Naruworks
All privacy policies

L2TP VPN Client

Privacy Policy

Version 2Version history

1. Overview

L2TP VPN Client ("the App") is developed and published by Naruworks ("we"). It is a client for connecting to L2TP/IPSec, IKEv2/IPSec, and WireGuard servers that you own or are authorized to use. Available protocols depend on your Android version and device capabilities.

  • The App has no sign-up or account system operated by us. Credentials entered for a VPN connection belong to the VPN server you choose.
  • We do not provide or operate VPN servers or an application backend that receives your VPN profiles, traffic, or diagnostic reports automatically.
  • VPN profiles are kept on your device. Connection details are shared only with the server you choose and the Android VPN components needed to connect.
  • Google provides the advertising, advertising-consent, and billing services described below.
  • If you choose to email us, we receive your email address and the information or diagnostic report you send.

This policy covers the App and support inquiries sent to us. The VPN operator, network/DNS providers, Google, and your email provider may process information under their own policies.

2. Information we handle

The App does not automatically upload VPN credentials, VPN traffic, browsing history, DNS queries, connection logs, or diagnostic reports to us. It contains no remote analytics or report-upload service operated by us. Advertising SDK processing is described in section 6.

We receive information when you voluntarily contact us: your sender email address, any name supplied by your email service, your message, and attachments such as a diagnostic report. A report may contain device and network details, connection settings, addresses, and error information as described in section 5. We use this information to respond, investigate the reported problem, and improve or fix the App. We do not use support correspondence for advertising or sell it.

Providing a report is optional. You can ask for help without attaching one. Review and remove information you do not want to disclose before sending it. Please do not send passwords, private keys, pre-shared keys, or complete VPN configuration files. Email providers process messages in order to deliver and store them. Our deletion deadline for support email and attachments is set out in section 10.

3. Information stored on your device

Depending on the protocol and settings you choose, a saved profile can include:

  • Profile name and identifier, selected protocol, server address, and connection settings.
  • User ID and password; IPSec pre-shared key; an optional L2TP tunnel secret.
  • L2TP/IKEv1 identity, exchange mode, DH group, DNS servers, search domains, and routes.
  • IKEv2 authentication method, identity, and an optional CA certificate.
  • WireGuard configuration, including private/public keys, optional peer pre-shared keys, endpoints, interface addresses, DNS, allowed IP ranges, and application inclusion/exclusion settings.

The App also keeps local settings such as the selected profile and whether you have bought ad removal. For IKEv2, Android receives the VPN profile needed to operate the connection, and the App stores profile ID, display name, and session metadata in its private preferences. A display name may contain a server address if you use an address as the name or leave the name blank.

Storage protection

The profile list, including credentials and WireGuard configuration, is encrypted with AES-256-GCM before being saved by the App. Its encryption key is managed by Android Keystore. Hardware-backed protection depends on the device.

The App sets allowBackup="false" to disable Android cloud backup of its app data. Device-to-device transfer behavior can vary by Android version and manufacturer. Files you imported, copied reports, and exported or emailed copies are outside this app-data setting. See Android's backup documentation.

You can delete profiles in the App. Removing an IKEv2 profile also removes its corresponding Android-provisioned profile when it is the profile registered by the App. Uninstalling removes the App's private data and its Keystore key; it does not remove source files or copies you stored elsewhere.

4. VPN connections and your traffic

How connections are established

The App's main function is connecting to a VPN. L2TP/IPSec and WireGuard use Android's VpnService; IKEv2/IPSec uses Android's platform VPN APIs on supported devices. Android controls VPN authorization and presents the applicable consent screen when authorization is required.

Traffic routed into a VPN tunnel is encrypted between your device and the selected VPN endpoint. L2TP/IPSec uses IKEv1 and IPSec ESP; IKEv2/IPSec uses Android's IKEv2/IPSec implementation; WireGuard uses the WireGuard protocol. The selected configuration and protocol determine which destinations and applications use the tunnel. Traffic outside those routes is not protected by that tunnel.

The App processes packets locally to operate the connection. We do not operate an intermediary VPN server, receive your VPN traffic, or redirect or modify other apps' traffic for advertising revenue. Local troubleshooting information is described separately in section 5. Your VPN operator handles traffic at the endpoint under its own policy. Hostname resolution and DNS requests use the relevant device or VPN DNS configuration.

The App's own advertising and billing traffic

The route of the App's own requests is protocol-dependent:

ProtocolRouting of the App's own traffic
L2TP/IPSecThe App configures its package to be excluded from its tunnel. Advertising and billing requests therefore normally use the underlying network.
IKEv2/IPSecRequests follow Android's platform VPN routing. The App does not apply the L2TP package-exclusion rule to this profile.
WireGuardRequests follow the imported allowed IP ranges and included/excluded application settings. They may use the VPN or the underlying network.

We do not guarantee that advertising or billing always bypasses every VPN. The address visible to a remote service depends on the route actually used. Likewise, if you set custom routes or exclude apps, some apps or destinations may not use the VPN.

5. Negotiation log and diagnostic report

The App provides an in-app negotiation log and an optional report to help troubleshoot connections. These are not uploaded automatically.

In-app retention and copying

  • The in-app report and log relate to the single most recent connection attempt. The log retains up to 300 entries, including events such as starting a connection, authentication progress, and errors.
  • They are held in process memory rather than a report file or history database. A new connection attempt clears the previous report/log.
  • Selecting OK in the error dialog or Close in the detailed log keeps the report and log. Closing either screen with the Back button also keeps them. While you remain on the App's screen, you can use the log button at the top to review and copy the most recent records again.
  • Switching to another app or closing the App clears the report and log when the App's screen is no longer visible. Rotating the screen or similar display changes preserves them. If the App's process ends, the report and log are lost with it.
  • Clearing diagnostics does not disconnect an active VPN. Operational connection state may remain while the service or Android maintains the tunnel.
  • Copy puts the report on the system clipboard and shows our support email address. The App does not send an email or upload the report for you, and the diagnostic screen has no direct Share action.

A report placed on the clipboard, or saved or sent through another app, exists separately from the App. Clearing the in-app report does not remove those copies or any email already sent.

Information a report may contain

SectionContents
AppPackage name, version, build type, install time, and install source
DeviceManufacturer, model, Android version, build number, security patch level, and ABI
NetworkTransport, interface, MTU, address-family counts, NAT64 prefix, and private DNS information
ConfigurationProtocol, authentication/negotiation settings, credential length and character types, configured routes, and WireGuard peer/address/DNS counts
ResultConnection state, failure category, stage, reason, assigned tunnel address, and negotiation summary
Layer stateL2TP/IKE/PPP state, IKEv2 status where available, or WireGuard stages and handshake/traffic statistics
Negotiation logRecent connection events and errors; some L2TP/IPSec error paths include limited hexadecimal packet dumps

Redaction and its limits

The profile-summary fields are designed to avoid printing credential values. When a report is copied, it is also checked for known credential strings, IKE identity/certificate values, and WireGuard keys/configuration, with matching strings of at least three characters replaced by ***redacted***.

Even so, a copied report or the on-screen log may still contain sensitive information. For example:

  • The profile-summary address is shortened, but L2TP connection events can include the complete server hostname or resolved IP address. Assigned addresses, custom routes, private DNS names, and other network details can also appear.
  • The raw log displayed on screen is not the same as the report after the final redaction pass.
  • String matching cannot catch very short values or values encoded differently, including data inside hexadecimal packet dumps. Error dumps can contain parts of actual packets.

Review a copied report before sharing and remove any remaining sensitive details. The App also uses Android system logging for certain operational or SDK errors. These logs are managed by Android, not the App, so closing the report dialog does not clear them. Who can read them and how long they are kept depend on Android and the device's diagnostic settings.

6. Advertising and consent (Google AdMob)

The App displays banner advertising through Google AdMob / Google Mobile Ads SDK, provided by Google LLC. Depending on settings and consent, SDK processing includes:

DataExamples and purposes
IP addressApproximate location, advertising, analytics, and fraud prevention
Product interactionsApp launches, taps, and ad interactions for advertising and analytics
DiagnosticsApp/SDK performance, failures, and related operational information
Device/account identifiersAdvertising ID, app set ID, and other identifiers where applicable

Google describes SDK data collection, sharing, and TLS encryption in its data disclosure documentation. Its handling is also covered by Google's advertising information and Google Privacy Policy. We receive advertising reports such as aggregate impressions and revenue; the App does not forward its VPN profiles or diagnostic reports to the advertising SDK as custom advertising data.

Consent and controls

The App uses Google's User Messaging Platform (UMP) to check consent requirements and display the applicable consent form. If Google indicates that you need a way to revisit these choices, the App's menu shows Privacy options, which reopens Google's form so you can review or change them. The App requests ads only when the SDK's consent status allows it and you have not bought ad removal. See Google's UMP information.

You can also reset or delete the advertising ID in Android's advertising/privacy settings. This affects only that identifier. It does not stop other advertising-related processing, such as IP-address or diagnostic processing, or delete information Google already holds.

Ad-removal purchase

Once the App confirms that you own ad removal, it stops showing and requesting banner ads. On later launches, it also skips ad setup and the consent request. Buying ad removal does not delete data already collected or stop Google Play from checking your purchase. If the ad SDK was already running when you bought ad removal, some of its activity may continue until the App is restarted.

Advertising and billing requests follow the protocol-dependent routes described in section 4.

7. Payments

Ad removal is a one-time, non-consumable purchase (ad_free_forever) processed through Google Play Billing. The App receives purchase status and purchase tokens from Google Play to check ownership and acknowledge a purchase. The App does not store or log these tokens. It only remembers on the device whether you own ad removal. Your purchase can be checked again or restored through Google Play.

We do not receive your card or bank credentials through the App. Google processes the payment under its own terms and privacy policy. Information you separately send in a billing-support email is handled as support correspondence. Refunds and billing inquiries are subject to Google Play's policies.

8. Permissions and file access

Permission or accessPurpose
INTERNETVPN connections, network resolution, advertising/consent, and billing services
ACCESS_NETWORK_STATENetwork status and connection handling
FOREGROUND_SERVICE / FOREGROUND_SERVICE_SPECIAL_USEUser-initiated L2TP/IPSec and WireGuard connections that continue in the background
POST_NOTIFICATIONSConnection status and disconnect controls
BIND_VPN_SERVICERestricts binding to VPN services to Android; this is not a general user-granted runtime permission
com.android.vending.BILLINGAd-removal purchase and ownership checks
AD_ID / ACCESS_ADSERVICES_*Advertising features supplied by Google SDKs
WAKE_LOCKIncluded by a bundled SDK; the App's own VPN code does not explicitly acquire a wake lock
System document pickerReading the configuration/certificate file you explicitly select for import

The App does not request broad access to your storage, location, contacts, camera, microphone, SMS, or call history. Selecting a file through Android's picker grants access to that selected document; importing it does not delete the source file. Advertising may derive approximate location from an IP address without requesting device-location permission.

9. Children's privacy

The App is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has sent us personal information, contact the address in section 13 so we can address the request and delete the information as appropriate.

10. Data retention and deletion

  • Saved profiles and settings: kept locally until deleted or replaced. You can remove profiles in the App or remove the App's private data through Android. IKEv2's system-managed profile is handled as described in section 3. Import source files and external copies require separate deletion.
  • In-app diagnostics: only the latest connection attempt, held in memory and cleared as described in section 5. Copies on the clipboard or sent elsewhere are not affected.
  • Support email and attachments: used to handle the inquiry and investigate the reported issue, and deleted from the developer's mailbox and working copies within 30 days after the inquiry is resolved. This includes attached diagnostic reports. You may request earlier deletion at the address below. Email-provider backups and deletion processes are governed by the provider's own procedures.
  • Advertising, consent, and payments: Google manages the data it receives under its own policies and retention rules. Deleting the App, resetting an advertising ID, or buying ad removal does not automatically delete previously collected Google data.

11. Your privacy rights

Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, obtain a copy of your data, or opt out of certain sharing. These may include rights under EU/UK GDPR and California CCPA/CPRA.

For information you sent to Naruworks, contact us to exercise those rights. We may ask for information reasonably needed to verify that the request concerns your correspondence. We do not sell your support correspondence or VPN profiles.

Google's advertising processing may be treated as sharing for behavioral advertising under some laws. To limit this, you can use Privacy options in the App (when shown), Android's advertising ID controls, and Google's own privacy settings. Deleting the advertising ID or buying ad removal does not erase earlier data or, on its own, exercise your privacy rights. For data held by Google, see the request mechanisms in the Google Privacy Policy. Contact your VPN or email provider about data it holds.

12. Changes to this policy

We will publish revisions with an updated date. Material changes to how the App handles information will also be described through an appropriate notice, such as the Google Play update description. If a change requires further notice or your consent, we will give that notice or ask for consent before the new processing begins. We will not treat continued use of the App as consent where consent is legally required.

13. Contact

Naruworks
Email: admin@naruworks.org

For questions, support correspondence, or privacy requests, contact this address. We aim to respond within 30 days, subject to any different deadline required by applicable law. Please send only information needed for your request.

L2TP VPN Client · org.naruworks.l2tpvpn · Naruworks · Last updated October 5, 2026