TipTop VPN

TipTop VPN / Legal

Privacy Policy

This Privacy Policy explains how TipTop VPN handles information when you use the TipTop VPN iOS application and related services.

Effective date: September 23, 2026   |   Last updated: September 23, 2026

Plain-language summary: The current iOS client configures Apple's system VPN framework and does not contain application code that parses the content of VPN traffic. Apple processes App Store payments. Firebase Remote Config helps deliver node configuration. The VPN node and its operating environment may process connection metadata needed to authenticate, route, secure, troubleshoot, and protect the service.

1. Scope

This Privacy Policy applies to the TipTop VPN mobile application, its in-app subscription features, and the VPN connection service made available through the application (collectively, the "Service"). It does not apply to websites, products, or services that link to a different privacy policy.

The Service is provided by [Legal Entity Name] ("TipTop VPN," "we," "us," or "our"). Replace the bracketed business details in this document before public release.

2. Information We Handle

Information you provide

  • Support messages: If you contact us, we receive the email address and message details you choose to send.
  • VPN settings: The app stores settings such as your selected server, protocol choice, and connection preferences on your device so the app can operate.

Information created by the app

  • Connection state: The app may store connection status, the selected node identifier, and the time of the last successful connection locally on your device.
  • Connection display: While the connected Home screen is visible, the app checks the public IP address through an HTTPS IP lookup service and samples available local tunnel-interface byte counters to display upload and download rates. These display measurements are kept in memory and are not retained as a browsing history.
  • VPN configuration: Credentials and VPN configuration references are stored in Apple's Keychain or in the system VPN configuration area. The app does not store payment card details.

Information received from service providers

  • Remote configuration: Firebase Remote Config may process an installation identifier, app version, operating system version, locale, and request metadata when the app checks for node and feature configuration.
  • Purchase status: StoreKit provides the app with product and entitlement information needed to unlock, manage, and restore subscriptions. Apple handles payment card and billing details.

Scope of the current client implementation

Based on the current repository, the client configures the iOS NetworkExtension framework and does not include application code that reads or parses website, message, file, or other VPN traffic content. This statement describes the current client build only; it is not a promise about a VPN node, network carrier, hosting provider, or future release.

The current iOS target does not declare a Firebase Analytics dependency in its Podfile, and no Analytics API use was found in the reviewed Swift sources. The Google service configuration still contains an Analytics-related flag, so the release build and Firebase project settings must be checked before publication. Do not publish a stronger analytics statement until that check is complete.

3. How We Use Information

We use information only as reasonably necessary to:

  • provide, maintain, and troubleshoot the Service;
  • create and save a VPN configuration on your device;
  • show available VPN nodes and apply node availability rules;
  • process, validate, restore, and manage subscriptions through Apple;
  • deliver security, configuration, and operational updates;
  • respond to support requests and prevent misuse; and
  • comply with legal obligations and protect our rights.

The current repository does not show an advertising or behavioral-profiling implementation. The operator must keep this statement aligned with the final Firebase project, app build, VPN infrastructure, and support systems.

4. Sharing

We may share limited information with the following categories of recipients:

  • Apple: Apple processes App Store purchases, subscription billing, refunds, and transaction records under Apple's terms and privacy policy.
  • Infrastructure providers: Firebase and hosting providers may process technical data needed to deliver Remote Config, operate infrastructure, protect the Service, and respond to support requests.
  • VPN node operators: A VPN node must receive network traffic in order to route it. The node operator may process technical metadata such as the connecting IP address, destination address, timestamps, data volume, and error information according to its operational practices.
  • Legal and safety recipients: We may disclose information if required by law, legal process, or a valid governmental request, or when reasonably necessary to prevent fraud, abuse, security incidents, or harm.

Recipients are expected to use information for the purposes for which it is provided and to apply reasonable safeguards.

5. VPN Connection Data

When you connect, your internet traffic is routed through the VPN node you select. The current iOS client does not include application code that inspects or records the content of that traffic. The connection still requires technical processing by the node and network providers, including IP routing, authentication, bandwidth management, abuse prevention, and fault diagnosis.

The repository's strongSwan deployment template enables service logging at a limited verbosity and uses system journal diagnostics. Those logs can contain connection metadata such as peer addresses and identities. The repository does not establish a production retention period, deletion process, or complete log inventory. The operator must document and implement those controls before publication. Do not use the Service to transmit information that you are not authorized to transmit.

Node names and displayed countries describe the available routing options. A displayed country may not always be the physical location of the server or the location of the final internet exit. Check the current node description before relying on a location representation.

6. Subscriptions and Purchases

TipTop VPN offers optional in-app subscriptions through Apple In-App Purchase. Current product identifiers include weekly_3days_trial and TipTop_annual_premium. The products, prices, introductory offers, eligibility, and billing period shown in the App Store or in the app control the purchase.

Apple processes payment and provides transaction and entitlement status to the app. TipTop VPN does not receive your full payment card number. You can use the app's restore purchase flow to refresh eligible purchases associated with your Apple Account.

Subscription status may be refreshed when the app starts, returns to the foreground, or you request a restore. We use the result to enable or disable premium features. For billing, cancellation, renewal, and refund details, see Apple's applicable terms and contact Apple Support where appropriate.

7. Third-Party Services

The app may use the following third-party technologies:

  • Apple NetworkExtension: iOS system frameworks create and manage the VPN connection.
  • Apple StoreKit: Apple processes in-app purchases, subscription transactions, and restoration.
  • Firebase Remote Config and Firebase Installations: These services help retrieve and identify app configuration requests. Their processing is subject to Google's applicable terms and privacy documentation.
  • ipify: The app contacts api.ipify.org or api64.ipify.org over HTTPS to show your current public IP. The service receives the source IP and ordinary request metadata. The app does not send VPN keys, browsing history, or subscription details with this request. See ipify for provider information.

Third-party services have their own terms and privacy practices. Review those documents before using their services.

8. Retention and Security

Local app data remains on your device until you delete it, remove the app, or clear the relevant settings. App deletion may not remove records held by Apple, Firebase, VPN node operators, or other providers. Retention by each provider must be confirmed against the production configuration and documented before release; this repository does not prove a single end-to-end retention period.

We use reasonable administrative, technical, and organizational safeguards. No transmission or storage method is completely secure. You are responsible for protecting access to your device and Apple Account.

9. Children

The Service is not directed to children under 13, or the minimum age required in your jurisdiction. We do not knowingly collect personal information from children. If you believe a child provided personal information, contact us so we can review and delete it where required.

10. Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where processing is based on consent. You may also have the right to complain to a data protection authority.

To make a request, contact us using the details below. We may need to verify your identity and may retain information where required or permitted by law. You can also manage subscriptions through your Apple Account settings.

11. Changes to This Policy

We may update this Privacy Policy when the Service, law, or data practices change. We will post the updated version at the same URL and update the effective date. If a change materially affects your rights, we will provide additional notice where required.

12. Contact

Email: support@mobilesupertools.com

Support URL: To be provided.