1. Scope
This Privacy Policy applies to the ASK VPN application, website, support channels, provisioning backend, and related VPN services operated by KHING HTET SAN COMPANY LIMITED.
KHING HTET SAN COMPANY LIMITED
19th Street, No. 106,
(2) Ward,
Mandalay
Myanmar [Burma]
94615127
admin@thanlar.com
2. Important Summary
- The app sends a
device_id, platform, app version, and build number for provisioning. The backend associates this data with a generated VPN username/profile, VPN configuration, entitlement, trial, and access-expiration records. - The app and provisioning backend do not use VPN activity for advertising, behavioral profiling, analytics, or cross-app tracking.
- The mobile provisioning record does not persist the source IP as identifiable VPN activity. Cloudflare, app stores, push providers, VPN infrastructure, and other network providers may process IP addresses for delivery and security under their own policies.
- The production app includes Firebase Core and Cloud Messaging (FCM) for push notifications. Firebase Analytics, Crashlytics, Performance Monitoring, App Check, and Remote Config are not bundled or used. Firebase initialization occurs only after acceptance of the current Terms, and notification delivery is subject to device permissions.
- You can request account or data deletion by emailing admin@thanlar.com.
3. Information We Collect
Account and VPN provisioning data
To create, identify, and manage VPN access, ASK VPN collects and stores:
- A generated ASK VPN username or profile ID.
- A
device_idgenerated or resolved by the app and used for provisioning, account/configuration assignment, access expiration, and abuse prevention. - App platform, app version, and build number sent with provisioning and update requests.
- VPN configuration fields such as subscription URI, VLESS URI, entitlement status, trial status, and expiry date.
- Local app preferences, such as language choice, cached VPN configuration, and expiry status.
Support and communication data
If you contact us, we may collect your email address, message content, support details, account/profile ID, screenshots, device information, and any other information you choose to provide.
Payment, subscription, and trial data
Apple App Store, Google Play, or another approved payment provider handles payment credentials for store or provider transactions. ASK VPN does not collect or store full payment card numbers or payment credentials. ASK VPN stores only operational records needed to provide access, such as payment status or reference where applicable, entitlement status, trial status, expiry dates, and support history.
VPN activity data we do not retain
The ASK VPN app and provisioning backend do not retain:
- Packet payloads or the content of websites, apps, messages, files, or other VPN traffic.
- Browsing history.
- DNS-query history.
- Traffic-destination history, including a persistent list of destination domains or IP addresses.
- Persistent VPN session or user-activity logs.
4. Firebase, Notifications, and Diagnostics
The production app includes Firebase Core and Firebase Cloud Messaging (FCM) only for push-notification functionality. Firebase Analytics, Crashlytics, Performance Monitoring, App Check, and Remote Config are not bundled or used. The app does not send VPN lifecycle events, browsing activity, DNS-query history, traffic destinations, or packet content to Firebase. Firebase services initialize only after acceptance of the current Terms.
Firebase Cloud Messaging and Apple push notifications
FCM, Firebase Installations, and Apple Push Notification service (APNs) process SDK-managed installation identifiers, notification tokens, delivery metadata, and diagnostic or other technical data needed to register and deliver notifications. Google's embedded SDK privacy manifests classify some unlinked delivery or diagnostic data under app functionality or analytics; ASK VPN does not send app-defined Analytics events. This SDK data is separate from the ASK provisioning identifier and VPN packet stream. The app does not upload FCM tokens to the ASK provisioning database.
You can control notification permissions in device settings. Google processes Firebase messaging data on Google-managed infrastructure, and Apple processes push delivery on Apple-managed infrastructure. Their retention and storage practices apply. ASK VPN's update and force-update policy is fetched from Cloudflare, not Firebase Remote Config.
5. VPN Connection and Network Data Handling
When connected, ASK VPN routes eligible internet traffic through the VPN except traffic excluded by configured routing rules. The default split-tunneling rules send matching TikTok, YouTube and Google domain connections directly over your normal network, where those services can see your real IP address. You can disable this domain bypass in Settings for the next connection; local-network and system exclusions still apply. VPN and network infrastructure process packets and connection metadata to forward traffic.
The app does not decrypt HTTPS payloads or retain application content. The tunnel processes limited protocol/domain metadata in memory only to make routing and split-tunneling decisions, including when optional domain bypass is off. The app and provisioning backend do not retain packet content, browsing history, DNS-query history, traffic-destination history, or persistent VPN session/activity logs.
On iOS, remote DNS queries use Cloudflare 1.1.1.1 DNS over HTTPS through the VPN proxy where applicable; the local resolver handles proxy-host and direct-outbound resolution. DNS and VPN infrastructure process queries or connection data under their own policies. ASK VPN cannot independently guarantee the logging or retention practices of remote VPN servers, DNS resolvers, hosting providers, ISPs, or other network infrastructure.
The first-party mobile provisioning code does not persist the source IP as identifiable VPN activity or attach it to the provisioning record. Cloudflare and other network providers necessarily process source IP addresses in network delivery, abuse-prevention, and security systems.
6. How We Use Information
We use information for the following purposes:
- Provide, operate, maintain, and secure the VPN service.
- Create and retrieve VPN profiles and configuration.
- Associate a device or account with an entitlement, plan, trial, or expiry date.
- Prevent abuse, duplicate entitlement misuse, fraud, or unauthorized access.
- Respond to support requests and deletion requests.
- Send service-related notices and push notifications where enabled.
- Improve app stability, performance, compatibility, and user experience.
- Comply with legal obligations, enforce our Terms and Conditions, and protect users, the service, and others.
ASK VPN does not sell personal information or use VPN activity for advertising, behavioral profiling, or cross-app tracking.
8. Data Storage, Retention, Security, and Deletion
ASK VPN stores account/provisioning records, such as device identifier, generated username/profile ID, VPN configuration, trial or access expiry, account assignment, and creation/update timestamps, for as long as needed to provide the VPN service, maintain account entitlements, prevent abuse, comply with legal obligations, and resolve disputes. New provisioning requests do not send device model or operating-system version.
Older provisioning records and secured operational backups can contain device model or operating-system information supplied by earlier app versions. New app versions do not send those fields. Legacy data is deleted or minimized through the applicable retention and migration process.
When data is no longer needed, we delete it or anonymize it within a reasonable period. Diagnostic data handled by Firebase, Cloudflare, Google, Apple, Google Play, hosting providers, or other processors may be retained according to those providers' retention settings and policies.
We use reasonable administrative, technical, and organizational safeguards, including HTTPS in transit for app/API communication and encryption or access controls where appropriate. No internet service can be guaranteed completely secure.
9. Your Rights, Account Deletion, and Data Deletion
Depending on your location, you may have rights to request access to your personal information, correction, deletion, restriction, portability, objection, or withdrawal of consent. You may also have the right to complain to a data protection authority.
How to request deletion
- Email admin@thanlar.com with the subject line "ASK VPN Data Deletion Request".
- Include your ASK VPN username/profile ID if available, your device type, and the email address you used to contact support.
- Do not send passwords, full payment card details, or sensitive personal documents unless we specifically request them through a secure process.
We may need to verify your identity or ownership of the account before processing deletion. We aim to respond within 30 days unless applicable law allows or requires a different period. Deleting account or provisioning data may disable VPN access, remove entitlement records, and prevent recovery of your configuration.
Some information may be retained after deletion if required for security, fraud prevention, legal compliance, tax/accounting, dispute resolution, backup integrity, or enforcement of our Terms and Conditions.
10. Children's Privacy
ASK VPN is not intended for children under 13 years old, or the minimum age required by applicable law in your country. We do not knowingly collect personal information from children. If you believe a child has provided personal information to ASK VPN, contact us and we will take reasonable steps to delete it.
11. International Processing
ASK VPN may process information in Myanmar [Burma] and in other countries where our providers, infrastructure, app stores, Firebase, Google, Cloudflare, or hosting services operate. Data protection laws in those countries may differ from the laws where you live.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we may provide notice in the app, on this website, by email, or through app store release notes where appropriate. The "Last updated" date shows when the latest version became effective.
13. Contact
For privacy questions, data requests, account deletion, or support, contact:
KHING HTET SAN COMPANY LIMITED
19th Street, No. 106,
(2) Ward,
Mandalay
Myanmar [Burma]
94615127
Email: admin@thanlar.com