Privacy Policy
NorthStatus exists to protect your traffic, so the rule is simple: we never look at what you do inside the tunnel. To run the service, enforce device limits, fix crashes, and make the apps better, we do collect the account, device, and diagnostic data listed below — and nothing beyond it.
What we collect
- Account data — your email address, your password (stored only as a salted hash — we cannot read it), subscription plan and expiry, redemption-code records, sign-in sessions (session tokens are stored hashed; we also record the browser/app user-agent of each sign-in for account security), and the list of devices bound to your account.
- Device & app data — platform (iOS / Android / Windows / macOS), device model, OS version, app version, system language, CPU architecture, and a hashed device identifier derived from a platform-provided ID. We never see the raw hardware identifier. Used for per-account device limits, compatibility decisions, and tying diagnostics to a device class.
- Connection diagnostics — when the app connects, fails to connect, or disconnects: event type, timestamp, the node you selected, protocol, error codes and error messages, connection duration, and latency measurements. This is how we find broken nodes and routes. It never includes what you access through the tunnel.
- Usage analytics — app-lifecycle and feature-usage events (app launched, screen opened, update installed, and similar), together with the device and app attributes above and related diagnostic attributes. This tells us which features matter and where the apps fail in practice. These diagnostic and analytics events are stored with your app version and are retained with those events for up to 24 months (see Retention).
- Crash reports — when an app crashes: stack trace, app version, and device state at the moment of the crash, delivered through Sentry.
- Traffic totals — the number of bytes your account transfers (a counter, per account), used for fair-use quotas, capacity planning, and abuse prevention. A number only — never contents, never destinations.
- Payment metadata — from our payment partners we receive transaction status, amount, and the plan purchased. Card and bank details never touch our servers.
- Operational server logs — like every internet service, our API servers keep standard short-lived logs (which include IP addresses) for security and troubleshooting. They rotate away automatically within weeks.
- Support conversations — whatever you choose to send us by email.
Diagnostics, analytics, and crash reporting start only after you accept the privacy prompt shown on first launch. If we materially expand what we collect, that prompt will ask again.
What we never collect
- Websites you visit or apps you use through the tunnel
- DNS queries
- Traffic contents — no inspection, no DPI, in any form
- Logs that could link a session to a destination
- Device location — the apps never request location permission
- Contacts, photos, or messages — those permissions are never requested
Why we collect it
- Delivering the service: authentication, subscriptions, device limits
- Reliability: finding failing nodes, routes, and protocols before you report them
- Stability: diagnosing and fixing crashes and errors
- Product improvement: understanding which features are used and where users get stuck
- Fair use: quotas and abuse prevention
- Security and compliance with applicable law
Data retention
| Data | Kept for |
|---|---|
| Account data | Life of the account |
| Diagnostics, analytics & crash reports | Up to 24 months |
| Traffic totals | Up to 24 months |
| Operational server logs | Weeks (auto-rotated) |
| After account deletion | Purged; backups age out ≤ 90 days |
Third parties
We use the following providers to operate. None of them can see your tunnel contents:
- Sentry — crash-report aggregation. Receives stack traces and the device/app attributes above.
- Cloudflare — network edge in front of our API and some connection modes. Sees encrypted bytes in transit, like any carrier.
- Payment processors — hold your card or payment details; we never receive them.
- Cloud hosting providers — run the servers the service operates on.
We do not sell personal data, and we do not share it with advertisers.
We do not sell, use, or disclose to third parties any data collected through this app or service for any purpose unrelated to providing the service itself. The providers listed above act solely as our data processors under contract: they process data only on our instructions, only to the extent needed to operate the service, and are not permitted to use it for their own purposes.
No tracking, no selling, no disclosure. We do not track you across other apps or websites, and we do not integrate any advertising or ad-attribution SDK. The hashed device identifier used for the device limit serves only this app's own device management and abuse prevention — it is never used for cross-app advertising attribution or identity-graph building, and it is never shared with data brokers.
A note on “the node you selected.” The connection diagnostics above record which NorthStatus server you connected through (the tunnel entrance). They do not record the destinations you visit inside the tunnel. We do not log, and cannot reconstruct, a link between a session and the sites or services you reached through it.
Your rights
- Request an export of the data we hold about you
- Request correction or deletion of your account and its data — we act within 30 days
- Withdraw consent for diagnostics at any time by uninstalling the app, or write to us and we will purge your diagnostic records
Children
NorthStatus is not directed at children under 16, and we do not knowingly collect their data.
Changes to this policy
If we materially change this policy, the app will show the privacy prompt again before new collection starts, and active subscribers will be notified by email.
Contact
Questions, export or deletion requests: [email protected]