Legal & Privacy Framework

Privacy Policy & Data Protection Agreement

Last Updated: August 2026 • Document ID: P-4029-A

Entity
ShadowSurf Browser
Data Fiduciary
ShadowSurf Technologies
Effective
August 2026
Frameworks
GDPR • CCPA • DPDP

01. Introduction & Scope

Welcome to ShadowSurf Browser & VPN ("ShadowSurf", "We", "Us", or "Our"). This Privacy Policy governs the collection, processing, storage, and transfer of data when you utilize the ShadowSurf mobile application ("App").

By accessing, downloading, or utilising ShadowSurf, you explicitly consent to the data practices outlined in this Agreement. We operate under the principle of Data Minimisation and strictly align with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Digital Personal Data Protection Act (DPDP Act, India).

02. Core VPN functionality & The "Zero-Logs" Policy

ShadowSurf utilises the Android VpnService API to provide core privacy features, including our encrypted tunnel and native ad-blocking (Sinkhole). We strictly adhere to a Zero-Logs policy regarding this service.

  • No Traffic Logging: We do not monitor, intercept, record, or store your browsing history, HTTP/HTTPS traffic, or payload content.
  • No DNS Logging: DNS requests are resolved securely and never logged.
  • No IP Logging: We do not retain your originating IP address beyond the necessary duration of an active cryptographic handshake.

Compliance Note: The VpnService is used exclusively for secure data routing and local ad-blocking. It is not used to collect personal information or track user activity across other applications.

03. Legal Basis for Processing (GDPR & DPDP Compliance)

Where we process any personal data, we rely on the following lawful bases:

  • Contractual Necessity: To deliver the VPN and premium browser services you requested (e.g., authenticating your Premium License via email).
  • Legitimate Interest: To protect our infrastructure from abuse, DDoS attacks, and fraudulent activity (e.g., maintaining temporary compliance logs).
  • Explicit Consent: For features like Crash Diagnostics or Third-Party AI integrations. You may withdraw this consent at any time via App Settings.

04. Data We Do Collect (And Why)

To maintain infrastructural security and fulfil customer support obligations, we process the absolute minimum data required:

Account Details (Premium)

If you create a Shadow ID, we collect your email address securely via Google Firebase Authentication for subscription validation. Payments are handled via secure third-party gateways; we never see your credit card details.

Compliance Logs

To prevent automated abuse, we generate a localized compliance log upon account creation containing the registered email, timestamp, and device model. This is strictly separated from your browsing activity.

Support Communications

In-app support chat transcripts are securely retained for technical troubleshooting and quality assurance, linked only to a random device identifier.

Crash Diagnostics (Opt-In)

Subject to explicit consent, we utilize Google Firebase Crashlytics to transmit anonymous crash logs to facilitate bug resolution. This can be disabled at any time.

05. Data Retention & Automated Deletion

We do not hoard data. Our retention policies are aggressive and automated:

  • Account Deletion: Upon initiating account deletion in the app, your Firebase Auth record, email, and associated compliance logs are irrevocably wiped within 30 days.
  • Support Logs: Anonymous support chat histories are subjected to automated cryptographic erasure after 3 years, or immediately upon user request.
  • VPN Handshakes: Connection handshakes are held in volatile RAM and destroyed instantly upon session termination or server reboot.

06. Third-Party Service Providers

To provide specific features, ShadowSurf integrates with audited third-party providers:

  • Shadow AI (Google Gemini API): When explicitly invoked, text prompts and necessary contextual data are transmitted via TLS encryption to Google for natural language processing. Users must not submit PII, financial, or health data to the AI interface.
  • Advertising (Google AdMob - Free Tier Only): Users on the Free Tier may see interstitial advertisements. Google AdMob may process non-personally identifiable identifiers (like the Android Advertising ID) to serve ads. Premium users are entirely exempt from advertising.

07. Device Permissions

The App requests hardware permissions exclusively for explicit, user-initiated actions. We do not use permissions for background surveillance.

Camera
Local execution for QR/Barcode decoding only.
Microphone
Local execution via Android SpeechRecognizer for voice-input.
Storage/Media
To write downloads to disk or read user-selected files.
Notifications
To surface critical foreground service alerts (VPN status).

08. Your Global Privacy Rights

Depending on your jurisdiction, you are entitled to statutory rights regarding your personal data. We honor the following rights globally:

  • Right to Access & Portability
  • Right to Erasure (Right to be Forgotten): Request permanent deletion of your account and support history.
  • Right to Rectification
  • Do Not Sell My Personal Information (CCPA): We categorically DO NOT sell, rent, or lease your personal information to data brokers. You may opt-out of targeted advertising by disabling AdMob tracking in your device settings.

09. Children's Privacy (COPPA Compliance)

ShadowSurf is not intended for or directed at children under the age of 13 (or 16 in specific European jurisdictions). We do not knowingly collect personal information from minors. If we discover that we have inadvertently collected data from a child, we will promptly delete it. If you believe we hold such data, please contact us immediately.

The Warrant Canary

Status: ALIVE

A warrant canary is a method by which a service provider informs users that they have not been served with a secret government subpoena. As of August 4, 2026:

  • > ShadowSurf Technologies has NOT received any National Security Letters.
  • > ShadowSurf Technologies has NOT been subject to any gag orders.
  • > ShadowSurf Technologies has NOT been forced to compromise our encryption keys or install backdoors.

If this section is ever removed from our Privacy Policy, assume our network has been compromised.

10. Governing Law & Updates

We are registered in Maharashtra, India. This policy is governed by the laws of India, and any disputes fall under the jurisdiction of competent courts in Wardha, Maharashtra. We reserve the right to modify this policy; significant changes will be communicated via in-app notifications.

11. Contact the Data Fiduciary

To exercise any of your privacy rights, request data deletion, or for legal inquiries, please contact our Data Protection Officer through the integrated Support Chat or via email:

shadowsurf.app@gmail.com