Privacy

Privacy Policy

What NimbusWay processes: account, devices, payments. Connection-protection software; no-log for traffic contents.

Last updated: 18 August 2026

Operator: independent developer (natural person), NimbusWay project

Product: NimbusWay — a software service that protects the connection and encrypts traffic on the user’s devices

Site: https://nimbusway.app

Cabinet: https://nimbusway.app/lk/

Privacy contact: support@nimbusway.app

Russian edition: /ru/privacy/.


1. Introduction

This Policy describes the data NimbusWay processes for registration, sign-in,

payment, and the client apps on Android, Android TV, iOS, iPadOS, macOS,

Windows, and Linux.

The service is a **software service that protects the connection and encrypts

traffic** on the user’s devices (public Wi‑Fi, privacy). Access to the apps

and infrastructure is prepaid; no physical goods are shipped. The device

performs a key exchange, then user traffic is encrypted in the session. We follow a **no-log

policy for traffic contents and destinations**: we do not keep journals of

visited sites, user DNS queries, destination addresses, or encrypted-traffic

payloads. We do store limited account and technical data required for billing

and account security, listed below.


2. Data we process

2.1. Account (required for the service)

DataWhy
Email addressRegistration, sign-in, recovery, contact
Password hash (bcrypt)Authentication; the password is not stored in plaintext
Username / display name / avatar (if set)Profile
Phone (if previously linked)Legacy identifier; new phone registration is not offered
OAuth / Telegram data (provider id, name, username, provider email if any)Sign-in and account linking
Email confirmation codes (temporary)Registration verification

2.2. Device identifiers (billing and session management)

DataWhy
Stable client device_idDevice accounting, per-device billing, limits
Device fingerprintStable binding across reinstalls
Device name, platform / OSDevice list, support
Client public keyKey exchange and session parameters; the private key stays on the device and is not sent to the server
Internal session address, selected node, last_active_atProtected session and device-activity billing

Device identifiers are not used for advertising and are not sent to ad

networks. The client has no third-party analytics / Firebase / Crashlytics /

ads SDKs.

2.3. Auth sessions and security

On sign-in and session refresh we may store:

This is for account security (sessions, token revocation), not a journal of

visited sites or encrypted-traffic contents.

2.4. Billing and payments

DataWhy
Balance and operation ledger (billing_ledger)Charges, top-ups, adjustments
Charge binding to device_id / device_uuidPer-device daily billing
Payment-operation ids at the payment serviceIdempotency and payment support

Card data is handled by the payment service used for that payment. Which

service is used may change. We do not store card numbers (PAN).

2.5. Minimal product telemetry

We may receive anonymized service data about selective-routing mode (mode,

platform, aggregate counters — no app list and no visited URLs). Domain-suffix

hints for DNS are not tied to page contents.

On-device diagnostic logs (if the user enables diagnostics) stay local until

the user sends them to support.


3. No-log policy (what we deliberately do not collect)

We do not collect or store:

“No-log” means no traffic and content journals. It does not mean there

is no account, billing, or device identifiers — the service cannot run without

those.


4. Encryption and key exchange

Protection is cryptographic, not a promise of invisibility:

1. the device generates a key pair; the private key never leaves the device;

2. the public key is registered for key exchange with the operator’s infrastructure;

3. after session keys are agreed, traffic is encrypted with ChaCha20-Poly1305 /

AES-256-GCM class algorithms, depending on protocol and transport;

4. transports additionally wrap the session in TLS / QUIC.

We do not guarantee protection against every technical or legal identification

mechanism outside our control.


5. Legal bases and purposes

Data is processed to:

1. provide connection protection, encrypt traffic, and manage devices;

2. register, authenticate, and protect the account;

3. bill and perform the services contract;

4. support users and comply with applicable law;

5. improve product reliability (minimal service telemetry).

Processing is limited to what those purposes require, under applicable

personal-data law, including mandatory rules of the customer’s country.


6. Retention and deletion

accounting / legal duties require.

cabinet /lk/, or by email to support@nimbusway.app. Zero balance: deletion

is immediate. Positive balance: access is blocked immediately; full deletion

after the balance reaches zero or after 30 days.

anonymized within a reasonable time, except data applicable law requires us

to keep (for example fragments of payment history).


7. Sharing with third parties

We do not sell personal data. Sharing is limited to:

There is no third-party advertising or tracking analytics in the apps.


8. Security

We use transport and session encryption (see section 4), hashed passwords,

access control on servers, and data minimisation. No online service can

guarantee absolute security.


9. Children

The service is not intended for people below the digital-consent age in your

jurisdiction. We do not knowingly collect children’s data.


10. Changes

The current version is always published at the Privacy Policy URL. Material

changes update the date at the top of this document.


11. Contact

Privacy questions: support@nimbusway.app

Telegram support: https://t.me/nimbusway_support