Skip to content

Privacy Policy

MearVPN for iPhone

· support@meertun.online

The short version. MearVPN has no servers, no accounts and no backend. It connects to the servers in configurations you bring yourself, fetches a subscription only from the address you enter, and sends nothing to the developer. The exceptions — two DNS resolvers the app sets, and the lookup of your server's name — are named in Section 4 rather than left for you to discover.

1. What MearVPN is

MearVPN is a client for servers you already have. It ships with no servers of its own and resells nobody else's: you bring a vless:// link, a subscription link from your provider, or a WireGuard configuration in the wg-quick format, and the app builds the tunnel on your iPhone.

Two engines are compiled into the app: Xray for VLESS (including REALITY and XTLS Vision) and WireGuard. The tunnel runs through the VPN system of iOS: before the first connection iOS asks you to allow a VPN configuration, and it shows the VPN indicator while the tunnel is up. There is no sign-up, no account and no purchase inside the app.

2. What we collect

Nothing. There is no account, no device registration with us, no analytics, no advertising and no tracking. MearVPN does not collect your name, email, phone number, payment details, location, contacts, photos, browsing history, DNS queries, session times or traffic volumes.

The app links no analytics, crash-reporting, advertising or payment SDK, requests no advertising identifier and does not use App Tracking Transparency, because there is nothing to track. The build published on the App Store contains no address of any server of ours. Its App Store privacy label is “Data Not Collected”.

This is a description of how the app is built, not a promise of restraint: we hold no record of your use of the app, so there is none to disclose, lose or hand over.

The one thing that may reach us is your message, if you write to support yourself: the sender address and the text. They are used only to reply, shared with no one, and deleted at your request.

3. What stays on your iPhone

Secrets — the full links you added (they contain your UUID), WireGuard private and pre-shared keys, and the configuration of the current session — are kept in the iOS Keychain with the “this device only” protection class. They are not included in iCloud or computer backups, are not synced through iCloud Keychain and do not move to a new iPhone.

The list of configurations — name, protocol, server host and port, date added — and your settings (appearance, language, kill switch) are kept in the app's own storage, shared only between the app and its tunnel extension. So is the tunnel's working data: received and sent byte counters, connection time, the last error and a short technical tunnel log. The log records events such as the start of the tunnel and the address of the server it connects to; it never records your link, UUID or keys. This storage is part of the ordinary iPhone backup, like the data of any app.

You can copy the tunnel log from Settings yourself; the app never sends it anywhere.

Deleting a configuration in the app removes its secrets from the Keychain. Deleting the app removes its storage; iOS may keep the Keychain items of a deleted app on the device, out of reach of other apps — delete your configurations in the app first if you want them gone at once.

4. What leaves your iPhone, and to whom

None of the connections below reaches us. MearVPN has no server of its own, so each one goes either to an address you chose or to a party named here.

Your traffic through the Xray tunnel (VLESS). It goes to the host and port in your link, when you connect — on the Shield screen or by choosing a configuration. While the tunnel is up it carries the traffic of the whole device except local networks (your router, printers and the like). The TLS handshake carries the server name and fingerprint from your link — by default the app imitates the ClientHello of Chrome — and certificate verification is always on. If your link uses REALITY, its parameters travel with the handshake, again from your link. The operator of your server can see what it forwards; that is inherent to any VPN, and their policy governs it, not ours.

DNS queries, to two resolvers the app sets. While an Xray tunnel is up, MearVPN gives iOS 1.1.1.1 (Cloudflare) and 8.8.8.8 (Google) as the DNS servers for all domains; there is no setting for it. The queries themselves travel through your server: its operator sees what is being resolved, and Cloudflare and Google see your server, not you, as the source — each under its own privacy policy.

The lookup of your server's name. If your link names a domain rather than an IP address, that name has to be resolved before the tunnel can carry anything — outside the tunnel, by the DNS of your network. Your network operator can therefore see the name of the server you connect to, though not what travels inside the tunnel. A link with an IP address avoids this lookup. We know this from the app's code; we have not confirmed it with a traffic capture of our own.

Your traffic through the WireGuard tunnel. It goes to the endpoint in your wg-quick configuration. WireGuard has no headers and no client name. DNS in this mode is whatever your configuration names; the two resolvers above do not apply. The private key stays on the device and is never transmitted.

A subscription you add. When you add an https subscription link, the app makes one GET request to exactly that address and turns the answer into configurations. Plain http is refused. The request carries no cookies, uses no cache and sets one header, Accept; iOS adds its standard User-Agent with the app's name and build and the versions of iOS networking components. The subscription server sees your IP address — or your VPN server's, if a tunnel is up — and is governed by its operator's policy.

Kill switch. If you turn it on, iOS lets no traffic leave the device outside the tunnel while the tunnel is down. The switch itself sends nothing anywhere.

Inside the tunnel extension, a local connection to 127.0.0.1:10808 links the tunnel to the Xray engine. It never leaves the device.

There is nothing else. In particular, none of the following happens: a connection to any server of ours; an external-IP check; a network speed test; a download of routing data — the datasets ship inside the app; any analytics, crash-reporting, advertising or payment endpoint; a web view.

5. Camera and images

MearVPN asks for the camera only when you choose to scan a QR code with a configuration or a subscription link. Frames are processed on the iPhone to read the code; nothing is recorded, saved or sent. You can refuse, or withdraw the permission in Settings, and still add configurations by pasting a link. You can also choose an image file with a QR code: the app reads only the file you picked, decodes it on the iPhone and keeps nothing of it.

6. Clipboard

The app reads the clipboard only when you tap Paste, and writes to it only when you copy the tunnel log.

7. Crash reports and diagnostics

MearVPN contains no crash-reporting SDK. If you have turned on Share With App Developers in iOS Settings → Privacy & Security → Analytics & Improvements, Apple may share crash reports and usage statistics of the app with the developer. That channel belongs to Apple, stays off unless you turn it on, and is covered by Apple's privacy policy; such reports contain no configurations or keys.

8. Third parties

Those who nevertheless see something, all already named above: the operator of the server in your configuration, who forwards your traffic; Cloudflare and Google, as resolvers; the subscription server, if you added one; your network operator, for the server-name lookup; and Apple — the App Store, the iOS VPN system, and diagnostics if you turned them on. Support mail is held by the mail provider Namecheap (Private Email) under its own policy.

We sell, share and disclose nothing, because we hold nothing. Should a future version ever need an outside service, it will be named in this section before that version ships.

9. Your rights

Under the GDPR you may access, correct, erase or port your personal data, restrict its processing and object to it. Because we hold none of it, every one of those rights is already in your hands: delete a configuration in the app, or delete the app. Nothing remains on our side, because nothing ever arrived there.

Keeping your configurations and settings on the device rests on performing the contract you enter into by installing the app (Article 6(1)(b) GDPR). A message to support is processed in order to answer it — our legitimate interest (Article 6(1)(f)). Consent is a basis we rely on for nothing; should a future feature ever need it, the app will ask first, in plain words.

For California residents: we do not collect, sell or share personal information under the CCPA and CPRA. If you have written to us and want that correspondence gone, say so and it will be deleted; we answer within 30 days. We make no automated decisions about you and do no profiling. If you are in the EEA or the UK and believe a request of yours was handled badly, you may complain to your national supervisory authority.

10. Children

MearVPN is not directed at children under 13 and collects data about no one — children included.

11. Retention, transfers and security

We retain nothing, receiving nothing — except support messages, kept as long as it takes to answer and deleted on request. What is on your device stays there until you remove it. Where the hosts in Section 4 sit, and what they keep, is their business and their policy.

The tunnel runs in a separate system process — an extension isolated by iOS from the app itself. Secrets live in the Keychain with the “this device only” protection class. No code is loaded at runtime: the build Apple delivers is the build that runs. Your device passcode, and your judgement about which server operator deserves trust, remain yours — no client app can make up for a server that logs you.

12. Cookies

None. MearVPN is not a web app, embeds no web view, and takes no part in cross-app or cross-site tracking. The meertun.online website sets no cookies either: your theme choice is kept in your browser's localStorage and goes nowhere.

13. Changes

Should this policy change, its version and date change with it. Any new kind of data processing — a new outbound connection included — will be named here and in the release notes of the app version that brings it. Collection will not be widened quietly.

14. Applicable law

Whatever protections your own country grants you apply here in full — in particular the GDPR in the EEA, the UK and Switzerland, and the CCPA/CPRA in California. We claim no jurisdiction more convenient to us than yours.

15. Contact

Privacy questions, requests and complaints: support@meertun.online

The developer is the one named on the MearVPN page in the App Store: that page is the authoritative record, and Apple keeps it current.

Appendix — open-source licences

Components compiled into the app. None of them transmits anything on its own; none is a service.

Xray-core — the VLESS implementation and tunnel engine, Mozilla Public License 2.0. Its source is public; the source used for this build is available on request at the address in Section 15.

wireguard-go — the WireGuard implementation, MIT licence. “WireGuard” is a registered trademark of Jason A. Donenfeld.

hev-socks5-tunnel (© hev) and Tun2SocksKit (© Ebrahim Tahernejad) — the link between the tunnel and the engine, MIT licence.

GeoIP and GeoSite routing rule sets — shipped inside the app and read locally, never downloaded at runtime.

Golos Text, Unbounded, Playfair Display and IBM Plex Mono typefaces — SIL Open Font License 1.1.