1. Scope
This Privacy Policy applies to ASK VPN, a virtual private network application and related backend services operated by KHING HTET SAN COMPANY LIMITED. The business details below are placeholders supplied for publication and must be confirmed before relying on this policy as final company information:
KHING HTET SAN COMPANY LIMITED
19th Street, No. 106,
(2) Ward,
Mandalay
Myanmar [Burma]
94615127
admin@thanlar.com
This policy is intended to support Google Play Store and Apple App Store review by clearly describing the data practices of the ASK VPN app and associated services. It does not replace legal advice for your jurisdiction.
2. Important Summary
- The ASK VPN app and first-party configuration API collect a device identifier, generated VPN username, device model, operating system information, and VPN entitlement/configuration status needed to provide the service.
- The app is designed so the first-party app/backend does not collect, inspect, or store the content of your internet traffic, browsing history, or DNS query history.
- The app/backend does not intentionally store your public IP address as part of the VPN account record. Cloudflare, Google, Firebase, app stores, VPN infrastructure, and other service providers may process IP addresses in transient logs, security systems, or network delivery systems.
- Firebase Analytics, Crashlytics, Performance Monitoring, App Check, Remote Config, and Firebase Cloud Messaging may be included in the app. Store-safe builds may disable some or all telemetry at runtime; observability builds may enable it.
- You can request account or data deletion by emailing admin@thanlar.com.
3. Information We Collect
Account and VPN provisioning data
To create, identify, and manage VPN access, ASK VPN may collect and store:
- A generated ASK VPN username or profile ID.
- A device identifier generated or resolved by the app, such as a platform device identifier where available.
- Device model, device name, operating system, and platform version.
- VPN configuration fields such as subscription URI, VLESS URI, entitlement status, and expiry date. Sensitive VPN configuration fields may be encrypted in the backend and decrypted by the app when needed.
- Local app preferences, such as language choice, cached VPN configuration, and expiry status.
Support and communication data
If you contact us, we may collect your email address, message content, support details, account/profile ID, screenshots, device information, and any other information you choose to provide.
Payment, subscription, and trial data
Where ASK VPN offers paid access, free trials, or subscriptions, payment may be handled by Apple App Store, Google Play, or another payment provider. ASK VPN should not collect full card numbers or payment credentials inside the app unless a properly disclosed payment processor is added. We may keep records of entitlement status, expiry dates, and support history needed to provide service.
Information we do not intentionally collect in the first-party app/backend
Based on the current app and first-party backend behavior reviewed for this deployment, ASK VPN does not intentionally collect or store:
- The content of websites, apps, messages, files, or other traffic sent through the VPN tunnel.
- Browsing history.
- DNS request history as user activity logs.
- A persistent record of destination websites or destination IP addresses visited through the VPN.
4. Google Sign-In, Firebase, Analytics, Crashlytics, Push Notifications, and Diagnostics
ASK VPN may use Google and Firebase services. The exact data collected depends on the app build, user settings, platform settings, and services enabled by the operator.
Google Sign-In
If Google Sign-In is enabled, we may receive basic Google account information needed to authenticate you, such as your Google account identifier, email address, display name, and profile image. We use this information for sign-in, account recovery, entitlement association, fraud prevention, and support. If Google Sign-In is not enabled in the shipped app build, this section describes possible future or optional functionality and should be updated before release.
Firebase Analytics
If enabled, Firebase Analytics may collect app events such as app open, language changes, update prompts, notification interactions, VPN connect requested, VPN connect succeeded, VPN connect failed, and VPN disconnected. These events are used to understand app reliability and improve the product. Analytics events should not include traffic content, browsing history, or DNS query contents.
Firebase Crashlytics
If enabled, Crashlytics may collect crash logs, stack traces, non-fatal error reports, app version, build number, platform, device model, OS version, and a user or profile identifier if configured. We use this information to diagnose and fix app stability issues.
Firebase Performance Monitoring
If enabled, Firebase Performance Monitoring may collect performance metrics such as app startup timing, network timing, device characteristics, and other diagnostic measurements. These metrics are used to improve speed and reliability.
Firebase Cloud Messaging and push notifications
If push notifications are enabled, Firebase Cloud Messaging may process push tokens, message delivery metadata, notification permission status, and notification interaction events. Push notifications may be used for account status, service updates, support, security, or product messages. You can control notification permissions through your device settings.
Firebase App Check and Remote Config
If enabled, Firebase App Check helps protect backend resources from abuse, and Firebase Remote Config may be used to deliver configuration such as update requirements or feature settings. These services may process device/app identifiers and technical metadata.
5. VPN Connection and Network Data Handling
ASK VPN routes internet traffic through a VPN tunnel when you connect. To make a VPN work, your device sends network packets to VPN infrastructure, and the VPN infrastructure forwards traffic to the internet. This means network operators and infrastructure providers may technically process connection metadata needed to transmit data, secure the service, prevent abuse, and maintain reliability.
The ASK VPN app and first-party configuration backend are designed not to inspect or store traffic content, browsing history, or DNS query history. The app may display local traffic counters, connection status, logs, or diagnostic messages on your device to show whether the VPN is connected and to help troubleshoot failures. These local diagnostics are not the same as a server-side browsing log.
We do not intentionally store your public IP address in the first-party account/provisioning database. However, IP addresses may be processed by Cloudflare, Google Apps Script, Firebase, Apple, Google Play, hosting providers, VPN server providers, anti-abuse systems, security logs, and standard internet infrastructure. If ASK VPN later enables persistent VPN server connection logs, this policy and store disclosures must be updated before release.
6. How We Use Information
We use information for the following purposes:
- Provide, operate, maintain, and secure the VPN service.
- Create and retrieve VPN profiles and configuration.
- Associate a device or account with an entitlement, plan, trial, or expiry date.
- Prevent abuse, duplicate entitlement misuse, fraud, or unauthorized access.
- Respond to support requests and deletion requests.
- Send service-related notices and push notifications where enabled.
- Improve app stability, performance, compatibility, and user experience.
- Comply with legal obligations, enforce our Terms and Conditions, and protect users, the service, and others.
We do not sell your personal information.
8. Data Storage, Retention, Security, and Deletion
ASK VPN stores account/provisioning records, such as device identifier, generated username, device model, operating system, VPN configuration, expiry date, and creation date, for as long as needed to provide the VPN service, maintain account entitlements, prevent abuse, comply with legal obligations, and resolve disputes.
When data is no longer needed, we delete it or anonymize it within a reasonable period. Diagnostic data handled by Firebase, Cloudflare, Google, Apple, Google Play, hosting providers, or other processors may be retained according to those providers' retention settings and policies.
We use reasonable administrative, technical, and organizational safeguards, including HTTPS in transit for app/API communication and encryption or access controls where appropriate. No internet service can be guaranteed completely secure.
9. Your Rights, Account Deletion, and Data Deletion
Depending on your location, you may have rights to request access to your personal information, correction, deletion, restriction, portability, objection, or withdrawal of consent. You may also have the right to complain to a data protection authority.
How to request deletion
- Email admin@thanlar.com with the subject line "ASK VPN Data Deletion Request".
- Include your ASK VPN username/profile ID if available, your device type, and the email address or Google account used for sign-in if applicable.
- Do not send passwords, full payment card details, or sensitive personal documents unless we specifically request them through a secure process.
We may need to verify your identity or ownership of the account before processing deletion. We aim to respond within 30 days unless applicable law allows or requires a different period. Deleting account or provisioning data may disable VPN access, remove entitlement records, and prevent recovery of your configuration.
Some information may be retained after deletion if required for security, fraud prevention, legal compliance, tax/accounting, dispute resolution, backup integrity, or enforcement of our Terms and Conditions.
10. Children's Privacy
ASK VPN is not intended for children under 13 years old, or the minimum age required by applicable law in your country. We do not knowingly collect personal information from children. If you believe a child has provided personal information to ASK VPN, contact us and we will take reasonable steps to delete it.
11. International Processing
ASK VPN may process information in Myanmar [Burma] and in other countries where our providers, infrastructure, app stores, Firebase, Google, Cloudflare, or hosting services operate. Data protection laws in those countries may differ from the laws where you live.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we may provide notice in the app, on this website, by email, or through app store release notes where appropriate. The "Last updated" date shows when the latest version became effective.
13. Contact
For privacy questions, data requests, account deletion, or support, contact:
KHING HTET SAN COMPANY LIMITED
19th Street, No. 106,
(2) Ward,
Mandalay
Myanmar [Burma]
94615127
Email: admin@thanlar.com