Open Door VPN is designed with privacy as a core principle. This disclosure explains how data is handled. It covers Open Door VPN for Android; our iPhone app is built differently and has its own disclosure.
Data Collected
No personal or sensitive data is collected. Open Door VPN has no accounts, logins, or profiles, and does not gather your identity, contacts, location, browsing history, or DNS queries. It contains no analytics, crash-reporting, or usage-tracking SDKs.
Optional free servers. If you use the built-in free servers, the App contacts our server to fetch the current server list and to report an anonymous, aggregate connection count so we can balance load. This carries no account and no browsing data. As with any internet request, our server temporarily receives your device's IP address in order to reply; it is not used to identify, profile, or track you. Servers you add yourself and subscriptions you import connect directly and never involve our infrastructure.
Data Shared
We never sell or share your personal data. We hold none to sell. One third party does receive data: the direct-download build carries the Unity Ads SDK, which sees device and advertising identifiers so it can show ads. It never sees your browsing, your DNS queries, or anything inside the tunnel.
- The build offered here (com.opendoor.vpn) shows ads via the Unity Ads SDK; an ad-free build (com.opendoor.vpn.play) exists for store distribution but is not currently offered
- The App integrates no analytics platforms
- No personal data is sold or shared with anyone
Unity Ads is subject to Unity's privacy policy.
Data Stored on Device
The following data is stored locally on your device and is never transmitted to us:
- Server configurations (address, port, protocol, credentials) — stored in a local database
- Subscription URLs — stored in a local database
- App preferences (theme, DNS, routing rules) — stored in Android SharedPreferences
- Connection logs — stored temporarily in memory, cleared when the App is closed
Network Activity
The App performs the following network activities:
- VPN tunnel: Routes device traffic through the server you connect to, using the Xray protocol
- Subscription updates: Fetches server lists from URLs you provide
- Free servers: Fetches the free-server list from our backend and reports an anonymous connection count to balance load
- Latency testing: Sends lightweight HTTP requests to measure server response times
All network activity is initiated by your actions in the App. No browsing content is ever sent to us.
Encryption
All VPN traffic is encrypted using industry-standard protocols, including:
- TLS 1.3
- AES-128-GCM / AES-256-GCM
- ChaCha20-Poly1305
- XTLS (Xray TLS)
The specific encryption method depends on the server configuration you choose.
Data Deletion
All locally stored data can be deleted by:
- Using the App's built-in reset: menu (☰) → Reset → Full application reset, which disconnects the VPN and permanently erases every server, subscription, routing rule, preference and log, then closes the App
- Removing individual server configurations or subscriptions within the App
- Clearing App data from Android Settings
- Uninstalling the App
The same Reset screen also offers Reset settings, which restores preferences to their defaults while leaving servers, subscriptions and routing rules intact.
Since no data is stored externally, uninstalling the App removes all associated data completely. Full instructions are on our Account & Data Deletion page.
Permissions Used
The App requests the following Android permissions:
- INTERNET — Required to establish network connections through the VPN
- ACCESS_NETWORK_STATE — Required to check network connectivity status
- FOREGROUND_SERVICE — Required to maintain the VPN connection in the background
- POST_NOTIFICATIONS — Required to show the VPN connection status notification
- FOREGROUND_SERVICE_SPECIAL_USE — Required on Android 14+ to declare the VPN foreground service type
- RECEIVE_BOOT_COMPLETED and WAKE_LOCK — Declared but not currently used by the App
- REQUEST_INSTALL_PACKAGES — Direct-download build only, so the in-app updater can hand a downloaded update to the system installer
- BIND_VPN_SERVICE — The permission Android requires a VPN service to be protected by
Contact
For any questions regarding data collection practices, please contact us at support@mmopendoor.com.
