Redwood Games Dev

Privacy Policy

Effective date and last updated: August 28, 2026

This Privacy Policy explains how Redwood Games Dev handles information when you use the VPN apps listed below and their supporting API services. The current versions do not require account registration or login.

1. Apps covered

This shared policy expressly applies to:

  • XiaoEr VPN for Android — package com.xiaoervpn.android;
  • XiaoEr VPN for iOS — bundle ID cc.draxgr.xiaoervpn;
  • Portlight VPN — package com.portlight.vpn;
  • Waypoint VPN — package com.waypoint.vpn.
  • PingPilot VPN — package com.pingpilot.vpn.

These apps provide a general-purpose VPN service. When you choose to connect, network traffic is transmitted through the selected VPN relay solely to provide the VPN connection.

2. Information we collect

We process only limited information needed to create anonymous sessions, provide VPN nodes and short-lived credentials, protect the service from abuse, and diagnose connection reliability:

2.1 Anonymous session and app information

  • Random installation identifier: generated locally when an app first runs and sent over HTTPS to request an anonymous session. The server stores only an HMAC-SHA-256 one-way hash, not the original identifier.
  • Platform and app version: used for compatibility checks, service availability, and troubleshooting.
  • Anonymous session token: used only to request available nodes and short-lived node credentials. It is stored in system-protected storage on the device, and the server stores only its hash.

2.2 Limited connection diagnostics

  • Selected node ID, connection result (connected, disconnected, or failed), connection duration, and a general error category such as timeout or auth.
  • These diagnostics do not include visited websites, URLs, DNS query contents, search terms, packet contents, or itemized upload and download activity.

3. VPN traffic and information we do not collect

The VPN relay necessarily processes source and destination IP addresses and ports while routing a live connection. Limited security or error logs may contain an IP address, port, and timestamp. These operational records are used only for service security and troubleshooting, are periodically rotated, and are not used to create browsing profiles.

We do not inspect, store, or analyze:

  • browsing history, website content, URLs, search terms, or DNS query contents;
  • VPN packet contents, communications, or uploaded and downloaded content;
  • precise location, contacts, photos, sensors, or other device data unrelated to VPN functionality.

An exit IP may be displayed locally in an app for connection verification, but it is not included in connection telemetry.

4. How we use information

  • create and maintain an anonymous session;
  • provide the current node list and short-lived VPN credentials;
  • apply request-rate limits and prevent service abuse;
  • diagnose aggregate connection failures and improve service reliability.

We do not use this information for advertising, profiling, personalized recommendations, cross-app tracking, or data brokerage.

5. Storage, security, and retention

  • Production API communication uses HTTPS.
  • Session tokens are stored in platform-protected storage, such as iOS Keychain or Android Keystore. Node credentials are not written to user-visible configuration or logs.
  • The backend stores one-way hashes rather than original installation identifiers or anonymous session tokens.
  • Limited session and aggregate diagnostic records are retained for no longer than 180 days and are then deleted.

6. Third-party services

We do not sell or share user information or VPN traffic information with advertisers, data brokers, analytics providers, or other third parties. The apps use the open-source sing-box networking library (github.com/SagerNet/sing-box) locally to provide the VPN tunnel. The library is not an external data recipient. VPN traffic passes through developer-controlled relay infrastructure only to provide the service and is not retained for advertising or profiling.

7. Your choices and rights

  • You may disconnect the VPN at any time.
  • You may clear app data or uninstall an app to remove its local session and preferences.
  • You may contact us to request deletion of server-side session and diagnostic records associated with your installation identifier hash.

8. Children's privacy

These apps are not directed to children under 14, and we do not knowingly collect personal information from children under 14. If you believe a child has provided information through the service, contact us so we can address the associated session and records.

9. Changes to this policy

We may update this policy as the products or applicable requirements change. The effective date above will be updated when changes are published, and material changes may also be announced in the apps.

10. Contact us


隐私政策(中文)

生效及最后更新日期:2026 年 8 月 28 日

本政策适用于 Redwood Games Dev 提供的以下 VPN 应用及其配套 API 服务:

  • 小耳 VPN(XiaoEr VPN)Androidcom.xiaoervpn.android
  • 小耳 VPN(XiaoEr VPN)iOScc.draxgr.xiaoervpn
  • Portlight VPNcom.portlight.vpn
  • Waypoint VPNcom.waypoint.vpn
  • PingPilot VPNcom.pingpilot.vpn

这些应用提供通用 VPN 服务。用户主动连接后,网络流量仅为提供 VPN 服务而通过所选中继传输。当前版本无需注册或登录账号。

1. 我们处理的信息

为完成匿名会话、节点分发、短期凭据、防滥用和连接诊断,应用会处理以下有限信息:

  • 随机安装 ID:应用首次运行时在本机生成,并通过 HTTPS 请求匿名会话;服务端仅保存其 HMAC-SHA-256 不可逆散列,不保存原始 ID;
  • 平台和应用版本:用于兼容性判断、服务可用性控制和问题诊断;
  • 匿名会话 Token:仅用于请求可用节点和短期节点凭据;客户端保存在系统安全存储中,服务端仅保存其散列;
  • 有限连接诊断:节点 ID、连接结果、连接时长和一般错误类别。

2. VPN 流量和我们不收集的信息

VPN 中继在实时转发连接时必须临时处理源和目标 IP 地址及端口。有限的安全或错误日志可能包含 IP 地址、端口和时间戳;这些运行记录仅用于服务安全和故障排查,会定期轮换,不用于建立浏览画像。

我们不检查、存储或分析浏览历史、网页内容、URL、DNS 查询内容、搜索词、VPN 数据包内容、通信内容、精确位置、通讯录或相册。出口 IP 可在应用本地显示以确认连接,但不会加入连接遥测。

3. 信息用途

上述有限信息仅用于建立匿名会话、下发节点和短期凭据、限流与防滥用,以及汇总诊断连接失败和改进稳定性。我们不将其用于广告、用户画像、个性化推荐、跨应用追踪或数据交易。

4. 存储、传输与保存期限

  • 生产 API 通信使用 HTTPS;
  • 会话 Token 保存在 iOS Keychain 或 Android Keystore 等系统安全存储中;节点凭据不写入用户可见配置或日志;
  • 服务端仅保存安装 ID 和匿名会话 Token 的单向散列;
  • 有限会话和聚合诊断记录的保存期不超过 180 天,到期后删除。

5. 第三方服务与共享

我们不会向广告商、数据经纪商、分析服务商或其他第三方出售或分享用户信息及 VPN 流量信息。应用在本地使用开源 sing-box 网络库提供 VPN 隧道;该开源库不是外部数据接收方。VPN 流量仅为提供服务而经过开发者控制的中继,不会为广告或画像目的保留。

6. 您的选择与权利

您可随时断开 VPN、清除应用数据或卸载应用,以删除本地会话与偏好。您也可以通过下方邮箱请求删除与安装 ID 散列关联的服务端会话和诊断记录。

7. 儿童隐私

这些应用不面向 14 岁以下儿童,我们不会明知地收集 14 岁以下儿童的个人信息。如您认为儿童通过服务提交了信息,请联系我们处理相关会话与记录。

8. 政策更新与联系方式

我们可能根据产品演进和适用要求更新本政策,发布更新时将同步调整页面顶部日期,重大变化也可能通过应用内公告通知。