is set: openvpn_client_installed (see Section 5.2). No PII (email, name, IP) is passed in event parameters, and no configuration content, server address, or V2Ray URI is ever sent as a parameter. Data is used for product analytics and quality improvements. Respects UMP consent — disabled if user declines. Privacy: policies.google.com/privacy
- Firebase Crashlytics – Purpose: Crash and error reporting. Collects stack traces, device model, OS version, free memory, and app version at the time of a crash. No custom keys or user identifiers are set. Privacy: policies.google.com/privacy
- Ipify – Purpose: Display your current public IPv4 address inside the App. Site: ipify.org
- OpenVPN‑compatible VPN applications (third‑party) – Purpose: Open or transfer .ovpn files to third‑party VPN apps. Those apps and servers operate under their own policies.
- V2Ray‑compatible client applications (third‑party) – Purpose: Hand a V2Ray configuration URI to a client you choose, such as v2RayTun or v2rayNG, at your explicit action. The hand‑off passes only the configuration itself; the App sends no personal data with it. Once imported, the connection and any logging are governed entirely by that client and the server operator, under their own policies. The App is not affiliated with the V2Ray, Xray, v2rayNG, or v2RayTun projects.
- Networking and storage libraries (code dependencies):
dio,retrofit,hive_ce,icmp_ping,ipify,logger,in_app_review,share_plus,open_file,file_saver,package_info_plus,device_type. These libraries do not, by themselves, transmit your data to the developer.
Note: Third‑party volunteer VPN servers are outside our control and may maintain their own logs for abuse prevention or legal compliance. Review the server's country laws and privacy notes before use.
7. Consent and analytics (UMP + Firebase)
When advertising is enabled, the App integrates Google Mobile Ads (AdMob):
- Request user consent where required (e.g., EEA/UK) using Google's User Messaging Platform (UMP).
- Respect your device‑level ad preferences (e.g., "Opt out of Ads Personalization" on Android).
- Serve non‑personalized ads if you decline consent for personalized advertising in regulated regions.
- Display rewarded ads (full‑screen video/interactive ads) at certain points in the app flow. Watching a rewarded ad is optional.
In addition, the same UMP consent gates Firebase Analytics: if you decline consent, all Analytics event collection is disabled. Firebase Crashlytics (crash reporting) runs independently for app stability and cannot be disabled per-consent, as crash data does not contain personal information.
Data associated with AdMob ad requests is handled by Google under its policies. See: policies.google.com/technologies/partner-sites
8. How we use information
- Provide the App's core features (retrieve server lists; download, share, and transfer .ovpn files and V2Ray configuration URIs).
- Validate VPN servers and measure network quality (ping/speed) to help you assess configurations.
- Manage the one‑time Pro purchase: verify the purchase receipt, grant the entitlement, and restore it after a reinstall.
- Diagnose problems and improve reliability.
- Display advertising, subject to consent where required.
We do not create behavioral profiles based on your VPN traffic because the App does not handle VPN traffic.
9. Data retention
- Network request data: We do not retain your original IP address beyond what is necessary to perform diagnostics.
- Local app data (Hive CE cache): Stored on your device until you clear the app data or uninstall the App.
- Purchase data: Retained by RevenueCat as long as necessary to keep your Pro entitlement restorable and as required by applicable law. You may request deletion of your RevenueCat customer data at any time (see Section 13, "Data deletion requests").
10. International data routing
When you use an .ovpn file in a third‑party VPN application, your traffic may be routed through servers in other countries with different data protection laws. Please select servers with care and review the source's guidance.
11. Security
We use reasonable technical and organizational measures to protect information. No method of transmission or storage is 100% secure. Use caution when transmitting data over public networks.
12. Your rights and choices
Depending on your jurisdiction, you may have rights such as access, correction, deletion, objection or restriction of processing, portability, and withdrawal of consent. You can also:
- Reset or limit your device's advertising identifier in system settings.
- Clear the App's local data or uninstall the App to remove locally stored cache.
- Request deletion of the data we hold about your installation (see Section 13, "Data deletion requests").
13. Data deletion requests
You can request deletion of the data associated with your app installation even though the App has no accounts or registration. Email one.good.developer@gmail.com with the subject "Data deletion request" and include one of the following so we can locate your records:
- your Support ID — the anonymous app user ID shown at the bottom of the App's side menu (tap it to copy), where available in your app version; or
- your Google Play order number (starts with
GPA.) if your request concerns a Pro purchase.
Upon a verified request we will, within 30 days:
- delete your RevenueCat customer record (anonymous app user ID, purchase history, and entitlement status);
- delete any support correspondence containing your personal data, unless retention is required by law (e.g., tax or accounting rules for purchase records).
Data not held by us that you control directly:
- The Android advertising ID can be reset or deleted at any time in your device settings (Settings → Google → Ads); this severs the link between past ad data and your device.
- Locally cached data (server lists, favorites, measurements, downloaded .ovpn files, V2Ray configuration URIs) is removed by clearing the App's storage or uninstalling the App.
- Crash diagnostics and analytics events are stored in aggregate form and expire automatically under Firebase's standard retention periods.
14. Third‑party links
The App may contain links to third‑party sites or services (e.g., VPN Gate information). We are not responsible for their privacy practices. Review their policies before use.
15. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above. Your continued use of the App after the effective date constitutes acceptance of the updated policy.
16. Contact us
- Developer: One Good Dev
- Email: one.good.developer@gmail.com
- Privacy Policy URL: https://onegooddeveloper-dev.github.io/ovpn-hub/privacy-policy
We welcome feedback to improve our products.
Short summary (for Google Play Data safety mapping)
- No account is required; the App does not provide VPN connections or handle VPN traffic, for either OpenVPN or V2Ray configurations.
- Transient IP use for diagnostics; network diagnostics include ICMP ping to VPN endpoints.
- Local caching on device via Hive CE (server lists, favorites, metrics, .ovpn files, V2Ray configuration URIs) — not uploaded to our servers.
- Financial Info — Purchase history: Collected by RevenueCat for App functionality and Analytics; not shared with third parties — RevenueCat processes it solely on our behalf as a service provider. Used to validate the one‑time Pro purchase and restore the entitlement. There is no subscription. Data encrypted in transit.
- App activity — Installed apps: A single yes/no signal for whether an OpenVPN‑compatible client is present, sent to Firebase Analytics. Package visibility is limited to the specific clients declared in the app manifest; your other applications are never enumerated or reported.
- Advertising data — collected and shared with Google: Monetization via Google Mobile Ads (AdMob) involves device or other IDs (advertising ID, app set ID), app interactions, app performance diagnostics, and approximate location inferred from IP address, processed by Google for advertising and fraud prevention, with consent where required (UMP, EEA/UK).
- App activity — App interactions: Firebase Analytics tracks anonymised feature usage (exports, filters, health checks, ad interactions). Disabled via UMP consent if declined.
- Diagnostics — Crash data: Firebase Crashlytics collects crash reports (stack trace, device info) for stability fixes.
- Data deletion: Available on request (see Section 13) — RevenueCat customer records are deleted within 30 days; the advertising ID can be reset or deleted in device settings.
- VPN sources and third‑party VPN apps/servers are outside our control and may have their own logging practices; review their privacy notes.