Privacy Policy
Effective and last updated: 12 August 2026
This policy describes how Whale VPN handles data for the Whale VPN and WhaleVPN Pro Android applications and their related account, VPN, attribution, reliability and support services. Whale VPN is the developer and data controller for these services. Questions and privacy requests can be submitted through Whale VPN support on Telegram.
1. Account and service data
Whale VPN creates either an installation-bound guest account or an account registered with an email address. We process the account or guest identifier, email address when provided, password hash and authentication data, subscription entitlement, device sessions, traffic allowance and usage totals, support messages, and account security events. Passwords are transmitted over an encrypted connection only for authentication, are stored as one-way hashes, and are never sent to Firebase.
2. VPN traffic and connection records
The app uses Android VpnService to create a device-level encrypted tunnel to a Whale VPN endpoint. While the VPN is connected, our infrastructure processes the network traffic needed to deliver the service and records connection metadata: the account or installation identifier, source IP address, destination domain, destination port and protocol, selected VPN server, timestamps and traffic totals. Raw destination connection records are retained for up to 90 days; per-account, per-domain daily summaries are retained for up to 180 days.
We use these records to operate and secure the VPN service, diagnose connection and routing faults, plan capacity, enforce service limits, and investigate abuse. We do not use VPN traffic for advertising, sell it, or alter third-party advertising traffic. We do not intentionally record the content of web pages, messages or files carried inside the tunnel.
3. First-party diagnostics and app activity
After the required in-app disclosure and consent, the Android app sends Whale VPN an installation identifier, download source, app/device/OS version, network type, connection state, routing mode, selected server, latency, traffic totals, app lifecycle state, connection outcomes and bounded error details. It may also send Dart crash names, reasons and stack traces. We use this information for authentication, service operation, installation attribution, reliability analysis, troubleshooting, fraud prevention and security. Operational telemetry is normally retained for up to 90 days; de-identified daily statistics may be retained for up to 180 days.
4. Firebase Analytics and Crashlytics
In the Google Play version, Firebase collection is disabled until the user accepts the prominent in-app disclosure. In other Android distributions, optional analytics may initially be enabled. Usage Analytics and Crash Reporting are separate controls and can each be turned off in Settings.
When Usage Analytics is enabled, Google Analytics for Firebase may process a Firebase app-instance identifier, app lifecycle and session events, limited app interactions, app/device metadata, confirmed download attribution identifiers, and approximate location inferred by Google from an IP address. When Crash Reporting is enabled, Firebase Crashlytics may process crash logs, stack traces, ANR and native crash information, device/app metadata and a Crashlytics installation identifier. Google processes this data as a service provider acting for Whale VPN.
Whale VPN disables advertising-ID collection and ad-personalization signals. The app contains no advertising. Firebase events do not contain passwords, subscription contents or browsing destinations; the VPN connection records described in section 2 are processed separately on Whale VPN infrastructure.
5. Download attribution
For a direct APK or Google Play installation, the app may send a short one-time download token, a 32-character Whale installation identifier and a fixed distribution-channel value to Whale VPN's attribution gateway. The Whale identifier is derived from an Android app-scoped system identifier; the original identifier is not transmitted. If Usage Analytics is enabled, the confirmed token, Whale installation identifier and channel may also be sent to Firebase Analytics to measure installation conversion.
6. Sharing, service providers and international processing
We do not sell personal or sensitive data and do not share it for advertising. Data may be processed by infrastructure, network, email, customer-support and analytics providers acting on our instructions, including Google for Firebase Analytics and Crashlytics. We may disclose information when required by applicable law, to protect users and the service, or in connection with a corporate transaction with appropriate notice. Processing may occur outside the user's country. Data is protected in transit using HTTPS/TLS and, for VPN traffic, an encrypted tunnel to the selected VPN endpoint. Access to stored data is limited to authorized operational personnel.
7. Choices, retention and deletion
The Google Play version does not start account provisioning, first-party telemetry, Firebase Analytics or Crashlytics before the prominent disclosure is accepted. Declining exits the app and the disclosure is shown again at the next launch. VPN connection records in section 2 are required while the VPN service is being used. Optional Usage Analytics and Crash Reporting can be disabled independently in Settings.
Account deletion can be requested inside the app or at whaleconnect.net/account/delete without installing the app. The account is disabled immediately and permanently deleted after a 7-day grace period. Associated account, authentication, support, device and session data is deleted or de-identified. Records that must be retained for legal, tax, accounting, security or fraud-prevention reasons are kept only for the required period and are no longer linked to an identifiable account where possible. Firebase retention follows the controls configured for the Whale VPN Firebase property.
8. Children
Whale VPN is intended for adults and is not directed to children under 18. We do not knowingly collect personal data from children.
9. Changes
We may update this policy when the app, providers or legal requirements change. The effective date at the top identifies the current version.
隱私權政策摘要
Whale VPN 與 WhaleVPN Pro 使用 Android VpnService 建立裝置級加密通道。VPN 連線期間,我們的基礎設施會處理流量,並記錄帳號或安裝識別碼、來源 IP、目標網域、連接埠與協定、所選節點、時間及流量總量。目標連線原始記錄最多保留 90 天;按帳號、網域及日期彙總的記錄最多保留 180 天。這些資料用於營運與保護服務、排查連線及路由故障、容量規劃、服務限制與濫用調查,不用於廣告,也不出售。
Google Play 版本在您接受應用程式內的顯著揭露前,不會開始帳號建立、第一方遙測、Firebase Analytics 或 Crashlytics。接受後,應用程式會向 Whale VPN 傳送安裝識別碼、下載來源、裝置/系統/應用程式版本、網路類型、連線狀態、節點、延遲、流量與診斷資料。可選的使用統計與當機回報由 Google Firebase 以服務供應商身分處理,Google 可能依 IP 推斷大致地區;兩項均可在設定中獨立關閉。本應用程式不含廣告,並關閉廣告 ID 與廣告個人化訊號。
可在應用程式內或前往 whaleconnect.net/account/delete 申請刪除帳號。帳號會立即停用,7 天寬限期後永久刪除,相關帳號、驗證、客服、裝置與工作階段資料會刪除或去識別化。法律、稅務、會計、安全或防詐所必須保留的記錄只保留必要期間。隱私問題可透過 Telegram 聯絡 Whale VPN 客服。