Eithel Android client

Privacy Policy

This policy explains how the Eithel Android application handles data on the device and distinguishes that client-side processing from the server-side practices of the organization or provider that supplies the connection profile and server key.

  • Effective: July 24, 2026
  • Version: 2026-07-24
  • Package: com.subbclub.eithel.vpn

1. Scope and roles

This policy applies only to the Eithel client application for Android 8.0 and newer, distributed under package identifier com.subbclub.eithel.vpn. It does not describe a universal Eithel server service, an iOS client, a desktop client, or the independent infrastructure selected through an imported connection profile.

Subbclub develops and publishes the Android client. The application does not operate a Subbclub application server that receives or stores users' personal data.

The organization, administrator, or service provider that supplies the server key and compatible connection profile is referred to in this policy as the Server-Key Provider. The Server-Key Provider determines the VPN endpoint and is responsible for any server-side collection, logging, storage, retention, disclosure, security measures, legal basis, and responses to data requests associated with that endpoint.

2. Local data stored by the Android client

Eithel stores the following information in the application's private storage on the Android device so that the client can establish and manage a connection:

Connection profiles

  • Profile name, connection address, remote public key, and client private key.
  • Virtual-interface addresses and settings.
  • Routes, DNS servers, MTU, keepalive, and reconnection parameters.
  • Routing-rule source addresses, signature-verification keys, and a cached verified ruleset.
  • Other technical values contained in a compatible imported profile.

The client private key is encrypted using AES-GCM. Its encryption key is generated and stored in Android Keystore. Other profile fields are held in the application's private database and are not represented as individually encrypted fields.

Settings and selected applications

Eithel reads the list of applications with launchable activities so that the user can configure per-app routing. The client stores package identifiers only for applications selected for inclusion or exclusion, together with the selected routing mode.

Theme, DNS, MTU, reconnection, restart recovery, energy-saving, logging, and connection-direction settings are also stored locally. The Android client does not transmit the installed or selected application list to a Subbclub analytics service.

Connection status and statistics

  • Total incoming and outgoing traffic per profile.
  • Last-used time and current connection status.
  • Assigned virtual address and technical active-session identifiers.

Local log and diagnostics

The application maintains a local technical log for connection events, profile import, network changes, and errors. Entries may contain the connection address, profile name, technical addresses, session identifiers, traffic sizes, an imported document name or URI, and error details.

The interface retains up to 500 recent entries and the log file is limited to the latest 2,000 lines. Detailed debug entries are added only when the user enables debug mode, while basic information, warnings, and errors may be recorded without debug mode.

A diagnostic file may include application and package versions, an active-profile summary, connection and virtual addresses, statistics, session identifiers, and up to 200 recent log entries. It is created and shared with another application only after the user chooses the system Share action. Eithel does not automatically upload diagnostic files.

3. Network traffic and DNS

When the VPN is active, Eithel processes IP packets from applications selected by the user or the active profile. Routing rules may evaluate destination addresses, networks, and domain names obtained from DNS requests. The client therefore has technical access to network destinations, transfer timing and volume, and DNS names while performing its core VPN function.

Traffic selected for the VPN is sent through an authenticated encrypted tunnel to the endpoint configured in the imported profile. Protection between that endpoint and the final destination depends on the destination protocol, such as HTTPS. Applications excluded from the VPN are handled directly by Android according to the selected routing mode.

The client may request updated routing rules from an address included in the imported profile or through the established connection. Profile providers should use HTTPS rule-source addresses. The security and behavior of these endpoints are controlled by the Server-Key Provider.

4. Data leaving the device

The following information may leave the Android device:

  1. Network traffic selected for the VPN, sent to the endpoint configured by the active profile.
  2. Technical requests for connection rules, sent to addresses contained in that profile.
  3. DNS requests, sent to the DNS provider selected by the profile or the user.
  4. A diagnostic file, sent only to a recipient selected by the user through Android's Share interface.

The checked Android client does not include a dedicated advertising SDK, Subbclub analytics SDK, or automatic crash-report upload SDK.

QR import uses Google Code Scanner from Google Play services. Google states that image processing occurs on the device and that Google does not store the image or scan result. Eithel receives the recognized text for profile import.

5. Server-side processing

Eithel does not store personal data on application servers operated by Subbclub.

Any storage or logging performed at the configured VPN endpoint is outside the Android client's local storage and is the responsibility of the Server-Key Provider that issued the server key and connection profile.

Users should obtain the Server-Key Provider's own privacy information before connecting. That provider must explain, as applicable, whether it stores source IP addresses, DNS requests, destinations, traffic metadata, account or profile identifiers, diagnostic information, or other server logs; why it processes them; where and for how long it stores them; who receives them; and how users can exercise applicable rights.

6. Android permissions and access

Permission or accessPurpose
VpnService / BIND_VPN_SERVICECreates the Android VPN interface after the user's system confirmation.
INTERNETEstablishes the VPN connection, obtains rules, and transfers selected traffic.
ACCESS_NETWORK_STATEDetects network availability and changes for reconnection.
Foreground service permissionsKeeps the VPN service operating while a connection is active.
POST_NOTIFICATIONSShows active foreground-service status where Android requires notification permission.
RECEIVE_BOOT_COMPLETEDRestores the VPN after restart or update only when the user enabled that setting and previously granted VPN permission.
Launcher-app visibilityDisplays launchable applications for include/exclude routing. Eithel does not request QUERY_ALL_PACKAGES.
Selected-document accessReads only a YAML file selected through Android's system file picker.
QR scanningUses Google Code Scanner; Eithel does not declare the CAMERA permission.
ClipboardReads clipboard content only after the user selects clipboard import.

The checked application manifest does not request location, contacts, microphone, phone-call, SMS, calendar, or broad photo/file access.

7. Security

  • Application data is held in Android private storage.
  • The profile private key is encrypted with a key held in Android Keystore.
  • The primary VPN connection uses authenticated encryption.
  • Downloaded routing rules are verified by digital signature before use.
  • Android application-data backup is disabled.
  • Diagnostic files are created in application cache and shared through a restricted FileProvider.

No security measure can guarantee absolute protection. Users must protect device access and obtain server-security information from their Server-Key Provider.

8. Retention and deletion

  • A profile, its statistics, and selected-app rules remain until the profile or application data is deleted.
  • Deleting a profile removes its database record, app-routing rules, and encrypted private key.
  • The current client may retain a separately cached signed ruleset after profile deletion.
  • The local log is limited to 2,000 lines and can be cleared from the log screen.
  • Temporary diagnostic files may remain in application cache until Android or the user clears it.
  • Copies shared or saved through another application are governed by that application's behavior and policy.
  • Clearing Eithel's application data or uninstalling Eithel removes its private local data under standard Android behavior.

Eithel does not provide an in-app account and therefore has no client account-deletion function. Requests concerning data stored by a VPN endpoint must be sent to the Server-Key Provider.

9. Children

Eithel is a technical networking utility and is not designed or marketed specifically for children. A Server-Key Provider may apply separate age, authorization, or organizational-use requirements to its service.

10. User choices and requests

Users can remove profiles, clear logs, clear application storage, uninstall the application, choose which applications use the VPN, select DNS settings, and decide whether to create or share diagnostics.

Questions about the Android client's local handling of data can be sent to [email protected]. Requests involving VPN-server logs, retention, access, correction, deletion, restriction, or disclosure must be addressed to the Server-Key Provider because Subbclub does not possess that server-side data through the Android client.

11. Third-party services and providers

The application may interact with Google Play services for QR scanning, the DNS provider selected by the profile or user, endpoints contained in the imported profile, and applications selected by the user for diagnostic sharing. Their processing is governed by their own terms and privacy information.

12. Changes to this policy

This policy may be updated when the Android client's features, dependencies, or data handling change. The effective date and version at the top of this page identify the current publication. Material client-side changes will be reflected on this page and, where appropriate, in the application or release information.

13. Publisher information

Application
Eithel for Android
Developer and publisher
Subbclub, operated by RATSIOSERVIS, TOO
Official domain
subbclub.com
Privacy contact
[email protected]