Panda VPN Privacy Policy

Panda VPN — Privacy Policy Draft
Draft — not yet published. Confirm the marked operational details and final app behavior, then host the approved version at a public HTTPS URL.

Panda VPN Privacy Policy

Draft prepared 21 September 2026. Owner review and a public hosting URL are still required before this becomes the published policy.

This policy describes the current Panda VPN Android client. For privacy questions, contact winsapps2k19@gmail.com. Panda VPN is an independent client; VPN services selected through the app and advertising providers have their own data practices.

VPN traffic and server operators

Panda VPN uses Android's VpnService and WireGuard or OpenVPN to route device network traffic to a VPN endpoint selected by you. The selected VPN operator receives your connection and processes the traffic routed through that endpoint. Information visible to an operator can include your originating IP address, connection times, destination addresses, DNS requests, traffic volume and any content not protected separately by end-to-end encryption such as HTTPS. What is available depends on your configuration and the protocols in use.

The current app connects to third-party or user-configured servers; it does not provide a Panda-operated VPN server network. It is not a guarantee of anonymity. Choose an operator you trust and review its privacy policy before connecting. Your data may pass through servers outside your country.

VPN Gate is a public volunteer network. Its published anti-abuse policy describes connection and directory-access logging and packet-header logging on volunteer relays. Panda VPN cannot control those records or guarantee that a volunteer server deletes them. See https://www.vpngate.net/en/about_abuse.aspx.

If you choose Mullvad, its own service and privacy terms apply. See https://mullvad.net/en/help/privacy-policy. Other configurations are subject to the policies of their server operators.

Information stored on your device

The app stores imported or manually entered server configurations, cryptographic key material needed for connections, selected and last-used server, connection-quality ratings, auto-connect preference, ad choice, and temporary reward expiration times in app-private storage. These values support connection setup and your preferences.

In the inspected build, configuration storage uses Android SharedPreferences without additional app-level encryption, and Android backup/transfer exclusions are not yet configured. Depending on device settings, backup or device transfer may copy app data. This behavior must be reconciled with the final release and this section updated if storage or backup rules change.

The app does not provide a Panda VPN account-creation flow. Provider accounts, if used, are separate from Panda VPN.

Server imports and quality checks

When you request a server import, the app contacts the relevant provider over HTTPS. Network services receive the network address needed to respond. For Mullvad setup, the account number you supply and a generated WireGuard public key are sent to Mullvad to request configuration. The app stores the generated private key locally for use by the VPN engine.

Latency checks send network requests to supported server endpoints. Those endpoints and networks may observe the source address and timing of those requests. Server ratings are estimates and can change.

Optional Unity advertising

Unity Ads is initialized only after you enable ads in Ad choices. The current configuration requests non-personalized advertising. When enabled, Unity processes data for ad delivery, measurement, diagnostics and fraud prevention; non-personalized advertising still involves data processing. Depending on applicable SDK features, this can include approximate location, identifiers and ad interactions. Review Unity's privacy policy and SDK disclosures for the complete categories and its retention and privacy-choice procedures:

- https://unity.com/legal/privacy-policy
- https://docs.unity.com/en-us/ads-android/4.19.0/privacy/developer-consent/disclosures/google-data-safety

The Panda app code does not pass your VPN configuration, private keys or routed browsing traffic to the advertising SDK as ad parameters. This statement does not describe or override a VPN operator's practices.

You can disable future in-app ad requests using Ad choices. Disabling ads is not a request to delete information already processed by Unity. Use Unity's privacy procedures for that information. Temporary rewards are recorded on your device.

Support requests

If you email winsapps2k19@gmail.com, the support mailbox and email service receive your email address, message and any information you choose to attach. Use this channel for support and privacy requests. Do not send passwords, private keys or complete VPN configurations. The owner must confirm and publish the actual support-message retention and deletion practice before release.

Retention and deletion choices

Local preferences and configurations remain until overwritten, removed through Android's app-storage controls, or otherwise deleted with the app. Clearing Panda VPN storage in Android settings removes local app data and resets preferences. Uninstalling does not necessarily delete existing cloud backups, third-party VPN records, advertising records or provider accounts.

For records held by VPN operators, Unity or email services, use the relevant provider's privacy/deletion procedure. Contact the support address for information held in the Panda VPN support mailbox. Owner confirmation of retention and deletion procedures is required before publishing this draft.

Security and permissions

Android asks for VPN authorization before establishing the first tunnel. The app may also request notification permission for connection notifications. VPN encryption protects the configured tunnel to its endpoint; it does not by itself protect all traffic after it leaves that endpoint. Use HTTPS and other appropriate application-level protections. No network or storage method is guaranteed to prevent every security incident.

Audience, rights and policy updates

Before publication, the owner must set the intended age audience and ensure the app, ads, disclosures and handling of children's data match it. The panda illustration alone does not determine the intended audience. Regional rights and any required operator identity, representative, legal basis or international-transfer information must be finalized for the countries where the app will be offered.

If data practices change, update the published policy and any relevant in-app disclosures and consent before enabling the changed processing. Privacy questions can be sent to winsapps2k19@gmail.com.

Comments

Popular posts from this blog

Privacy Policy

Privacy Policy for Find Barn Buddies

Privacy Policy for Dragon Siege: Last Stand