Last updated: 18 August 2026
Operator: independent developer (natural person), NimbusWay project
Product: NimbusWay — a software service that protects the connection and encrypts traffic on the user’s devices
Site: https://nimbusway.app
Cabinet: https://nimbusway.app/lk/
Privacy contact: support@nimbusway.app
Russian edition: /ru/privacy/.
1. Introduction
This Policy describes the data NimbusWay processes for registration, sign-in,
payment, and the client apps on Android, Android TV, iOS, iPadOS, macOS,
Windows, and Linux.
The service is a **software service that protects the connection and encrypts
traffic** on the user’s devices (public Wi‑Fi, privacy). Access to the apps
and infrastructure is prepaid; no physical goods are shipped. The device
performs a key exchange, then user traffic is encrypted in the session. We follow a **no-log
policy for traffic contents and destinations**: we do not keep journals of
visited sites, user DNS queries, destination addresses, or encrypted-traffic
payloads. We do store limited account and technical data required for billing
and account security, listed below.
2. Data we process
2.1. Account (required for the service)
| Data | Why |
|---|---|
| Email address | Registration, sign-in, recovery, contact |
| Password hash (bcrypt) | Authentication; the password is not stored in plaintext |
| Username / display name / avatar (if set) | Profile |
| Phone (if previously linked) | Legacy identifier; new phone registration is not offered |
| OAuth / Telegram data (provider id, name, username, provider email if any) | Sign-in and account linking |
| Email confirmation codes (temporary) | Registration verification |
2.2. Device identifiers (billing and session management)
| Data | Why |
|---|---|
Stable client device_id | Device accounting, per-device billing, limits |
Device fingerprint | Stable binding across reinstalls |
| Device name, platform / OS | Device list, support |
| Client public key | Key exchange and session parameters; the private key stays on the device and is not sent to the server |
Internal session address, selected node, last_active_at | Protected session and device-activity billing |
Device identifiers are not used for advertising and are not sent to ad
networks. The client has no third-party analytics / Firebase / Crashlytics /
ads SDKs.
2.3. Auth sessions and security
On sign-in and session refresh we may store:
- session-token hash;
- client platform;
device_id(if provided);- API client IP (the device calling the auth API) and User-Agent.
This is for account security (sessions, token revocation), not a journal of
visited sites or encrypted-traffic contents.
2.4. Billing and payments
| Data | Why |
|---|---|
Balance and operation ledger (billing_ledger) | Charges, top-ups, adjustments |
Charge binding to device_id / device_uuid | Per-device daily billing |
| Payment-operation ids at the payment service | Idempotency and payment support |
Card data is handled by the payment service used for that payment. Which
service is used may change. We do not store card numbers (PAN).
2.5. Minimal product telemetry
We may receive anonymized service data about selective-routing mode (mode,
platform, aggregate counters — no app list and no visited URLs). Domain-suffix
hints for DNS are not tied to page contents.
On-device diagnostic logs (if the user enables diagnostics) stay local until
the user sends them to support.
3. No-log policy (what we deliberately do not collect)
We do not collect or store:
- browsing or app history through the protected session;
- user-traffic DNS queries / QNAMEs as an activity journal;
- destination IPs or encrypted packet payloads;
- contents of messages, files, and media passing through the session.
“No-log” means no traffic and content journals. It does not mean there
is no account, billing, or device identifiers — the service cannot run without
those.
4. Encryption and key exchange
Protection is cryptographic, not a promise of invisibility:
1. the device generates a key pair; the private key never leaves the device;
2. the public key is registered for key exchange with the operator’s infrastructure;
3. after session keys are agreed, traffic is encrypted with ChaCha20-Poly1305 /
AES-256-GCM class algorithms, depending on protocol and transport;
4. transports additionally wrap the session in TLS / QUIC.
We do not guarantee protection against every technical or legal identification
mechanism outside our control.
5. Legal bases and purposes
Data is processed to:
1. provide connection protection, encrypt traffic, and manage devices;
2. register, authenticate, and protect the account;
3. bill and perform the services contract;
4. support users and comply with applicable law;
5. improve product reliability (minimal service telemetry).
Processing is limited to what those purposes require, under applicable
personal-data law, including mandatory rules of the customer’s country.
6. Retention and deletion
- Account and billing data are kept while the account is active and as long as
accounting / legal duties require.
- Step-by-step instructions: Delete account.
- You can delete the account in the app (Profile → Delete account), in the
cabinet /lk/, or by email to support@nimbusway.app. Zero balance: deletion
is immediate. Positive balance: access is blocked immediately; full deletion
after the balance reaches zero or after 30 days.
- After deletion, account personal data and linked devices are erased or
anonymized within a reasonable time, except data applicable law requires us
to keep (for example fragments of payment history).
7. Sharing with third parties
We do not sell personal data. Sharing is limited to:
- the payment service used for that payment;
- hosting / infrastructure processors acting on our instructions;
- public authorities — only on a lawful demand.
There is no third-party advertising or tracking analytics in the apps.
8. Security
We use transport and session encryption (see section 4), hashed passwords,
access control on servers, and data minimisation. No online service can
guarantee absolute security.
9. Children
The service is not intended for people below the digital-consent age in your
jurisdiction. We do not knowingly collect children’s data.
10. Changes
The current version is always published at the Privacy Policy URL. Material
changes update the date at the top of this document.
11. Contact
Privacy questions: support@nimbusway.app
Telegram support: https://t.me/nimbusway_support