Privacy Policy
This policy applies to the YamYam VPN Android app (package com.yamyam.vpn) and supporting VPN and control services. YamYam VPN operates the service. Email [email protected] with privacy questions or data requests.
Updated:
At a glance
- After Android VPN permission, device traffic travels to a selected endpoint. That endpoint necessarily processes connection metadata and packets needed to forward requests.
- We create an app-scoped, pseudonymous device record for access, quotas and abuse prevention. You do not provide a name, phone number or email to start.
- The control database does not intentionally store page contents, messages or per-site browsing history. This does not make you anonymous to a destination or endpoint operator.
- When ads are enabled, Google Mobile Ads and its consent platform may process IP address, ad/device identifiers, interactions and diagnostics under their own notices.
Data we process
| Data | Purpose and recipients |
|---|---|
| Device identifier | An identifier derived from Android ID and package name is unique to this app. A server-side hash, public device ID and route credentials support registration, authentication, quotas and abuse prevention. We do not request IMEI or SIM identifiers. |
| Device and usage details | Device model, Android and app versions, language, time zone, selected route, connection state, timestamps, quota, errors and ad events support compatibility, support and operations. They go to YamYam control systems and authorised administrators. |
| Traffic and DNS | The endpoint processes packets, destinations, timing and DNS requests as needed to route traffic. Destinations receive traffic you send. While connected, DNS questions travel through the encrypted tunnel to a YamYam relay and onward to public resolvers without your IP. The app requests no GPS or location permission. |
| Advertising | Google Mobile Ads/UMP may process IP, advertising identifiers, interactions, consent and technical diagnostics for delivery, measurement and fraud prevention. In-app ad choices are available where required. |
| Crash and error reports | Error type and stack trace, app/Android version, device model, processor, language, memory, connection state and recent app logs may be recorded. IP and email addresses, tokens, passwords and VPN credentials are removed on-device; reports contain no visited sites, traffic contents or DNS questions. Reports are sent with the device record for troubleshooting and can be turned off at Settings → Send crash reports. |
| Local data | Language, favourites, selected route and mode, reduced motion, consent, bounded unsent events and encrypted session/catalog data stay on the device. Clearing app data removes them. |
| Split tunneling | The app reads names and icons of launchable apps so you can choose bypasses. App choices and site rules stay on the device and are never sent to YamYam or third parties. |
Sharing and retention
Necessary data is shared with YamYam infrastructure processors; advertising data is shared with Google and its partners as needed for ads. We may disclose limited information for a valid legal obligation or to protect the service. We do not sell personal data.
Detailed operational events and crash reports are normally removed after 30 days. Daily aggregates, device metadata, quota and active route information remain while the record is active or until deletion. Expired sessions are cleaned up; database backups normally rotate out after more than 14 days. Independent services may have different retention.
Your choices and deletion
VPN access starts only after you approve Android’s permission; you can disconnect or revoke it. Turn off crash reports, reset the advertising ID or clear local data. Uninstalling does not by itself delete server records. For access, correction or deletion, email the public device ID shown in Settings to [email protected]. We may ask for proof of control. After verification, live records and route credentials are removed; rotating backups expire normally.
Security, children and changes
API requests use HTTPS, device-to-endpoint traffic uses an encrypted tunnel, and session data on the device is encrypted. No system can be guaranteed completely secure. YamYam is not designed for children. We update this policy when features, providers or law change and will surface material changes in the app where required.