Privacy Policy for TiYi

Last updated: 2026.9.14 · 简体中文

TiYi is a multi-protocol VPN client provided by Weigan Technology (Shenzhen) Co., Ltd. (hereinafter referred to as "we" or "us"). This Privacy Policy applies to TiYi on iOS, iPadOS, and macOS.

We attach great importance to the protection of your personal information and privacy. We will provide appropriate security measures for your personal information in accordance with legal requirements and industry-standard security practices.

This Privacy Policy works together with our User Agreement for TiYi.

TiYi is a VPN / proxy client that runs on your device and connects to nodes, remote configuration URLs, or enterprise VPN servers that you import yourself. We do not operate public VPN nodes and do not provide a traffic-relay service hosted by us. Profiles are stored primarily in the main app's local database. The compiled configuration used for the current connection, tunnel options, and some preferences are shared with the system Network Extension on the same device through an App Group. IKEv2 passwords are stored in the system Keychain. The Service currently does not integrate third-party advertising SDKs and does not offer in-app purchases or paid subscriptions.

1. How We Collect and Use Your Information

We will only use your personal information where we have a lawful basis to do so. Under applicable law, we may process your information based on lawful grounds such as your consent, where necessary to perform or enter into a contract with you, or where necessary to comply with legal obligations.

1.1 Profiles, nodes, and remote configuration URLs. You may import Shadowsocks, VMess, VLESS, Trojan, Hysteria / Hysteria2, TUIC, WireGuard, OpenVPN, Clash / sing-box configurations, or share links by pasting text, entering a remote configuration URL, importing a file, opening a configuration file from the system, using a URL scheme (such as ss, vmess, or vless), or (on iOS / iPadOS) scanning a QR code, subject to your actual build. The original configuration, parsed node list, remote configuration URL, expiry information, and the node you select are stored locally on your device so that the app can connect, switch nodes, and display profiles. The compiled configuration needed for the current connection may be written to the App Group for the Network Extension to read. When you import or refresh a remote configuration, the app requests the URL you provided and downloads the configuration. That request goes to the third party you specified, not to servers we operate. The request may include a client identifier (the current User-Agent may contain fields such as clash-meta/tiyi, subject to your actual build) so the provider can recognize the client type.

1.2 VPN connection, traffic routing, and DNS. After you authorize the system VPN / Network Extension, the Service may establish a packet tunnel or a system IKEv2 connection on your device and forward traffic according to the rule, global, or direct mode you choose. Web and app traffic inside the tunnel is forwarded by the operating system and the on-device engine to the node or VPN server you specified. Default configurations generated by the app for proxy connections may include third-party DNS resolver addresses (the current build may use 1.1.1.1, 223.5.5.5, or similar, subject to your actual build). A complete configuration you import yourself may also specify other DNS servers. During a connection, domain-name lookups may be sent to those resolvers, system DNS, or a node you configured. We do not record, store, or analyze your browsing content, access history, DNS queries, or full traffic logs on servers we operate, and we cannot view your browsing content from our servers.

1.3 IKEv2 credentials. If you add an IKEv2 profile, the username, server address, and identifiers are stored in the local profile; the password is written to the system Keychain and read by the system VPN API to establish the connection. We do not upload IKEv2 passwords to our servers.

1.4 Speed tests, latency checks, and traffic statistics. When you measure node latency in the app, the device makes a short TCP connection attempt to that node's host and port. Configurations generated by the app for proxy connections may also include an automatic urltest outbound that periodically probes the speed-test URL you configured (the default may be a public connectivity-check address such as https://www.gstatic.com/generate_204, which you can change in Settings). That request is typically sent through the relevant node and is handled by the connectivity-check provider under its own policies. Upload/download byte counts are calculated by the on-device Network Extension, shown in the app, and stored locally.

1.5 Diagnostic logs. During a connection, the local engine and Network Extension may generate diagnostic logs (such as connection status and error messages) so the app can show why a connection failed. Logs remain on your device. We do not automatically upload them to our servers.

1.6 Camera and clipboard (on your action). On iOS / iPadOS, after you grant camera access, the Service may scan a node or remote-configuration QR code and parse only the code you point at. When you tap Paste from Clipboard, the app reads the current clipboard text to import a configuration. We do not read or upload clipboard content in the background.

1.7 File import. When you choose to import a local file (such as `.json`, `.yaml`, `.yml`, `.ovpn`, `.conf`, or `.txt`), the app reads the configuration text from the file you selected. This read happens only after you choose the file. The content is stored locally on your device.

1.8 Update checks and review prompts (where applicable). The app may query Apple App Store public APIs to see whether an update is available, or use the system review-prompt capability. Those requests are handled by Apple. We do not collect payment credentials or advertising identifiers as a result.

1.9 What we do not do. We do not require you to create an in-app account operated by us. We currently do not integrate third-party advertising or user-behavior analytics SDKs such as Firebase, Umeng, Pangle, or AdMob, and we do not offer in-app purchases, paid subscriptions, or cloud account sync operated by us. We do not enable VPN without your authorization, do not request photo library, contacts, microphone, location, Bluetooth, or other sensitive permissions unrelated to core connectivity (subject to your actual build), and do not upload your profiles, credentials, or internet content to our servers.

1.10 Personal information inventory. To meet applicable privacy laws and app-store compliance requirements, we disclose below the categories of personal information that TiYi may involve. The purpose, method, and scope described for each category apply only to the versions or scenarios noted. Categories marked as "not collected" mean that our app does not actively collect, read, or upload that type of information for the stated purpose.

2. Third-Party Services

This section describes third-party services that the Service may involve. Actual capabilities may differ by operating-system version.

2.1 Apple services (iOS / iPadOS / macOS)

The Service uses Apple's Network Extension (Packet Tunnel), system VPN (including IKEv2), Keychain, and App Groups, as well as optional camera, local network, App Store update lookup, and system review prompts (StoreKit). VPN configurations are stored by the system and managed in system Settings. In-app purchase is not currently used. Related processing is governed by Apple's policies.
Apple privacy policy: https://www.apple.com/legal/privacy/

2.2 Nodes, remote-configuration sources, DNS, and speed-test addresses

When you import or refresh a remote configuration, connect to a node, resolve a domain name, or run a speed test, network requests are sent to third-party servers you provide or select, and to third-party DNS / connectivity-check addresses in the app's default configuration (the current build may include 1.1.1.1, 223.5.5.5, and https://www.gstatic.com/generate_204, subject to your actual build). Those services are operated by the relevant providers. We cannot control their logging, retention, or privacy practices. Confirm that a source is trustworthy before importing it, and read that provider's terms and privacy policy.

2.3 Operating-system capabilities and the on-device engine

The Service uses an on-device VPN / proxy engine in the Network Extension to process profiles you import, and uses operating-system capabilities for local storage, Keychain, networking, file picking, camera, and UI rendering. Except for necessary requests to third parties you specify or to Apple, we do not upload your profiles, credentials, or internet content to cloud servers we operate. The current version does not provide cloud sync operated by us. If a future version enables iCloud or other sync, we will update this Policy as required by law.

3. Paid Features and Commercialization

The current version of TiYi does not offer in-app purchases, paid subscriptions, or ad-based unlocks. If a future version introduces paid features or advertising, we will update this Privacy Policy and the User Agreement as required by law and obtain your consent where necessary.

4. Device Permission Usage

TiYi requests permissions only as needed for VPN connectivity, profile import, and speed testing. We ask for your consent through the system permission dialog or system-settings guidance. Permissions you deny will limit only the related features. Permissions are described by platform below.

iOS / iPadOS

VPN / Network Extension

Used to install and enable a packet tunnel or system IKEv2 configuration so the app can connect through nodes you import. Connection is not possible without this authorization.

Camera

Used to scan node or remote-configuration QR codes. You can still import profiles by paste, URL, or file if this permission is denied.

Local Network

Used for node latency checks and local-proxy related communication.

Internet

Used to import or refresh remote configurations, run speed tests, resolve domain names, check for App Store updates, and connect to nodes you specify.

Clipboard (on-demand read)

Read only when you tap paste-to-import.

Files (user-selected)

Used to read a local configuration file after you choose it and import its contents.

macOS

VPN / Network Extension, local network, internet, clipboard paste, and file import are used for the same purposes described above. The current macOS build does not provide camera QR scanning; you can import profiles by paste, remote configuration URL, or file.

You can disable VPN, withdraw camera or local-network access, or uninstall the app at any time in system Settings to stop related processing.

5. Managing Your Personal Information

Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal information, and to data portability where applicable.

You can stop processing and remove locally stored profiles, preferences, and logs by deleting profiles in the app, removing the VPN configuration in system Settings, uninstalling the app, or clearing app data. IKEv2 passwords are removed from the Keychain when the corresponding profile is deleted. For information processed by Apple or by a node, remote-configuration, DNS, or speed-test provider you specify, you may also exercise choices through that provider's settings and policies.

To exercise rights relating to data we control, contact us using the details in Section 7. We will respond within a reasonable time as required by applicable law.

6. Information Storage Location and Retention Period

6.1 Profiles, node lists, routing preferences, traffic statistics, and diagnostic logs you generate through the app are handled and stored primarily on your device. The compiled configuration needed for the current connection and some preferences may be shared with the Network Extension through an App Group. IKEv2 passwords are stored in the system Keychain. The current version does not provide cloud sync operated by us.

6.2 Remote-configuration refresh, DNS resolution, speed tests, and tunnel traffic occur between your device and the relevant third parties. Update-check requests are processed by Apple according to Apple's policies and infrastructure, which may involve servers outside your country of residence.

6.3 We retain information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required by law. After you uninstall the app, delete a profile, or clear data, corresponding local information is deleted, but VPN preferences already written to the system, and requests already sent to third parties, remain subject to those system or third-party mechanisms.

7. How to Contact Us

You may contact us through the following methods to exercise your relevant rights. We will respond as soon as possible.

Email: weigantechnology@outlook.com

If you are not satisfied with our response, especially where applicable law grants you additional remedies, you may lodge a complaint with a data protection authority in your country or region. You may also seek resolution through a court of competent jurisdiction where permitted by law.

Effective date: 2026.9.14