Privacy Policy

Effective and last updated: 23 July 2026

This policy explains how Whale VPN handles data in its Android application and related account, attribution, reliability and analytics services. Usage Analytics is enabled by default for new installations, can be disabled in the app settings, and is not required for the core VPN service.

1. Account and service data

When you create or use an account, the service processes the credentials and account information needed for authentication, subscription entitlement, device management, billing and support. Passwords are transmitted only to the account service for authentication and are never sent to Google Analytics for Firebase.

2. VPN operation

The app processes subscription configuration, selected routes and network traffic to establish the VPN connection. VPN infrastructure necessarily processes network connections while carrying them. Whale VPN does not send node names, node addresses, gateway domains, SNI, visited domains, destination IP addresses or subscription contents to Firebase Analytics.

3. Usage analytics

Google Analytics for Firebase starts enabled with the Android application and is enabled by default for new installations. You can turn Usage Analytics off or on independently in the Android app settings at any time. Because collection starts from application startup, some startup events can be collected before a previously stored off setting is loaded and applied.

When enabled, Firebase may process an automatically generated app-instance identifier, app lifecycle and session events, app interactions, device/app metadata, and coarse location derived by Google from a masked IP address. Whale VPN also sends custom events for onboarding, verified VPN connection outcomes, confirmed download attribution, and VPN use after at least 16 KB of real proxied traffic.

Whale VPN does not set a Firebase User-ID and disables advertising-ID collection and ad-personalization signals. Except for the confirmed attribution identifiers described below, Analytics events never include email, password, account UID, guest account, subscription token, server or node details, browsing destinations, precise location, exception stacks or full logs.

4. Download attribution

For a direct APK or Google Play install, the app sends a short one-time download token and a 32-character Whale installation identifier to Whale VPN's attribution gateway to match a download with an installation. The Whale identifier is derived on the device from Android's app-scoped system identifier; the original Android system identifier is not transmitted. After the gateway confirms the claim, and only when Usage Analytics is enabled, the app also sends the validated download token, Whale installation identifier and the fixed channel value direct_apk or google_play to Firebase Analytics. This creates an exact link between the gateway download record and Firebase app activity for conversion analysis.

5. Crash reporting

Crash reporting is a separate optional setting. If enabled, Firebase Crashlytics may receive crash diagnostics and device/app metadata needed to investigate stability problems. Turning Usage Analytics on or off does not change the Crashlytics setting.

6. Purposes, processors and transfers

We use data only to provide accounts and VPN connectivity, secure and operate the service, attribute installations, measure aggregate retention, diagnose fixed connection failure categories, and improve reliability. Google acts as a service provider for Firebase Analytics and, when separately enabled, Crashlytics processing. Data is encrypted in transit.

7. Retention and choices

Operational and account records are retained only for the period needed for the purposes above, legal obligations, security and dispute handling. Firebase data follows the retention controls configured for the Whale VPN Firebase property. Turning off Usage Analytics or Crash Reporting stops future collection by that product. To request account or associated data deletion, or ask a privacy question, use the customer-support entry inside the app or contact Whale VPN support on Telegram.

8. Changes

We may update this policy when the app, providers or legal requirements change. The effective date at the top identifies the current version.

隱私權政策摘要

Google Analytics for Firebase 從 Android 應用程式啟動時即開始收集,並在新安裝中預設開啟。您可隨時在應用程式設定中獨立關閉或重新開啟「使用情況分析」。由於收集從啟動時開始,先前已儲存的關閉設定在載入並套用前,仍可能收集部分啟動事件。開啟後,Firebase 可能處理自動產生的應用程式執行個體識別碼、生命週期與工作階段事件、互動事件、裝置/應用程式中繼資料,以及 Google 從遮罩 IP 推導的粗略位置。

下載歸因經 Gateway 確認成功後,Firebase Analytics 亦會收到經驗證的原始下載 token、32 字元 Whale install_id,以及固定的 direct_apk/google_play 渠道,以便把下載記錄與應用程式活動精確關聯。Whale install_id 由裝置上的 Android 應用程式範圍系統識別碼派生,原始 Android 系統識別碼不會傳送。

我們不設定 Firebase User-ID,並關閉廣告 ID 收集與廣告個人化訊號。除上述歸因識別碼外,Firebase Analytics 不會收到電子郵件、密碼、帳號 UID、完整訪客帳號、訂閱 token、節點名稱/IP、Gateway 網域、SNI、瀏覽網域、目標 IP、訂閱內容、精確位置、例外堆疊或完整日誌。Crashlytics 使用獨立的選擇性開關,不與 Analytics 共用授權。

如需刪除帳號或相關資料,或提出隱私問題,請使用應用程式內的客服入口,或透過 Telegram 聯絡 Whale VPN 客服