Privacy Policy

Effective Date: May 6, 2026
Last Updated: May 6, 2026
Developer: MH DIGITAL

Data Controller

MH DIGITAL is the data controller for any data this application processes. Contact: [email protected]. As we do not collect personal data, our data controller responsibilities are limited to confirming non-collection upon request.

Information we collect

None. Birrya VPN does not require an account, an email address, or any sign-up. We do not embed analytics SDKs and do not collect advertising identifiers (including IDFA).

Data stored on your device

The app stores the following locally in iOS UserDefaults: speed test history (last 100 records), reaction-time history (last 80 entries), pulse host preferences, and your settings toggles. This data never leaves your device and is removed when you uninstall the app.

VPN traffic

The IKEv2 tunnel encrypts traffic between your device and our server endpoint. We do not log connection metadata, IP addresses, timestamps, session duration, or traffic content. We operate a strict no-logs policy on the VPN endpoint.

Third-party services

For the diagnostic features, the app issues requests to a small set of public endpoints: Cloudflare Speed Test (speed.cloudflare.com) for bandwidth measurement, Cloudflare 1.1.1.1 for latency probes, and user-toggleable hosts in the live pulse feature including Google DNS, GitHub, and OpenAI. These services see only standard request metadata (your IP address visible to that service, request timing). We do not share any user identifiers with them because we do not have any. For Cloudflare's data handling practices, see https://www.cloudflare.com/privacypolicy/.

Security

Network traffic between your device and our VPN endpoint is encrypted using IKEv2 with industry-standard ciphers negotiated by Apple's Network Extension framework. App preferences and history stored on your device are protected by iOS sandboxing and the device passcode/biometric lock. We do not transmit your data to our servers, so there is no server-side storage to secure.

Your Privacy Rights (GDPR / EU users)

If you are located in the European Union, the United Kingdom, or another jurisdiction with comparable data protection law, you have the following rights regarding personal data:

To exercise any of these rights, email [email protected].

California Residents (CCPA / CPRA)

We do not collect, sell, or share personal information of California residents within the meaning of the California Consumer Privacy Act or the California Privacy Rights Act.

To exercise any of these rights, email [email protected].

Children's privacy

Birrya VPN is not directed to children under 13 (or under 16 in EU jurisdictions where applicable). We do not knowingly collect personal information from children. If you are a parent or guardian and believe a child has provided us with information, please contact [email protected] and we will confirm there is nothing to delete.

Changes

We may update this policy from time to time. The Effective Date and Last Updated fields above will be revised when changes are made.

Contact

Questions about this policy or your data: [email protected]

Jurisdiction

This Privacy Policy is governed by the laws of France, where MH DIGITAL is established, without regard to conflict-of-law principles.

Back to Birrya VPN