VPMKS LLC · Updated September 28, 2026
Privacy Policy
How VPMKS handles subscriptions, device identity and diagnostics.
Who is responsible
VPMKS LLC develops the VPMKS app and maintains vpmks.online and docs.vpmks.online. For privacy questions or deletion requests, contact support@vpmks.com. This policy covers the app and these websites.
VPMKS is a client for your subscriptions and configurations. Installing it does not by itself provide a VPN server, subscription or provider account. The operator of the subscription you choose is separately responsible for its service and processing on its servers.
Information kept on your device
Subscription links, server configurations and credentials supplied by your provider, your selected server, settings, names, announcements, expiry dates and usage metadata are stored in protected device storage. The configuration is also available to the local tunnel component in protected app storage while providing VPN functionality.
VPMKS does not require a cloud account or automatically sync subscriptions to the developer’s server. Do not publish a subscription link: it may grant access to your service.
Information your subscription provider receives
When importing or refreshing a subscription, the app requests the link you supplied. The server receives the connection IP address, request, VPMKS device identifier (HWID), device model, operating system and version, and the app version in the VPMKS User-Agent. Your provider may use HTTPS redirects; their recipients receive the same information. The app may also request a /json route to obtain a compatible full JSON configuration.
HWID helps providers manage permitted devices. It is derived from a system identifier with a VPMKS-specific transformation, or generated randomly if that identifier is unavailable. The original system identifier is not sent to the provider. The app does not use an IMEI, serial number or MAC address for this purpose. On iOS, HWID is stored separately in Keychain and does not change during an ordinary app update or when an individual subscription is deleted.
Subscription refresh on opening is enabled by default. You can change automatic updates and startup actions in Settings. Your provider may retain device registration and request records under its own policy; removing a subscription from the app does not delete those records.
VPN, DNS and connectivity checks
When VPN is enabled, the app processes traffic on your device and routes it according to the selected configuration. The VPN operator and configured DNS services receive information needed to establish and handle connections. Routing rules may send some traffic directly. What an operator can see depends on the protocol and end-to-end encryption of each app or website. A VPN does not provide complete anonymity.
TCP/ICMP checks contact the selected server. Proxy checks and active-connection checks contact your configured diagnostic address, which defaults to https://www.gstatic.com/generate_204, operated by Google. You can change this address in Settings. The recipient sees the connection IP address and technical request information. Subscription HWID headers are not added to diagnostic requests.
VPMKS does not sell VPN activity data, use it for advertising or profiling, or disclose it to advertising networks or data brokers. The app does not send your browsing history or VPN traffic contents to the developer. Necessary communication with servers and services selected by you is described above.
Camera, clipboard and TV
The camera is used at your request to decode QR codes on your device. The app does not upload the camera stream to a VPMKS server. Clipboard text is read when you choose Paste. You can revoke camera permission in system settings.
Connect TV uses the camera and local network. The selected original subscription link and provider name are sent to the selected TV in an AES-GCM encrypted session. The secret is carried by a short-lived QR code and is not sent through a VPMKS relay server. Do not share the QR code with others. The TV then downloads the subscription using its own HWID. Success is confirmed after the TV saves it.
You can revoke local-network permission in system settings. If you separately enable local-network SOCKS/HTTP access, devices able to reach that interface can access the configured ports. Use this feature only on a trusted network.
Diagnostics and support
App logs are kept locally and have bounded sizes. Core logs contain timestamps, severity and event categories, with a level selected in Settings. On iOS, a small tunnel lifecycle and memory record is kept separately, including when core messages are disabled. App-exported records are filtered to contain technical events and numeric measurements rather than raw messages containing destination addresses, subscription links or keys.
Local logs are not automatically uploaded to the developer. You can view, copy, share or clear them in Settings. When you share them, the recipient is the app or contact you choose. Review additional text, files and screenshots yourself: they may contain personal information.
If you contact support, we process your address, message and attachments you choose to provide to respond and investigate. Do not send passwords, private keys or active subscription links. Correspondence and diagnostic materials are retained while needed to handle the request, a related fix or a legal obligation, and are then deleted or de-identified.
TestFlight and third-party services
If you install through TestFlight, Apple processes installation, usage, device and crash information and makes available reports and your feedback to the developer. We use this information for testing and fixes and do not share TestFlight data with third parties. Apple’s notice is available at https://www.apple.com/legal/privacy/data/en/test-flight/.
Provider links, Telegram, email and other external pages open at your request. Those services have their own privacy practices. The app does not include advertising or third-party analytics SDKs.
Websites and technical information
vpmks.online and docs.vpmks.online serve static pages. To deliver a page, the server processes your IP address and normal HTTP request information. Routine access logs are disabled for these websites. Separate error logs may contain an IP address and request path; they are used for availability and security. Daily rotation retains up to seven archived files, and archives older than seven days are removed when rotation runs. These records concern website operation, not your VPN traffic.
These websites have no advertising trackers, third-party analytics, remote fonts, data-collection forms or cookies. The documentation may remember your chosen theme only in your browser’s localStorage; you can remove it by clearing site data. Language is determined by the page URL. Following an external link or sending an email opens the chosen third-party service, which receives information needed for that action.
Your choices, retention and deletion
You can remove a local subscription from its menu, disable automatic refresh in subscription settings, and clear logs in the core log section. Turn VPN off to stop tunnel processing. You can revoke system permissions and remove the system VPN configuration.
Settings and subscriptions remain until changed or removed. Local logs rotate and can be cleared. HWID is stored separately and is not reset when you remove a subscription. Reinstalling is not a guaranteed way to remove Keychain records or provider-held data. Copies you have exported to other apps must be deleted separately.
For access, correction or deletion of information held by VPMKS LLC, contact support@vpmks.com. Contact your provider about data on its servers. We may request only the information needed to verify your request. Depending on applicable law, you may also have rights to restrict processing, portability, withdraw consent, object to processing and complain to a supervisory authority.
Processing supports requested features and support, optional actions you choose, website security and applicable obligations. Where applicable law requires consent, you may withdraw it without affecting the lawfulness of earlier processing. The app does not make automated decisions with legal effects. Network requests may be processed in the countries where your chosen provider, DNS, diagnostic service or Apple operates.
Policy changes
The date of this version appears at the top of the page. We will update this policy when features or processing change and obtain fresh consent separately where required. Material changes do not retroactively authorize incompatible purposes. The app is not specifically directed at children; the age requirements of your country and distribution service apply.