Privacy Policy
Last updated: August 26, 2026
The short version: Grbit collects no personal data. There is no account system, no analytics, and no backend of ours that your data could reach. Everything the app knows lives on your device.
Grbit ("the app") is an iOS Personal VPN / network utility published by GRBIT NETWORKS LIMITED ("we", "us"). This policy explains what data the app handles, where that data lives, and the choices you have.
1. Data we collect
We do not collect personal data. The app has no registration or sign-in, and it contains no third-party analytics, advertising, or tracking SDKs. We do not receive your usage data, your configuration, or your network traffic. We operate no server that the app reports to.
We do not, and will not, sell, use, or disclose to any third party any data about you or your network activity, for any purpose.
2. Data stored on your device
To do its job, the app stores the following on your device only:
- Server configurations you add. Credentials and other secrets are stored in the iOS Keychain.
- Subscription URLs you import, and the server lists they resolve to.
- Routing rules, policy groups, and app settings.
- Diagnostic output you generate, such as traffic records, connection logs, and capture files.
This data never leaves your device unless you export and share it yourself. Deleting the app deletes it.
3. Network traffic
When you connect, iOS may show a VPN configuration. That is how Apple's Network Extension packet-tunnel API hands traffic to the app on your device for rule matching. Your traffic is then forwarded directly to servers you configured. We do not operate those servers, we do not route traffic through any infrastructure of ours, and we have no ability to observe, log, or store it. Grbit is a client only; it is not a VPN service provider.
4. Connections the app makes
The app talks to the network only in ways you initiate:
- Fetching a subscription from the provider URL you added. That request goes directly from your device to your provider and is governed by the provider's own privacy practices.
- Connecting to servers in your configuration.
- Running latency tests you start against servers in your configuration.
The app makes no background calls to us and sends no telemetry.
5. On-device diagnostics
Optional diagnostic and debugging features — for example connection summaries, traffic records, or HTTPS decryption — run on your device and are off until you switch them on. HTTPS decryption is scoped to hostnames you explicitly add to an allow list, not your traffic in general. Turning it on takes two manual steps only you can complete: installing the certificate profile the app generates, then separately granting that certificate full trust in iOS Settings > General > About > Certificate Trust Settings — the app cannot do this on your behalf. The certificate's private key is generated on your device, stored in the Keychain, and never transmitted anywhere, including to us — we operate no servers, so decrypted traffic never leaves your device. For hosts you've allow-listed, the companion rewrite feature can edit response headers, issue redirects, or substitute content you've written into your own rule (up to 64 KB); it does not alter the body of the actual upstream response. You can remove the installed profile at any time from iOS Settings, which immediately turns decryption off for every host.
6. Purchases
If the app offers paid features, payment is handled entirely by Apple through your Apple Account. We do not receive or store your payment details.
7. Children
The app is not directed at children under 13, and, as described above, it does not collect personal information from anyone.
8. Changes to this policy
If we change this policy, we will update this page and revise the date above. Material changes will also be noted in the release notes.
9. Contact
Questions about privacy? Write to hello@grbit.app.