Облако VPN
MenuPrivacy Policy

Облако VPN Privacy Policy

Version of October 7, 2026. Effective date: October 7, 2026.

Русская версия

1. Who we are and what this policy covers

The Облако VPN app for iPhone and iPad (the "app") is developed and published by Professional Fabrication and Machine LLC, registration number 52456698, 16123 S Bud Broussard Rd, Prairieville, LA 70769, USA (the "developer", "we", "us").

The app is a client for connecting to proxy servers through a subscription. It works with a subscription from any compatible provider: you obtain a subscription (a link or a QR code) from a provider of your choice and add it to the app yourself. There is no registration or account in the app, and there are no in-app purchases.

The developer's company also runs its own subscription service (the "developer's subscription service"). It is sold outside the app. For subscriptions of this service, the app receives additional settings from the developer's server, and the developer's server receives account data from the service's management panel. This is described in section 5.

This policy explains what data the app keeps on your device, what it sends and to whom, why, and for how long, and which data of the developer's subscription service is associated with the app. Buying and paying for a subscription, traffic accounting on servers and other processing by the subscription provider itself (including the developer's subscription service) are described in that provider's terms (sections 5.5 and 6.1).

Contacts for data questions:

2. What the app does not do

  • It does not collect or send to the developer the content of your traffic, the websites you visit, your browsing history or your DNS queries.
  • It does not determine or send your location, Wi-Fi network names, phone number, name, email address, contacts or photos. Account data of the developer's subscription service (username, Telegram ID, email) reaches the developer's server from the service's panel, not from the app — section 5.
  • It does not send the developer your subscription link or the access token in it, nor server parameters (addresses, keys, passwords).
  • It contains no ads, advertising identifiers or third-party analytics libraries, does not track you across other apps and websites, and does not sell or share data for advertising.
  • It does not have your IP address stored in the developer server's database (see section 4.6).

3. What is stored on your device

WhatWhereWhy
Subscription link (contains the provider's access token)iOS Keychain, this device only, not transferred to other devices through backupsDownloading and refreshing the server list
Server list from the subscription and its parameters, routing profile, selected server, remaining traffic and expiry reported by the providerApp storage and the shared container of the app, its VPN extension and widget (App Group)Connecting, automatic server selection, showing the subscription
VPN configurationiOS system VPN settingsRunning the VPN, including connect on demand
Random installation ID (32 hexadecimal characters)App storageSection 4
Queue of error reports (up to 100 entries) before they are sentApp storageSection 4.2
Routing database files (geoip, geosite)App storage and App Group"Direct / through VPN" rules
Settings (reminders, notifications, selected mode)App storageSettings

Data in app storage and the App Group may be included in device backups made by iOS (iCloud or a computer), according to your iOS settings. The subscription link in the Keychain is not transferred to other devices through such backups.

The installation ID is generated randomly by the app and is not derived from hardware identifiers, your Apple ID or the advertising identifier.

4. What the app sends to the developer's server

The developer's server is admin.tuchkaspace.top. It provides the app with signed settings and receives the data listed below. All requests use HTTPS. When the VPN is on, a request first goes through the VPN and, after a network error, is retried directly over Wi-Fi or cellular.

4.1. Device check-in

When: when the app starts or returns to the foreground, when the VPN connects, and periodically while the VPN is on (currently about every 10 minutes, including from the VPN extension while the app is closed).

What:

  • the installation ID;
  • platform (iOS), app version, iOS version;
  • device language and region (for example, en-US);
  • the version of the settings received and whether automatic server selection is on;
  • up to four SHA-256 hashes (truncated to 32 characters) of path parts of the subscription link. The link and the token themselves are not sent and cannot be recovered from the hashes;
  • for notifications: the Apple Push Notification service (APNs) token, the environment (production or test build) and whether notifications are allowed.

Why: to deliver current settings, developer messages and notifications; to know which app versions are in use; for subscriptions of the developer's subscription service, to associate the device with the account in that service and apply its settings (section 5).

Association with an account in the developer's subscription service. The server compares the hashes from the check-in with the subscription hashes of the accounts of the developer's subscription service (section 5.2). If a hash matches, the server stores the identifier of that account in the device record. If your subscription comes from another provider, there is no match and no association is created.

The server responds with settings, developer messages and a speed limit if the developer has set one (for all devices, for a single device or for an account in the developer's subscription service), and, for subscriptions of the developer's subscription service, also the number of devices of the subscription (section 5.4). The speed limit is enforced by the app itself, on the device.

4.2. Error reports

When: after a failure to connect, to download the subscription, of automatic selection, of routing or of loading settings, and after a crash of the app or the VPN extension. Reports are queued on the device and sent in batches when a network is available. Sending does not depend on the statistics setting.

What:

  • the error type, its text and technical details (stack trace), time, how many times it repeated, whether it was fatal;
  • the server name as it appears in the subscription;
  • the installation ID, platform, app and iOS versions, device model (for example, iPhone15,2);
  • for crashes, the crash report that iOS hands to the app through MetricKit: exception type, signal, offsets in the app's code and memory information.

Before sending, the text is cleaned on the device and again on the server: links, tokens, UUIDs, keys, passwords, IP addresses and host names are replaced with placeholders.

Why: to find and fix errors and to help you when you contact support (by installation ID). If the device is associated with an account in the developer's subscription service, the admin panel shows that account's username next to the report.

4.3. Message acknowledgements

When you open or close a developer message in the app, or open it by tapping a notification, the app sends the installation ID, the message ID and the action ("opened" or "dismissed"). Why: not to show the message again and to count how many times it was opened.

4.4. Anonymous statistics

Sent only if the developer has turned statistics on in the published settings.

What: platform and app version; for servers in the developer's registry (the servers of the developer's subscription service; no statistics are sent about other servers) — network type (Wi-Fi, cellular, Ethernet), number of probes, failed probes and total latency per day; connection events (success, time in milliseconds, short failure reason), automatic switches between servers and their reasons, detection of mobile carrier restrictions.

Statistics do not include the installation ID, IP address or network names.

Why: to improve automatic server selection and to find servers that do not work.

4.5. Downloading settings

The app downloads a signed settings file from the developer's server (/v1/config). No personal data is sent in this request.

4.6. IP address and server logs

Like any internet server, the developer's server sees the IP address a request comes from. With the VPN on, this is usually the VPN server's address, not yours. The server software uses the address only in memory, to limit the request rate, and does not store it in its database. The web server that accepts HTTPS connections does not keep a log of all requests. Its technical log records only connection errors and service messages, which may include the IP address, time and requested page address. This log is used to diagnose failures, is not associated with the installation ID and is kept for no longer than 7 days.

4.7. Retention on the server

DataPeriod
Error reports30 days from receipt, then deleted automatically
Anonymous statistics90 days, then deleted automatically
Device record: installation ID, platform, versions, language and region, settings version, automatic selection, notification token and environment, notification permission, association with an account in the developer's subscription service (section 4.1), first and last check-in datesWhile the device keeps checking in. If a device has not checked in for 180 days, its record is deleted automatically together with all of that device's data on the server: error reports, records of messages and notifications, and a speed limit set for the device. Earlier at your request (section 9). The notification token is removed earlier if Apple reports it is invalid
Records of message delivery and opening and of notifications sentDeleted together with the device record (after 180 days without check-ins or at your request) or together with the message. Totals per message (how many were delivered and opened) are kept without the installation ID
Log of actions by the developer's staffIf a staff member performed an action on a device (for example, set a speed limit or deleted the device's data), the log keeps a record of the action. After a device's data is deleted, the installation ID in such records is shortened to its first 12 characters
Account data of the developer's subscription service received from its panel (section 5.2)As long as the account exists in the service's panel. After the account is deleted in the panel, its record is deleted on the developer's server at the next synchronization (currently within 30 minutes)
The account's device list from the service's panel (section 5.2)Not stored in the database: kept only in the server's memory, for no longer than 10 minutes

4.8. Where data is stored

The developer's server is hosted by a hosting provider in the Russian Federation. Account data of the developer's subscription service received from its panel (section 5.2) is stored there as well.

5. The developer's subscription service

5.1. What it is

The developer's company runs its own subscription service. Subscriptions to it are sold outside the app; the app has no purchases, prices or payment links. To the app, a subscription of this service is a link like a subscription from any other provider: you add it yourself, and the app connects to the servers in it.

To make the account's speed limit, "Devices N of M" and automatic server selection under the service's policy work for subscriptions of this service, the developer's server is connected to the service's management panel and receives account data from it.

5.2. What the developer's server receives from the service's panel

About accounts (periodically, currently every 30 minutes, about all accounts of the service):

  • the account's internal identifiers in the panel;
  • username;
  • Telegram ID, if the account has one;
  • email address, if the account has one;
  • account status (for example, active, disabled, expired) and subscription end date;
  • the account's device limit;
  • a SHA-256 hash (truncated to 32 characters) of the subscription's short identifier. The developer's server neither receives nor stores the identifier itself or the subscription token.

About the account's devices (on request, only for an account a device is associated with): the device list that the service's panel keeps to limit the number of devices — the installation ID (from the x-hwid header, section 6.1), platform, OS version, device model, User-Agent string, dates added and updated. This list is not stored in the developer server's database: it is kept in memory for no longer than 10 minutes. Only the number of devices and the limit are sent to the app.

5.3. How this is associated with your device

The app sends the developer's server hashes of path parts of the subscription link (section 4.1). If one of them matches the subscription hash of an account of the service, the server stores the identifier of that account in the device record. This way the installation ID, versions, language and region, notification token and error reports of the device become associated with the account in the developer's subscription service — with its username, Telegram ID and email.

If you added a subscription from another provider, there is no match: the device's data is not associated with any account.

5.4. What this is used for and who sees it

For a device associated with an account of the developer's subscription service, the developer's server:

  • tells the app the speed limit if one is set for the account, and "Devices N of M" (how many devices the panel counts and how many are allowed);
  • when the account's speed limit changes, sends its devices a silent service notification so that they get the new limit right away.

In addition, for subscriptions of the developer's subscription service (whether or not a device is associated with an account), the signed settings that every installation of the app receives contain:

  • the service's automatic selection policy — priorities and availability of its servers; the app recognizes these servers by their names in the subscription and applies the policy on the device;
  • the service's current domains: if a subscription link points to a former domain of the service, the app replaces the domain in it with the current one. The replacement happens on the device; the link is not sent to the server.

The developer's staff see in the admin panel: accounts of the service (username, Telegram ID, email, status, subscription end date), the devices associated with them (installation ID, platform, app version, last check-in date), the device list from the service's panel and the error reports of these devices. This is needed for support: to find a device when you contact us, to free a slot in the device limit, to investigate an error. At your request, staff can remove a device from the account's device list in the service's panel.

5.5. What the service's terms cover

The service's panel keeps the account's device list from the headers the app sends when it downloads the subscription (section 6.1), to limit the number of devices. Buying and paying for a subscription, the data you provide when buying, and traffic and connection accounting on the service's servers are described in the terms of the developer's subscription service, which you accept when you buy a subscription.

6. What your subscription provider and third parties receive

6.1. Your subscription provider

You choose your subscription provider. It can be any compatible provider, including the developer's subscription service (section 5). The provider's terms and privacy policy apply alongside this policy.

  • When the subscription is downloaded or refreshed, the app sends a request to the address in the link, containing the link itself (with the provider's access token) and these headers: User-Agent such as v2rayNG/1.10.11 (compatible; OblakoVPN/1.0.17; iOS 26.6) — the app's name and version and the iOS version (the leading v2rayNG/1.10.11 tells the provider which subscription format the app understands), x-hwid — the installation ID, x-device-os — iOS, x-ver-os — the iOS version, x-device-model — the device model. Providers that limit the number of devices per subscription need the x-… headers.
  • VPN traffic goes through the provider's servers. What the provider records about connections is up to the provider.
  • The provider's routing profile may specify addresses from which the app downloads routing database files (HTTPS only) and DNS servers. The owners of those addresses see an ordinary HTTPS request and an IP address. Without a profile, DNS queries with the VPN on go to 1.1.1.1 (Cloudflare) through the VPN server.

6.2. Connectivity checks

To tell "no internet", "Wi-Fi sign-in page", "carrier restrictions" and "VPN server not responding" apart, the app, while the VPN is on, periodically sends simple requests that carry none of your data: through the VPN to www.gstatic.com (Google) and cp.cloudflare.com (Cloudflare); directly to www.gstatic.com, captive.apple.com (Apple) and ya.ru (Yandex). The developer may replace these addresses in the settings. To show latency in the server list, the app opens test connections to the server addresses from your subscription.

6.3. Apple

  • Notifications. To deliver notifications, iOS gives the app an APNs token; the developer's server sends notifications through Apple's service. Regular notifications are shown only if you allowed them; silent service notifications (a "check settings" signal) arrive without permission and show nothing. You can turn regular notifications off in iOS Settings or in the app: Settings → Notifications.
  • Crash reports are produced by iOS (MetricKit) on the device and handed to the app; the app sends them to the developer as described in section 4.2.
  • Apple may collect its own usage and crash data if you allowed it in iOS settings (Analytics & Improvements). This is governed by Apple's policy.

6.4. Hosting provider

The hosting provider of the developer's server keeps the server running and technically has access to it.

6.5. Support

If you contact support, we receive what you send us and your Telegram account details or email address. Telegram processes conversations under its own policy. Do not send your subscription link to support — it contains an access token.

The developer does not sell data and does not share it with anyone other than those listed above, except where required by law.

7. iOS permissions

  • VPN. The app creates a VPN configuration through the system Network Extension framework (Packet Tunnel). Traffic is processed on the device and routed to the server you selected.
  • Camera — only to scan a subscription QR code or the code on a TV screen. Images are processed on the device and are not stored or sent.
  • Local network — only to send the subscription to your TV on the same Wi-Fi network. The link is sent directly to the TV in encrypted form; the developer's server is not involved.
  • Notifications — section 6.3.

We process data so that the app works as you expect (connection, settings, automatic selection, notifications, messages), to apply the subscription settings of the developer's subscription service (section 5), to find and fix errors, to protect the server from abuse and to answer support requests.

Where the applicable law requires a legal basis for processing (for example, the EU General Data Protection Regulation, GDPR), we rely on: performance of a contract — for the operation of the app and the subscription settings of the developer's subscription service; legitimate interests — for fixing errors, anonymous statistics and protecting the server; consent — for regular notifications (you can withdraw it in iOS settings).

9. Your rights and how to delete data

On the device:

  • Settings → «Удалить подписку» (Delete subscription) removes the subscription link, the server list, the routing profile and the VPN configuration from the device.
  • Settings → «О приложении» (About) → «Сбросить настройки» (Reset settings) also resets the app settings.
  • Deleting the app removes its data from the device, including the installation ID; a new installation creates a new ID, and a subscription link left in the Keychain is deleted on first launch.

The installation ID is kept when you delete the subscription or reset settings.

On the developer's server: a device's data is deleted automatically if it has not checked in for 180 days (section 4.7). Before that, you can request information about the data associated with your installation ID, its correction or its deletion. Write to support@app.tuchkaspace.top or on Telegram to @oblakosupportt_bot and include your installation ID: Settings → «О приложении» (About) → «ID устройства (для поддержки)» → «Скопировать ID» (Copy ID). Without the ID we cannot find the device's data. On a deletion request we delete the device record from the developer's server together with all the data listed in section 4.7 and confirm the deletion. We will respond within 30 days.

If the app keeps running on the device with the same installation ID after the deletion, the server creates a new device record at the next check-in. To avoid this, delete the app (a new installation creates a new ID) and only then send us the deletion request (copy the installation ID beforehand).

The developer's subscription service: the developer's server receives account data (username, Telegram ID, email, subscription end date) from the service's panel and deletes it after the account is deleted in the panel (section 4.7). To delete the account or correct its data, contact the support of the developer's subscription service or us using the contacts above. The association of a device with the account is deleted together with the device's data; a device can be removed from the account's device list in the service's panel on request to support.

Data about you held by another subscription provider is deleted by that provider — contact the provider.

You can also turn notifications off in iOS Settings. There is no separate statistics switch in the app: statistics are anonymous and are turned on only by the developer (section 4.4).

10. Security

Communication with the developer's server is HTTPS only. Settings received by the app are signed and verified by the app. The subscription link is stored in the iOS Keychain. Error texts are cleaned of links, keys and addresses before sending. The access token to the panel of the subscription service is kept only on the developer's server; the server only reads data from the panel and can remove a device from an account's device list at the request of support. The admin panel is available over HTTPS only, and sign-in to it is protected by a password and two-factor authentication; sign-in to the server is by SSH key only.

11. Children

The app is not intended for children under 13, and we do not knowingly collect their data. If you believe such data has reached us, contact us and we will delete it.

12. Changes to this policy

We may update this policy when the app changes. A new version is published at this address with a new date. We will announce material changes in the app.

13. Contact

Professional Fabrication and Machine LLC, registration number 52456698, 16123 S Bud Broussard Rd, Prairieville, LA 70769, USA.

See also: Terms of Use, Support.

Professional Fabrication and Machine LLC

16123 S Bud Broussard Rd, Prairieville, LA 70769, USA