Welcome to ShadowSurf Browser & VPN ("ShadowSurf", "We", "Us", or "Our"). This Privacy Policy and Data Protection Agreement governs the collection, processing, storage, and transfer of data when you utilize the ShadowSurf mobile application ("App"). We operate on a foundational principle of "Privacy by Design." This document is strictly aligned with international data protection frameworks, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Digital Personal Data Protection Act (DPDP Act, India).
By accessing, downloading, or utilizing ShadowSurf, you explicitly consent to the data practices outlined in this Agreement.
ShadowSurf operates a premium Virtual Private Network (VPN) infrastructure utilizing the highly secure WireGuard® cryptographic protocol. We strictly adhere to a Zero-Logs policy.
No Traffic Logging: We categorically do not monitor, intercept, record, or store your browsing history, HTTP/HTTPS traffic, payload content, or DNS queries.
No Connection Logging: We do not retain session timestamps, allocated bandwidth metrics, or connection duration logs on our servers.
No IP Logging: We do not record or retain your originating Internet Protocol (IP) address or the assigned VPN IP address beyond the strictly necessary duration of an active cryptographic handshake.
Our strict zero-log VPN infrastructure operates on isolated, encrypted virtual instances hosted by enterprise-grade cloud infrastructure providers (such as Amazon Web Services). While we retain 100% exclusive control over the cryptographic keys, server configurations, and routing logic, you acknowledge that by using a global VPN, encrypted data packets may traverse international borders (e.g., routing through servers in Singapore, the United States, etc.) to bypass regional restrictions. All transit data remains mathematically unreadable to our cloud providers.
To maintain infrastructural security, prevent malicious automated access, and fulfill customer support obligations, we process the absolute minimum data required.
4.1 Authentication & Cryptographic Identities If you choose to create a ShadowSurf Secure ID, we collect your email address and securely process an encrypted password hash utilizing Google Firebase Authentication. This data is strictly used for subscription validation and identity authorization.
4.2 Compliance and Anti-Abuse Logging To safeguard our network against DDoS attacks, brute-force attempts, and fraudulent account creations, we generate a localized compliance log upon account creation or successful login. This log contains:
The registered Email Address.
A Server-side Timestamp.
The specific Device Hardware Model (e.g., "Pixel 7"). We do not track, correlate, or append your post-login browsing activities to this compliance log.
4.3 Premium Support Chat & Data Retention When utilizing the in-app Premium Support Chat, your communications are linked to a randomly generated alphanumeric string known as the ANDROID_ID (this is independent of your IMEI or phone number).
Retention Period: For legal compliance, quality assurance, and ongoing technical troubleshooting, support chat transcripts are securely retained on our encrypted databases for a maximum period of three (3) years, after which they are subject to automated cryptographic erasure.
4.4 Telemetry and Crash Diagnostics (Opt-In) Subject to your explicit consent during the onboarding process, we utilize Google Firebase Crashlytics to transmit anonymous crash logs (stack traces, memory states) to facilitate rapid bug resolution.
ShadowSurf is engineered as a local-first browser. The vast majority of your data never leaves your physical device and remains inaccessible to our servers. This includes:
Browsing Artifacts: Local History, Cache, Cookies, Bookmarks, and active Session Tabs.
Secure Vault Data: Passwords, Payment Methods, Addresses, and Media securely downloaded to the isolated "Ghost Vault."
Tracker Metrics: Telemetry regarding blocked advertisements and bypassed fingerprinting attempts.
To provide state-of-the-art features, ShadowSurf integrates with audited third-party service providers. By using specific features, you consent to data processing by these entities:
6.1 Shadow AI (Google Gemini API Integration) When you invoke the "Shadow AI" or "Page Ninja" functionalities, your explicit text prompts, alongside necessary contextual data (such as the active webpage URL, Title, and up to 5000 characters of parsed Document Object Model text), are securely transmitted via TLS encryption to the Google Gemini API for natural language processing. Users are strictly prohibited from submitting sensitive Personally Identifiable Information (PII), financial data, or protected health information (PHI) into the AI interface.
6.2 Image Generation (Pollinations AI) Text-to-image algorithmic requests are securely processed through the Pollinations AI API.
6.3 Advertising (Google AdMob) Users accessing the "Free Tier" VPN servers may be presented with Interstitial Advertisements. Google AdMob may process non-personally identifiable device identifiers (such as the Android Advertising ID) to serve contextual ads, adhering to Google's proprietary privacy frameworks.
6.4 Financial Processing (Google Play Billing) All fiat and subscription transactions are securely processed by the Google Play Billing Library. ShadowSurf does not intercept, process, or store raw Credit Card numbers or banking credentials.
ShadowSurf acts solely as a secure conduit to the internet. We do not control, endorse, monitor, or verify the content, privacy policies, or security practices of the third-party websites you visit through our browser. We are not liable for any phishing attempts, malware infections, data compromises, or financial losses incurred on external websites. Users browse the internet at their own risk.
We implement industry-standard AES-256 encryption, secure transport protocols (TLS 1.3), and strict access controls to safeguard your data. However, no digital system is impenetrable. In the highly unlikely event of a data breach affecting your ShadowSurf ID or Support Chat logs, we commit to notifying affected users within 72 hours of discovery, in strict accordance with GDPR and international data protection standards.
The App requests specific hardware permissions exclusively to facilitate explicit user actions:
Camera: Executed locally for QR/Barcode decoding.
Microphone: Executed locally via the native Android SpeechRecognizer for voice-input functionalities.
Storage/Media: Executed to write downloaded payloads to disk or read user-selected files.
Notifications: Executed to surface critical foreground service alerts and live VPN telemetry.
Depending on your jurisdiction, you are entitled to specific statutory rights regarding your data:
Right to Access & Portability: You may request a cryptographic export of the data associated with your ShadowSurf ID.
Right to Erasure (Right to be Forgotten): You may request the permanent deletion of your Account, Compliance Logs, and Support Chat history.
Do Not Sell My Personal Information (CCPA): We categorically DO NOT sell, rent, or lease your personal information to data brokers or third parties.
To exercise these rights, initiate a formal request via the in-app Premium Support Chat.
PLEASE READ THIS SECTION CAREFULLY AS IT AFFECTS YOUR LEGAL RIGHTS. Any dispute, claim, or controversy arising out of or relating to this Privacy Policy, the App, or the breach thereof, shall be determined by binding arbitration rather than in a court of general jurisdiction. You and ShadowSurf further agree that any arbitration shall be conducted in your individual capacity only, and not as a class action or other representative action.
This Privacy Policy and all matters relating to your use of ShadowSurf shall be governed by and construed in accordance with the laws of India. Specifically, any localized legal proceedings not subject to arbitration shall fall under the exclusive jurisdiction of the competent courts located in Wardha, Maharashtra, India.
For legal inquiries, data deletion requests, or compliance concerns, please contact our Data Protection Officer (DPO) via the integrated Support Chat within the ShadowSurf application.
for more support you can writes mail to us on "shadowsurf.app@gmail.com"