Android VpnService
Utilizes the official Android VpnService framework to establish secure, encrypted virtual network tunnels for device traffic.
No Activity Logging
We do not log, inspect, record, or monitor your visited websites, browsing history, DNS queries, or transmitted content payloads.
No User Accounts
Operates without registration, email logins, phone numbers, or passwords. No personal profile is ever created or stored.
Encrypted Transit
All tunnel routing and external API/telemetry transmissions are protected using standard end-to-end transport encryption (TLS/HTTPS).
Introduction & Service Provider Identity
Welcome to Ice VPN ("the Application", "the App", "our Service"), developed and published by Newgates ("Service Provider", "we", "us", or "our"). Ice VPN is an Android network utility application designed to provide users with secure, encrypted network proxying and tunnel connectivity over public and private networks.
This Privacy Policy applies to your installation, access, and usage of Ice VPN on Android mobile devices. We believe that user privacy and network transparency are foundational. This document clearly articulates what information is processed, how network traffic is routed via Android's native VpnService architecture, how third-party services operate within the App, and how you can exercise your privacy rights in full compliance with the Google Play Developer Program Policies, the Google Play User Data Policy, and Google Play VpnService requirements.
Android VpnService & Network Routing Architecture
The primary and core functionality of Ice VPN is to provide a virtual private network service. To deliver this functionality on Android devices, the Application utilizes the official Android android.net.VpnService API framework.
How VpnService Operates in Ice VPN
- Local Virtual Network Interface (TUN): When you activate Ice VPN by tapping the connect button, the App requests permission from the Android operating system to create a local virtual network interface (a TUN interface) on your device.
- Encrypted Tunnel Establishment: Outgoing IP packets originating from apps and services on your device that you route through the VPN are encapsulated and encrypted on the local device, then transmitted over an encrypted tunnel to our designated VPN server endpoints.
- Gateway Relay & Ephemeral Processing: The VPN server decrypts the packets and forwards them to their intended destination on the Internet. Return traffic is received by the VPN server, re-encrypted, sent back through the tunnel, and decrypted locally by the TUN interface on your device.
- Direct Network Transit: Packet routing occurs strictly in real-time within volatile memory (RAM) solely for the purpose of forwarding network packets. No packet payload data is ever saved to persistent disk storage on our servers.
VpnService connection requires an explicit system confirmation dialog presented by the Android operating system. The VPN tunnel cannot and will not be established without your affirmative consent to this system prompt.
Zero-Activity-Logging & Traffic Disclosures
We believe you should have complete visibility into how your network traffic is handled. Ice VPN operates under a strict, transparent Zero-Activity-Logging commitment regarding your personal browsing and communication data.
What We Do NOT Log or Inspect
- No Browsing History: We do not log, inspect, store, or monitor the domain names, website URLs, web pages, or online resources you access through the VPN tunnel.
- No Traffic Content / Payload Inspection: We do not inspect, intercept, record, alter, or inject data into the content of your communications, files, downloads, or network streams.
- No DNS Query Logs: DNS queries resolved through the VPN connection are processed transiently in memory to establish connectivity and are not archived or associated with your identity.
- No User Identity Linking: Because Ice VPN does not require user accounts, email registration, or logins, your network traffic cannot be linked to any personal identity or user profile.
- No Traffic Monetization or Ad-Injection: We never sell, rent, monetize, or manipulate your network traffic for advertising, tracking, or data-brokerage purposes.
Information We Collect & Process
To provide connection stability, monitor server health, diagnose technical crashes, and deliver ad-supported features, Ice VPN processes limited technical and diagnostic information.
| Data Category | Specific Data Items | Collection Method | Purpose |
|---|---|---|---|
| Network & Connection Telemetry | Approximate network state (Wi-Fi / Cellular indicator), connection latency, tunnel connect/disconnect events, protocol version, aggregate bytes transferred (session totals). | Automatic via App runtime & Firebase SDKs | VPN server routing, load balancing, evaluating node availability, and diagnosing connection drops. |
| Device & Hardware Diagnostics | Device manufacturer, device model, Android OS version, system architecture (ARM/x86), app version code, system language, available RAM. | Automatic via Firebase Crashlytics | Diagnosing hardware-specific crashes, maintaining compatibility, and optimizing stability across Android builds. |
| Advertising Identifiers | Google Android Advertising ID (AD_ID), Google Play Services identifier. |
Automatic via Google AdMob SDK | Serving contextual and frequency-capped advertisements, preventing ad fraud, and measuring ad delivery. |
| Crash & Performance Reports | Stack traces, non-fatal exception logs, thread state at crash time, cold start latency, UI frame render metrics. | Automatic via Firebase Crashlytics & Perf | Identifying software bugs, resolving null pointer exceptions, and improving app responsiveness. |
| Support Inquiries (User-Initiated) | Your email address, correspondence message, and any diagnostic attachments you voluntarily provide when emailing support. | Voluntary direct email | Responding to your customer service requests, technical troubleshooting, and policy inquiries. |
Information We Strictly Do Not Collect
To avoid ambiguity, we explicitly state that Ice VPN does not collect, process, or store the following categories of data:
- No Precise Location Data: We do not request, access, or track GPS coordinates, fine location, or coarse location sensor data (
ACCESS_FINE_LOCATIONorACCESS_COARSE_LOCATION). - No Personal Identifiable Information (PII): We do not collect your real name, physical address, phone number, government ID numbers, or contact lists.
- No Financial or Payment Data: Ice VPN does not collect bank account information, credit/debit card numbers, or billing addresses.
- No Media, Camera, or Microphone Access: We do not access your photos, videos, audio recordings, microphone, or camera.
- No Device Storage Scanning: We do not scan or read your local documents, downloads, or external storage files.
- No User Account Credentials: There is no registration system, password database, or authentication token storage.
How We Use Collected Information
We use the limited technical data collected solely for legitimate operational and engineering purposes:
- Delivering Core VPN Services: Allocating server resources, routing encrypted packets through available gateway clusters, and maintaining tunnel stability.
- System Performance & Diagnostics: Investigating software crashes, memory leaks, connection timeout anomalies, and optimizing data throughput.
- Service Integrity & Security: Detecting and mitigating distributed denial-of-service (DDoS) attacks, protocol abuse, automated spam, and malicious bot activity targeting our servers.
- Ad Serving & Monetization: Enabling Google AdMob to deliver compliant banner and interstitial advertisements that sustain free server infrastructure.
- Customer Support: Addressing troubleshooting tickets, responding to user feedback, and resolving technical connectivity inquiries.
- Legal Compliance: Complying with applicable legal obligations, lawful government requests, or court orders where mandatory under governing law.
Third-Party SDK Integrations & Service Partners
Ice VPN integrates trusted industry-standard software development kits (SDKs) provided by Google to handle infrastructure, diagnostics, and monetization. Each third-party partner handles data pursuant to their own privacy standards and Google's certified developer policies.
Provides essential Android system APIs, security verification, and application update infrastructure.
Google Privacy Policy ↗Delivers mobile banner, interstitial, and rewarded advertisements in compliance with Google Play ad policies.
AdMob Privacy & Data ↗Measures aggregate, non-personal app interaction metrics (e.g. session counts, screen flows, connection success rates).
Firebase Privacy Details ↗Captures real-time crash stack traces, hardware states, and non-fatal exceptions to identify and fix bugs.
Crashlytics Privacy Details ↗Advertising & Monitored Attribution
Ice VPN displays advertisements via Google AdMob to fund server maintenance, bandwidth costs, and ongoing development.
Advertising Identifiers & User Choices
AdMob may use the Android Advertising ID (AD_ID) to serve relevant ads, limit the number of times you see the same ad, and measure ad performance. You maintain full control over this identifier on your Android device:
- Resetting Advertising ID: On Android devices running Android 11 or earlier, you can reset your Advertising ID at any time via Settings → Google → Ads → Reset advertising ID.
- Deleting Advertising ID: On Android 12 and higher, you can completely delete your Advertising ID via Settings → Security & Privacy → Privacy → Ads → Delete advertising ID. When deleted, the identifier returns a string of zeros, preventing ad networks from tracking your device across apps.
- Personalized Ads Opt-Out: You can opt out of personalized ads at any time via your device's Google Ads settings.
Data Sharing, Transfers & Disclosures
We do not sell, rent, lease, trade, or monetize your personal information or network data to third parties, data brokers, or commercial marketers. We only share or disclose data under the following strictly limited circumstances:
- Infrastructure & Service Providers: Trusted third-party cloud, hosting, and diagnostic providers (such as Google Cloud and Firebase) that process telemetry on our behalf under strict confidentiality and security commitments.
- Legal Requirements & Law Enforcement: If required to do so by applicable law, a valid subpoena, court order, or binding government warrant issued by a competent legal authority with jurisdiction over our operations. Because we do not store browsing history, DNS logs, or user accounts, we cannot produce logs that do not exist.
- Protection of Rights & Safety: When necessary to investigate potential fraud, security violations, malicious attacks against our server infrastructure, or to protect the safety of users and the public.
- Business Transfers: In the event of a merger, acquisition, restructuring, or sale of assets, user data handled under this policy will remain subject to the terms of this Privacy Policy.
Data Security & Encryption Standards
We employ robust administrative, technical, and physical safeguards designed to protect the integrity and confidentiality of your data and network streams.
Technical Safeguards
- Transport Layer Security: All API communication between the Ice VPN app and back-end diagnostic/configuration endpoints is enforced via modern HTTPS and TLS 1.2/1.3 encryption.
- VPN Tunnel Encryption: Network packets traversing the VPN tunnel between your device's virtual TUN interface and our gateway nodes are encapsulated and encrypted using standard cryptographic protocols.
- Volatile Memory Packet Routing: VPN gateway servers operate stateless packet forwarding in RAM. Packets are processed in real-time and purged from memory immediately upon transmission.
- Access Controls & Hardened Infrastructure: Administrative access to server nodes is restricted to authorized engineers via multi-factor authentication, key-based SSH, and continuous firewall monitoring.
Data Retention & Ephemeral Processing
Our data retention practices follow the principle of strict data minimization:
- VPN Network Traffic: Processed ephemerally in real-time. Packets are never written to disk or retained after transmission completes. Retention period is zero seconds.
- Diagnostic & Crash Telemetry: Anonymized stack traces and crash reports stored within Google Firebase are automatically retained for standard diagnostic windows (typically 90 to 180 days) before automatic rolling deletion.
- Local Device Preferences: User settings (e.g. auto-connect toggle, selected server location, theme preference) are stored 100% locally on your device via sandboxed Android SharedPreferences and are never synchronized to external servers.
- Support Correspondence: Emails and support tickets sent to our support addresses are retained only for as long as necessary to resolve your inquiry and maintain support records.
User Rights, Controls & Data Deletion Mechanisms
Depending on your geographic location (including under the GDPR for European users and CCPA/CPRA for California residents), you possess specific legal rights regarding your data:
1. Deleting Local Application Data
You can instantly delete all locally stored preferences, caches, and connection state by:
- Navigating to your device's Settings → Apps → Ice VPN → Storage → Clear Data & Clear Cache.
- Uninstalling the Ice VPN application from your device.
2. Opting Out of Advertising & Analytics Identifiers
You can reset or delete your Android Advertising ID (AD_ID) via device settings (Settings → Security & Privacy → Privacy → Ads), which permanently disconnects past telemetry from future device interactions.
3. Requesting Telemetry Record Deletion
Because Ice VPN does not maintain user accounts, we do not have an account-deletion button in the App. However, if you wish to request the manual deletion of any diagnostic telemetry or support correspondence associated with your device or email, you may submit a formal request to our privacy team:
- Email: newgates.developer@gmail.com / weicevpn@gmail.com
- Subject: Ice VPN Privacy & Data Deletion Request
- Processing Time: We evaluate and process all verified deletion and rights requests within 30 business days at no cost to you.
Android System Permissions & Hardware Access
To perform its network utility duties, Ice VPN requests only standard, essential Android permissions:
| Permission | Category | Purpose & Usage |
|---|---|---|
android.permission.INTERNET |
Network | Required to transmit VPN tunnel traffic to remote gateway nodes and fetch server configuration lists. |
android.permission.ACCESS_NETWORK_STATE |
Network State | Monitors whether device is connected via Wi-Fi, cellular, or offline to manage reconnection triggers. |
android.permission.BIND_VPN_SERVICE |
VPN System Service | Required by Android OS to bind our VPN service implementation and instantiate the local TUN interface. |
com.google.android.gms.permission.AD_ID |
Advertising | Declared by Google Mobile Ads (AdMob) SDK for advertising attribution and frequency capping. |
android.permission.FOREGROUND_SERVICE |
Service Execution | Maintains active VPN tunnel routing while the app is in the background or device screen is locked. |
android.permission.FOREGROUND_SERVICE_SPECIAL_USE |
Foreground Type | Declares VPN background processing to Android 14+ (API 34+) operating system components. |
android.permission.POST_NOTIFICATIONS |
Notifications | Required on Android 13+ (API 33+) to display the persistent notification indicating active VPN status. |
android.permission.WAKE_LOCK |
Power Management | Prevents CPU sleep while network packets are actively transiting the VPN tunnel. |
In-App Prominent Disclosures & User Consent Notice
In compliance with Google Play's VpnService and User Data policies, this web-hosted Privacy Policy is accompanied by runtime in-app prominent disclosures presented directly inside the Ice VPN Android client:
- Runtime In-App Consent Dialog: Prior to initiating any VPN tunnel for the first time, Ice VPN displays an explicit in-app disclosure modal explaining that the application utilizes Android's
VpnServiceto create a secure tunnel and route device network traffic. - Affirmative User Action: The VPN connection is only established after the user explicitly taps the confirmation button on the in-app disclosure dialog and confirms the Android system VPN dialog.
- Persistent Status Indicator: While connected, an active foreground notification and the native Android system key icon in the status bar continuously notify the user that network traffic is actively routed through the VPN.
- Independent Scope: We note that this Privacy Policy document provides full legal and technical disclosures for publication and store listing review, while the in-app disclosure fulfills the runtime interactive requirements within the mobile app client.
Children's Privacy (COPPA & Global Compliance)
Ice VPN is intended for a general audience and is strictly directed to users aged 13 and older (or 16 and older in jurisdictions where required by local law).
- We do not knowingly solicit, collect, or process personal data from children under the age of 13.
- We do not design features, themes, or marketing targeted at children.
- If we learn that personal data of a child under 13 has been inadvertently transmitted through customer support or diagnostic logs, we will take prompt steps to immediately delete such information from our records.
- Parents or legal guardians who become aware that their child has provided personal information to us may contact us immediately at newgates.developer@gmail.com or weicevpn@gmail.com for swift remediation.
Google Play Console Data Safety Mapping
For complete transparency and ease of verification in the Google Play Console, the table below provides our exact Data Safety declaration mappings for Ice VPN:
| Data Safety Category | Collected? | Shared? | Processed Ephemerally? | Purpose |
|---|---|---|---|---|
| App Interactions (app launches, taps) | Yes | No | No | Analytics, App Functionality |
| Crash Logs & Stack Traces | Yes | No | No | App Functionality, Diagnostics |
| Performance Diagnostics | Yes | No | No | Analytics, Performance Optimization |
Device or Other IDs (AD_ID, Firebase ID) |
Yes | Shared (AdMob) | No | Advertising, Analytics, SDK Functionality |
| Network Traffic & Web Browsing Data | No | No | Ephemeral Transit | VPN Routing (zero persistent storage) |
| Personal Information (Name, Email, Phone) | No | No | N/A | Not Collected |
| Precise / Coarse Location | No | No | N/A | Not Collected |
| Financial / Payment Information | No | No | N/A | Not Collected |
| Photos, Videos, Files & Media | No | No | N/A | Not Collected |
Play Console Security Practices Summary
- Data Encryption in Transit: Yes — All network data and diagnostic communications are encrypted in transit using standard cryptographic protocols (HTTPS/TLS and encrypted VPN tunnels).
- Account Creation & Deletion: No / Not Applicable — The application does not require or support user account registration.
- Target Age: 13 and older (General Audience).
Policy Modifications & Updates
We may revise this Privacy Policy periodically to reflect updates to the Application, adjustments to server infrastructure, advancements in privacy legislation, or updates to Google Play Developer policies.
- When updates occur, we will revise the "Last Updated" date displayed at the top and bottom of this document.
- For substantial or material changes, we will provide noticeable notifications within the Application or on this webpage prior to the changes taking effect.
- We encourage you to review this Privacy Policy periodically to remain informed about our data protection commitments. Continued use of Ice VPN following the effective date of an updated policy signifies your agreement to the revised terms.
Developer Identity & Contact Inquiries
If you have any questions, comments, concerns, or requests regarding this Privacy Policy, our network privacy practices, or your data rights, please contact our dedicated developer and privacy team:
Developer / Publisher: Newgates
Primary Developer Email: newgates.developer@gmail.com
Application Support Email: weicevpn@gmail.com
Privacy Hub URL: https://zino.mrkotlinx.workers.dev/
We review and respond to all genuine inquiries, technical questions, and privacy requests promptly and within statutory deadlines.