Kovalink privacy notice

Kovalink is a one-button VPN: you press Connect, your traffic egresses to the public internet, and the app keeps its surface small on purpose. This notice describes what data exists in the app, what the service stores, and what you control. It matches the consent text shown in the app before first use. The permanent home of this notice is https://kovalink.app/privacy, published alongside the app.

What we collect

On your device (Keychain, this device only, not synced):

Sent from your device:

Payments. Purchases happen through Apple's StoreKit. Kovalink never receives your card, bank, or Apple ID credentials; Apple handles payment and shows you the localized price. The service keeps only the Apple transaction identifiers needed to enforce your subscription. Access keys bought outside the App Store are billed by the checkout provider that sells them; that provider's own privacy terms cover the purchase, and Kovalink receives no payment details from it either.

Where your data goes

  1. api.kovalink.app — the pairing service that redeems invitations and provisions access. The app talks to this one fixed HTTPS origin; it never connects to a user-typed or link-supplied API host, follows no redirects, and uses an ephemeral network session with no cookies, caches, or stored credentials.
  2. Apple — your purchase, subscription state, and price. Governed by Apple's own privacy disclosures.
  3. The checkout provider that issued your access key — the key itself, when the service verifies it (only if you use an access key). Governed by that provider's privacy terms.
  4. The Kovalink egress server — your internet traffic while connected. A VPN server necessarily receives and forwards your traffic, so it sees the destination addresses of that traffic. This is disclosed below, in "What the service stores."
  5. Nowhere else. The client embeds no analytics SDKs, ad networks, or third-party code beyond the Xray-core networking engine.

DNS requests from your device are carried through the tunnel to the profile's configured resolvers (Cloudflare's public resolvers by default), not leaked to the local network.

What the service stores and for how long

We do not make stronger claims than this. Encrypted page contents, passwords, and messages are not read, and a complete browsing history is neither recorded nor claimed; but destination metadata for forwarded traffic is necessarily visible to the service while it forwards it (kept only under the access-history rule above, when recording is on), and domain names that stay encrypted in transit (encrypted DNS or ECH) may not be observable as names at all.

What Kovalink does not collect

Your controls

Contact

Questions or requests: https://kovalink.app/support