Kovalink privacy notice
Kovalink is a one-button VPN: you press Connect, your traffic egresses to the public internet, and the app keeps its surface small on purpose. This notice describes what data exists in the app, what the service stores, and what you control. It matches the consent text shown in the app before first use. The permanent home of this notice is https://kovalink.app/privacy, published alongside the app.
What we collect
On your device (Keychain, this device only, not synced):
- A random installation identifier (a UUID generated on first launch). It is not derived from your name, Apple ID, or hardware serial number, is not an authentication secret, and is never printed or logged.
- Your validated connection profile after access is granted.
- While an invitation redemption is in flight: the one-time code and its retry markers, deleted once the redemption settles.
Sent from your device:
- To redeem an invitation: the invitation code, a fresh redemption identifier, your installation identifier, and the consent version. The code is sent once (at most twice on retry of the same redemption), over HTTPS, and the server stores only a hash of it.
- To activate a subscription: a signed App Store transaction proof, your installation identifier, and the consent version. The proof is submitted once and is never stored by the app or retained by the service beyond the entitlement fields derived from it.
- To activate an access key: the key, your installation identifier, and the consent version. The service verifies the key with the checkout provider that issued it and keeps the key and its membership identifier to enforce your access; the administrator's console shows the key masked.
- A connectivity probe to Apple's public reachability page after connecting. The request carries no identifier and is not a location or throughput test.
Payments. Purchases happen through Apple's StoreKit. Kovalink never receives your card, bank, or Apple ID credentials; Apple handles payment and shows you the localized price. The service keeps only the Apple transaction identifiers needed to enforce your subscription. Access keys bought outside the App Store are billed by the checkout provider that sells them; that provider's own privacy terms cover the purchase, and Kovalink receives no payment details from it either.
Where your data goes
- api.kovalink.app — the pairing service that redeems invitations and provisions access. The app talks to this one fixed HTTPS origin; it never connects to a user-typed or link-supplied API host, follows no redirects, and uses an ephemeral network session with no cookies, caches, or stored credentials.
- Apple — your purchase, subscription state, and price. Governed by Apple's own privacy disclosures.
- The checkout provider that issued your access key — the key itself, when the service verifies it (only if you use an access key). Governed by that provider's privacy terms.
- The Kovalink egress server — your internet traffic while connected. A VPN server necessarily receives and forwards your traffic, so it sees the destination addresses of that traffic. This is disclosed below, in "What the service stores."
- Nowhere else. The client embeds no analytics SDKs, ad networks, or third-party code beyond the Xray-core networking engine.
DNS requests from your device are carried through the tunnel to the profile's configured resolvers (Cloudflare's public resolvers by default), not leaked to the local network.
What the service stores and for how long
- Access grants (what lets a device connect): the grant type, status, creation and expiry times, the hashed invitation, the Apple transaction identifiers, or the access key and its membership identifier, the installation identifier, and your consent version and timestamp. Grants are kept while access is active; revoked or expired grants are disabled and removed by the operator.
- Invitation records: the SHA-256 hash of the one-time code, never the code itself.
- Access history: for each access grant, aggregated by UTC day, the service keeps connection timestamps, connection counts, upload and download byte totals, the observable destination domains or IP addresses and ports — and nothing beyond these fields. Encrypted page contents, passwords, and messages are never read, and no TLS interception is performed. Entries are kept for seven days (today plus the previous six); the service itself deletes expired days automatically, and revoking a grant deletes that grant's history immediately. The history is visible only to the private administrator, through an administration page served only on the server machine's loopback address; it is not exposed publicly and is never shared with any third party. It is destination metadata, not page contents — domain names that stay encrypted in transit (encrypted DNS or ECH) may never appear as names at all — so it is not a complete browsing history. Recording is off by default and is switched on explicitly by the administrator; while it is off, none of these fields are kept, and whether it is on or off changes nothing about how the app works. The in-app notice accepted before first use (consent version `kovalink-access-v1`) has covered this access history since that version was introduced.
- Service request logs on the pairing service: method, path label, and status code per request. No client identifiers, invitation codes, or query content.
We do not make stronger claims than this. Encrypted page contents, passwords, and messages are not read, and a complete browsing history is neither recorded nor claimed; but destination metadata for forwarded traffic is necessarily visible to the service while it forwards it (kept only under the access-history rule above, when recording is on), and domain names that stay encrypted in transit (encrypted DNS or ECH) may not be observable as names at all.
What Kovalink does not collect
- Page contents, passwords, messages, or anything inside your TLS sessions.
- Contacts, photos, location, advertising identifiers, or device telemetry.
- Payment card or Apple ID credentials.
- Third-party analytics of any kind; there are no such SDKs in the app.
Your controls
- Connect or disconnect at any time with the single button. On-demand connecting is an optional setting and stays off unless you enable it.
- Stop entirely by disconnecting and removing the app (or the VPN configuration) from your device.
- Cancel the subscription any time through your Apple subscription settings; access then ends at the current period's expiry. If you use an access key, cancel the membership behind it with its seller; access ends when that membership does.
- Request deletion or revocation of your grant and access history via https://kovalink.app/support — the administrator can disable a grant immediately.
- Treat invitation links as credentials. Each is one-time use; anyone who redeems it first consumes it.
Contact
Questions or requests: https://kovalink.app/support