This page covers Open Door VPN for iPhone. Our Android app is built differently and has its own disclosure.
Data Collected
No personal or sensitive data is collected. The app has no accounts, logins or profiles. It does not collect your identity, contacts, location, photos, browsing history or DNS queries. There is no advertising identifier (IDFA), no vendor identifier (IDFV), and no installation ID created by us.
Free servers. If you use the built-in free servers, the app asks our server for the current list, and reports the ID of the key it was given plus whether the connection succeeded, failed or ended — so that shared servers can be balanced and dead ones withdrawn. The key ID identifies a shared server, not you; many people use the same one. As with any internet request, our server receives your IP address in order to reply. Servers and subscriptions you add yourself connect directly and are never sent to us.
Data Shared
We do not sell, use, or disclose to any third party any data collected through this app, for any purpose.
- The iOS app contains no advertising SDK and no advertising of any kind
- It contains no analytics, crash-reporting or attribution SDK — verified: the shipped binary links only Apple system frameworks and our own VPN engine
- No data is sold or shared with advertisers, data brokers or analytics companies
Third-Party Services
The app has no third-party SDKs, but some screens contact external services:
- ipinfo.io — receives your IP address automatically when you open the IP Checker screen, so it can show your IP and location
- Cloudflare (
1.1.1.1,speed.cloudflare.com) — receives your IP address when you run a leak test or speed test - app.contxchat.com — our live-chat support vendor, only if you open Live Chat; it has its own privacy practices
- nextv2.com — only when your subscription provider's site is unreachable, the app can retry through this mirror with your subscription address included so it can be fetched for you. That address, including any token in it, is visible to the mirror.
Data Stored on Device
Stored locally on your iPhone and never transmitted to us:
- Server configurations and subscription addresses, including their credentials and tokens — stored in the iOS Keychain, which is encrypted by the system and not readable from an unencrypted backup
- App preferences and routing rules — stored in the app's private storage
- A connection log for troubleshooting (server address, connection stages, errors, memory use) — viewable and clearable inside the app
- The VPN engine's own diagnostic log while a tunnel is running — deleted every time you connect, and never uploaded
Network Activity
- VPN tunnel: routes device traffic through the server you connect to, using the Xray protocol
- Subscription updates: fetches server lists from URLs you provide
- Free servers: fetches the free-server list and reports connect / disconnect / failure events
- Latency testing: sends lightweight requests to measure server response times
No browsing content is ever sent to us. We do not log, inspect, record or store the sites you visit or anything you send through the tunnel.
Encryption
VPN traffic is encrypted using industry-standard protocols, depending on the server you choose:
- TLS 1.3
- AES-128-GCM / AES-256-GCM
- ChaCha20-Poly1305
- XTLS (Xray TLS)
Data Deletion
All locally stored data can be deleted by removing individual servers or subscriptions inside the app, or by uninstalling it. Uninstalling removes everything, including the Keychain entries. Since we hold no account and no profile for you, there is nothing stored externally to delete.
Permissions Used
The app uses Apple's Network Extension framework to create the VPN tunnel — iOS asks for your permission the first time you connect. It requests no other permissions: no location, contacts, photos, microphone, camera, health or calendar access.
Contact
For questions about data collection, contact us at support@mmopendoor.com.
