Data handled by the app
The app connects to Vonode nodes selected and operated by the user. Node credentials and relay credentials are stored in the iOS Keychain. Device, message, call, eSIM, automation and diagnostic information is retrieved from the user’s node and displayed on the device.
Contacts
Contacts access is optional. When authorized, the app and notification service extension use the iPhone or iPad address book locally to replace a matching phone number with a saved contact name. Contacts are not uploaded to Vonode, the user’s nodes or the developer-operated relay.
Crash reports and usage analytics
To find and fix problems and to understand which features are used, the app includes software development kits (SDKs) from Sentry (crash reports and app performance) and PostHog (usage analytics). Both are optional: the app does not start them until you agree in the app, and you can turn either off at any time in Settings, after which the app stops sending new data.
Crash reports may include the app version and build, device model, operating system version and language, the state of the app and device when the problem occurred (such as the stack trace, the screen in use, memory, storage and battery state, network type, time zone and how long the app had been running), timestamps and a random identifier. Usage analytics may include app launches, the screens viewed and features used, session duration, the app version, device model, operating system version, language, region and time zone settings, whether the device is on Wi-Fi or cellular, and a random identifier. The providers also receive the IP address of the connection; we configure both services not to store it or use it to determine your location.
Each service uses its own random identifier, created by the app only for crash reports or analytics. It is separate from the relay installation identifier and the subscription account token and is not combined with them or with data from other companies; a new one is created when you reinstall the app. The app does not use the advertising identifier (IDFA) and does not use this data for advertising, to track you across apps or websites owned by other companies, or to identify you.
Crash reports and analytics never include message content, phone numbers, call history, contacts, eSIM details, node addresses, credentials or subscription transactions.
The providers process this data on behalf of VONODE LLC and may store it in countries other than yours, including the United States. Where the law requires it, for example for users in the United Kingdom, the European Economic Area or mainland China, these transfers rely on your consent in the app and on appropriate safeguards such as standard contractual clauses. The providers used by the current version of the app are:
- Sentry (Functional Software, Inc.): crash reports and app performance; data stored in the United States. Sentry Privacy Policy.
- PostHog (PostHog Inc.): usage analytics; data stored in the United States. PostHog Privacy Policy.
Developer-operated relay
VONODE LLC operates a relay at push.vonode.cc. The app and nodes use it for:
- delivering notifications and incoming-call alerts through the Apple Push Notification service (APNs);
- confirming subscriptions: it checks App Store signed transactions, receives App Store Server Notifications from Apple about renewals, refunds and revocations, and issues short-lived signed subscription leases to the app and to nodes;
- checking with Apple App Attest that requests come from a genuine copy of the app;
- checking the integrity of the node software, through integrity reports and short-lived verification modules that the node runs;
- delivering encrypted carrier configuration bundles to nodes with a subscription.
For notifications, the relay stores an app installation identifier, encrypted Apple Push Notification service tokens, node-to-installation authorization grants, delivery status, the time an installation last contacted the relay and other timestamps required to operate the service. The last-contact time is used to count how many phones currently use a node. A notification waiting to be sent is kept only until it is delivered or fails; the record of each delivery is deleted one day later, or seven days later if delivery failed. To apply a daily notification limit, the relay counts deliveries per day under a keyed hash of the installation identifier and keeps these counts for the current and the previous eight UTC days. These identifiers are used only for app functionality, are not used for advertising or tracking, and are not sold.
The relay does not store plaintext message content. If the user enables notification details, the node encrypts the sender and preview for the intended installation; the notification service extension decrypts them locally for display. An incoming-call alert contains the caller’s number, which the relay passes to Apple for delivery to your device and does not store in readable form. Invalid tokens are disabled after Apple reports them as invalid. Removing a node revokes its relay grant. If the app's stored relay credentials are lost or removed, the app creates a new installation identity; operating-system keychain behavior can otherwise preserve credentials across an app reinstall.
For App Attest, the relay stores the public key of the app’s App Attest key, its key identifier and a usage counter, with the times it was registered and last used; it does not store Apple’s attestation or receipt. For node integrity, it stores the latest findings a node reports, which are names from a fixed list of checks (for example, that the node software’s signature does not match), and deletes them when the node reports no findings; for verification modules, the random challenge it last issued to each node, when it was issued and the result of the last check. The values a node uses to answer a verification module are checked and not stored. For carrier configuration bundles, it stores for each node a random session identifier, a random watermark identifier that makes each node’s copy traceable, the revision delivered and the related times; the bundles contain carrier settings, not personal data. To limit abuse, the relay keeps the IP address of some requests, such as requests for an App Attest challenge, as a rate-limit counter for up to about an hour.
Review environment
The App Review environment contains synthetic records only. State is isolated per review session and automatically removed after its retention window. Simulated SMS, USSD, eSIM, automation and device actions do not contact a carrier, SIM, modem, real person or user node. Camera access is optional and is used only to scan pairing, eSIM and App Review QR codes.
Service providers
Cloudflare processes requests and stores encrypted relay state, subscription records and synthetic review state on behalf of VONODE LLC. Persistent logs and traces are disabled for both developer-operated Workers. Apple processes push notification delivery and subscription purchases. GitHub hosts node software downloads. Sentry and PostHog are described under Crash reports and usage analytics. Each provider processes data under its own terms and security controls.
Subscriptions
Subscriptions are purchased and billed by Apple. When you buy, the app gives the App Store an account token: the token of your earlier Vonode purchase, or otherwise a random value created on your device. It only links purchases made with the same Apple account and does not identify you or your node. A subscription is used on one node at a time, the one you choose in the app.
The app sends the App Store's signed transaction to that node over the pinned SSH connection and to the developer-operated relay; the node verifies it with Apple's certificates and also passes it to the relay. The relay verifies it the same way and keeps only a keyed hash of its original transaction identifier and of each transaction identifier, the product, the App Store environment, when Apple signed it, the expiry and any refund or revocation time, which nodes it is or was used on, and when it moved between them. Apple also sends the relay App Store Server Notifications about renewals, refunds and revocations; the relay verifies Apple’s signature and uses them only to update subscription records it already holds. It does not keep the signed transaction, the account token or any payment details; Vonode never receives your payment card information. The relay returns a signed statement of the subscription status, which the app and node use to decide which features are available. Apple provides VONODE LLC with sales and subscription reports under its own terms.
Node software
The node software runs on hardware you control and keeps its database, messages, call history and backups there. Support bundles are created on the node with identifiers redacted and leave it only when you choose to share one, for example by email to support. Notification channels you configure on the node, such as Telegram, email or webhooks, are sent directly from your node to those services under their own terms.
A node with a subscription contacts the developer-operated relay when you add a subscription, when it starts, about every 10 minutes and when the relay declines a notification, to confirm its status and renew its lease; if it cannot get a valid lease for 30 minutes, it continues with the function available without a subscription until it can. It sends its node identifier and, when needed, the signed transaction, the names of any integrity findings, the watermark identifier of the carrier bundle it holds, and its answer to the current verification module together with the values it used: a digest of the node software, a digest of the signed transaction it holds, a value derived from the subscription’s original transaction identifier, the subscription expiry, its integrity findings, flags describing its environment (whether it is a commercial or review build, whether a debugger is attached, whether library preloading is set, whether it runs on Linux and whether it considers itself unlocked) and the node’s clock. The node downloads verification modules and carrier configuration bundles from the relay. When software updates are enabled, the node downloads the release list and signed updates from Vonode's release page on GitHub.
Website
This website does not use advertising, analytics, tracking pixels or cross-site profiling. Standard hosting security logs may be processed by Cloudflare.
Retention and choices
The relay runs its cleanup every hour; in each run it deletes at most 500 installations, App Attest keys and node records of each kind, and anything left over is deleted in the following hours. It deletes:
- an app installation, together with its grants, push tokens (including disabled ones), delivery records and its App Attest key, when for 90 days the app has not contacted the relay, no node has used any of its grants and the app has not changed them;
- an App Attest key whose installation no longer exists, 90 days after it was last used, or after it was registered if it was never used;
- a node’s integrity findings and verification challenge and result, when for 90 days none of the node’s grants has been used or changed and the node has not renewed its lease;
- carrier bundle sessions, after a node has not renewed its lease for 90 days;
- subscription records, transaction snapshots and node bindings, 90 days after the subscription ends, that is after its expiry plus a 72-hour grace period; a refunded or revoked subscription is kept, marked as revoked, until 90 days have passed both since the end of the period it was paid for (plus the grace period) and since the refund or revocation, so that an older copy of the purchase record cannot restore it;
- records of moves between nodes, after 90 days;
- delivery records, one day after delivery or seven days after delivery failed;
- daily notification counts, once they are older than the current and the previous eight UTC days;
- App Attest challenges, which expire after 10 minutes and are deleted within the next hour, and rate-limit counters, including the IP addresses recorded for some requests, after about an hour.
The first three kinds of cleanup are paused while the relay’s subscription checks are switched off. Removing a node deletes its grant immediately, and you can ask support at support@vonode.cc to delete other relay data at any time. Crash reports are kept for up to 90 days and analytics event data for up to 13 months; after that only aggregate statistics that do not relate to a device are kept. Users can turn off crash reports or analytics in Settings, disable notifications in iOS, revoke a node inside Vonode, or contact support to request deletion of developer-operated relay data.
Controller and legal bases
The controller of the personal data described in this policy is VONODE LLC, a Michigan limited liability company, United States, which you can contact at support@vonode.cc. Data stored on your own node stays under your control; we do not have access to it. We process personal data on these legal bases:
- to provide the app, the relay, subscriptions and the features of the node software you use: performance of our contract with you;
- to keep the services secure, prevent abuse and fraud, confirm subscriptions, check the integrity of the node software and fix problems: our legitimate interests, which we balance against your rights;
- to collect crash reports and usage analytics: your consent, which you can withdraw at any time in Settings.
You do not have to provide personal data, but without the relay data, notifications and subscription features do not work. VONODE LLC is based in the United States. Relay data is processed by Cloudflare and Apple, and app data by the providers named above, in the United States and in other countries where those providers operate; where the law requires safeguards for these transfers, we rely on those offered by the providers, such as standard contractual clauses.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw your consent at any time without affecting processing before the withdrawal. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work. To exercise these rights, contact support@vonode.cc.
Security and children
Connections to the developer-operated relay are encrypted. Manual Login requires a system-trusted HTTPS connection, and paired nodes use a pinned SSH connection. Relay secrets are not stored in readable form. Vonode is not directed to children and does not knowingly collect children’s personal information.
Contact
Privacy and deletion requests: support@vonode.cc.