Back to home
PRIVACY POLICY

Privacy policy

How ValeFly handles account, device and network data, and the choices available to you.

Effective date: 2026-09-17 · ValeFly 1.0

Scope and service providers

The ValeFly app and valefly.com are operated by TECH HUB HOLDINGS LIMITED. This policy covers the client and website. Our privacy contact is [email protected].

ValeFly connects to the independent service site you choose. That site manages authentication, nodes, allowance and its own server records. Check the site name and read its policy before signing in. This policy does not replace an independent site's privacy policy.

Accounts and credentials

Your account name and password are sent over HTTPS to the selected service site for authentication. The client does not save your password. Sign-in tokens use the device Keychain; account, node and selection caches are encrypted locally to restore your session.

The app requests account status, available nodes, allowance and expiry from your service site. The site can associate these requests with your account.

To delete your current site account, enter its current password. It is sent directly over HTTPS to the selected site’s API to verify your identity and is not saved by the client. Do not send your password to support.

Network processing and recipients

The client processes destination domains, IP addresses and traffic locally to establish connections and apply routing rules. Your selected proxy node handles data required for forwarding. DNS services receive resolution requests. Nodes and DNS services depend on your site and configuration.

Initialization, rule downloads and latency tests generate network requests. Their recipients can see request source IPs. Latency tests use the HTTPS endpoint cp.cloudflare.com/generate_204 through the tested route. Live transfer rates are calculated locally.

ValeFly does not collect or retain VPN traffic content or browsing history, build user profiles, integrate advertising or cross-app tracking SDKs, or send device heartbeats. We do not sell personal data, use VPN data for advertising, profiling or other non-connection purposes, or disclose it to third parties for those purposes. Your chosen site and node process connection data needed to fulfil your request; this does not mean an independent provider keeps no server records.

Service checks you request

When you tap Check, the client sends HTTPS requests through the tested proxy route to ChatGPT, Claude, Gemini, YouTube, Netflix or Disney+ to assess regional support or availability. Smart mode uses a dedicated route assigned to that service, if any; otherwise the current route is used. The service and its network infrastructure can see the check request, generic request headers and the proxy's exit IP. The client does not send your service-site account, password or sign-in token to these services, or read your sign-in cookies for them.

The Disney+ check requests a temporary anonymous token using fixed, generic browser information, without your device's unique identifier. The token is used only for that check. Results contain the service, status, region, check time and duration. Only the latest result per service is kept in device memory; results are not saved as a history file or uploaded to ValeFly or your site. Node check information supplied by your site is separate and is cached locally with the node configuration.

Session usage and optional reminders

The device counts direct and proxied upload and download bytes for the current connection and estimates service categories from recognized domains. Unidentified traffic is shown separately. These estimates are not per-app activity records or your provider's bill. Classification does not retain domain lists, page contents or connection histories, and is not reported to a server. Usage totals stay in memory; the last sample may remain visible after disconnection and is cleared on sign-out. No history of connection summaries is saved.

Usage reminders are off by default. Enabling them saves your preferences and up to two threshold events for the current reminder session in protected local shared storage. Events contain site, account and session identifiers, the budget, aggregate proxy bytes, the 80% or 100% threshold and time, so the app and VPN extension can coordinate reminders. Events are replaced when the next reminder-enabled connection starts, and cleared when reminders are disabled, you sign out or switch sites, or account deletion completes. They have no daily archive and are not uploaded. iOS delivers notifications locally; notifications already shown may remain in Notification Center until you clear them.

Custom rules and local preferences

Custom website rules store the domain you enter, its matching scope and your direct or proxy choice. Pasted URLs retain only the domain, not the path or query. Rules, dedicated service routes and reminder preferences are held in the current account's protected local cache and VPN configuration for on-device routing and reminders, without backend synchronization. You can edit them in Settings; they are cleared on sign-out, a site switch or completed account deletion. Language and appearance preferences may remain.

Retention and security

Local sign-in credentials and account and node caches remain until sign-out or a site switch. Language preferences may remain to remember your choice. Account requests use HTTPS; credentials are protected with the device Keychain and encrypted local caches.

Support email and website technical logs currently have no fixed automatic deletion schedule. We assess retention by purpose: open requests and necessary follow-up require relevant correspondence, while troubleshooting or security incidents require related technical records. We delete or anonymize information when no longer needed for those purposes. Where law or an unresolved dispute requires retention, use is restricted to that purpose. Request access or deletion at [email protected]; we verify necessary details, process the request and explain any legally required retention. Independent sites control retention and deletion of their accounts, logs and backups.

Withdrawal and deletion

Disconnecting VPN stops forwarding. Signing out stops account sync and clears local sign-in credentials and account and node caches. You can also remove the VPN configuration in iOS Settings.

For sites that support in-app deletion, open Account → Delete account, check the current site and account, enter your current password and confirm permanent deletion. If the site has not implemented deletion, you cannot sign in, or you need access to or correction of other server records, use “Contact site support” in app help. Uninstalling the client or signing out does not delete your service account.

See Account & data deletion for clearing local data, deleting the current site account and asking ValeFly to delete support information. Support verifies necessary identity information and responds under applicable law. Do not send passwords, verification codes or node keys to support.

Website technical data

This website has no account registration, advertising scripts, analytics SDKs or forms collecting personal data. On first visit, the preferred browser language selects a supported language, falling back to English when none is supported. A manual language choice is stored only in this browser’s local storage to remember your preference, is not sent to the server, and does not use preference cookies.

The website uses Cloudflare for content delivery and security and a web server for static pages. These services may process source IP addresses, request times, browser information and technical logs to deliver pages and resolve faults. These records are not used for advertising or cross-site tracking. Website infrastructure may process technical data outside your country or region.

Support email and infrastructure services

When you contact [email protected], we process your sender address, message and attachments you choose to provide to reply, troubleshoot and handle privacy requests. Cloudflare Email Routing forwards messages to a Google-hosted support inbox. Those email services process information needed for delivery and storage. Do not send passwords, complete subscriptions or node keys.

App configuration, rule and DNS requests reach the services specified in the configuration, including Tencent Cloud configuration resources, rule-resource hosting, AliDNS or Cloudflare DNS, and Cloudflare's latency endpoint. Recipients see the domains, request information and source IP necessary to fulfil requests; proxied requests normally show the node's exit IP. Processing needed for pages, email, resolution and connectivity is separate from advertising or user tracking.

Contact and changes

TECH HUB HOLDINGS LIMITED handles privacy matters for the ValeFly client and website. Contact [email protected] with your request and a reply address. We verify necessary information and handle access, correction, deletion or restriction requests. Contact your independent site for its account and server records.

This policy takes effect on September 17, 2026. We update the website and in-app notice when purposes or recipients change. Where renewed consent is required, a choice is provided before that processing. You may stop using the service and use applicable data-protection complaint channels in your location.

[email protected]