Privacy Policy and Terms for ToBeVPN
Effective date: July 13, 2026
ToBeVPN (“we”, “the app”) is a VPN service for Android devices. Phone/tablet and Android TV variants are distributed under the com.tobevpn.app application identifier. This policy applies to both variants and describes what data we collect, why, and with whom we share it.
| Data | Purpose | Stored at |
|---|---|---|
Android device ID (Settings.Secure.ANDROID_ID) |
Linking the subscription to a specific device | Bot backend |
Device name (Build.MANUFACTURER + Build.MODEL) |
Display in your devices list | Bot backend |
| Telegram ID | Authentication and subscription management | Bot backend and VPN panel |
| Email (optional, if you provide it) | Account recovery, notifications | Locally in an encrypted database (SQLCipher), bot backend, and VPN panel |
| Hardware ID (HWID) | Device tracking in the VPN panel | VPN panel |
| OS version, device model, app version | HTTP headers when requesting subscription | VPN panel |
| Inbound and outbound traffic in bytes | Plan quota calculation | Bot backend and VPN panel |
| Connection IP address | Briefly — for VPN technical operation | VPN panel and VPN nodes |
| QR code image (phone scans TV’s QR, or TV renders a QR for the phone to scan) | Linking a TV device to your Telegram account | On the device only, not sent to our servers |
| Permission | Purpose |
|---|---|
INTERNET, ACCESS_NETWORK_STATE |
Establishing the VPN tunnel and tracking network state |
BIND_VPN_SERVICE |
Using the system VpnService API to build the VPN tunnel |
FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE |
Keeping the VPN connection alive while the app is in the background |
POST_NOTIFICATIONS |
Showing the VPN status indicator. Notifications are not used for marketing, advertising, or analytics. |
The mobile version additionally uses the built-in Google Code Scanner module to link a TV device by scanning a QR code. The scanner runs locally; the app does not request CAMERA permission, and images are not stored or sent to our servers.
The Android TV version instead renders a QR code locally using the open-source ZXing library. The QR encodes a https://t.me/<bot>?start=<auth_token> URL that the user scans with their phone to complete Telegram sign-in. The TV app does not request CAMERA permission either; the image is generated and displayed entirely on the TV.
The deep link tobevpn://auth_callback (mobile only) is used only to return to the app after a successful Telegram authentication.
In accordance with Google Play policies for apps that use the VpnService API, we declare:
VpnService is used solely to build a VPN tunnel from your device to our VPN nodes.VpnService as a library inside other apps.Data is shared only with the following processors required for the service:
open.er-api.com) — public exchange-rate API used to show subscription prices in your local currency. Only your device’s IP address is sent; no personal data.repo1.maven.org) — public repository used as the endpoint for the internet speed test. Only your device’s IP address is sent; no personal data.We do not sell your data to advertisers and do not share it for marketing purposes.
Some processors and VPN nodes may be located outside the Republic of Kazakhstan. This may involve a cross-border transfer of the personal data necessary to provide the service, where the user has consented or another basis permitted by applicable law exists.
Retention periods by data type:
| Data | Retention |
|---|---|
| Telegram ID, email, device name, HWID, device→account link | Until you delete the account or unlink the device |
| Subscription traffic counters | For the subscription period + up to 12 months in anonymized form for statistics |
| Server technical logs (IP, timestamps) | Up to 90 days |
| Financial and tax records of payments | For the period required by the laws of the Republic of Kazakhstan |
The app’s local database is encrypted (SQLCipher) and stays only on your device.
How to delete your account: see the dedicated Account deletion page. Request-processing periods are set out in section 8 below.
Uninstalling the app clears local data but does not break the device→Telegram link on the server — use the deletion instructions for that.
The service is not directed at:
We do not knowingly collect data from minors. If you become aware that a child has provided personal data to us, please contact us and we will delete it.
You have the right to:
To exercise these rights, email the address below. Information about stored personal data, or a reasoned response, will be provided within 3 working days after receipt of the request. If consent is withdrawn, processing will stop within 15 working days, unless storage or processing is required by the laws of the Republic of Kazakhstan or an obligation remains unfulfilled; otherwise, a reasoned refusal will be provided.
Users may challenge actions or omissions relating to personal data processing before the competent authority of the Republic of Kazakhstan or a court. Where GDPR applies to a request, its requirements and time limits also apply.
We do not use automated decision-making producing legal or similarly significant effects on the user, including profiling (Art. 22 GDPR).
If you are located in the European Union or EEA, GDPR applies to you.
If you are a California resident, CCPA/CPRA applies to you.
For material changes we will update the effective date and try to notify you in the app. The current version is always available at this URL.
Email: iv.zai4k@gmail.com