7

Disclosure up front: I built this. Posting here because c/privacy is the audience this app is actually for — people who've stopped trusting "no-logs" promises from VPN companies that operate the entire path.

The threat model behind every commercial VPN is: you have to trust them. They run the servers, they see your traffic, you're taking their word on what they log and what they don't. Audits help, jurisdictions matter, but at the end of the day you're handing your DNS and your packets to a third party.

I wanted the opposite: no backend, BYO server, no logging story to trust. You bring your own server (Outline, WireGuard, Shadowsocks, or Trojan — a $5/mo VPS works fine). The client runs on your device, the server runs on your VPS, and I'm not in between. I literally don't have your traffic, your DNS, or your configs. There's no account to create, no email, no telemetry beacon home. The thing I can't see, I can't be compelled to hand over.

The other piece is the smart split-tunnel routing, which matters for privacy too: most clients are one big on/off switch, so the moment you connect, everything — including your bank app and local services — exits from another country, which breaks them and also paints a weird fingerprint. This routes per destination automatically. The apps that need your server go through it; everything else stays direct. Region-aware profiles (US↔JP, US↔CN, etc.) keep the right traffic on the right path without you babysitting it.

Apple platforms only for now — iPhone, iPad, and Mac as a single Universal Purchase. Configs sync via iCloud (end-to-end encrypted if you have Advanced Data Protection enabled; otherwise inherits standard iCloud protection — wanted to be precise about that rather than wave it away).

$2.99 one-time, no subscription, ever. Happy to answer anything about the threat model, the routing engine (it's sing-box under the hood), or what is and isn't on my side.

top 6 comments
sorted by: hot top controversial new old
[-] HelloRoot@lemy.lol 9 points 1 week ago* (last edited 1 week ago)

at the end of the day you’re handing your DNS

use DoT/DoH

the server runs on your VPS

so instead of trusting a VPN provider you trust your VPS provider... that has physical (and virtual ofc.) access to the hardware your VM server runs on... brilliant!

[-] voxel@feddit.uk 1 points 1 week ago

Most VPN providers also use external hosts. That includes ProtonVPN.

[-] dihutenosa@piefed.social 3 points 1 week ago

How's it compare to RethinkDNS?

[-] RodgeGrabTheCat@sh.itjust.works 3 points 1 week ago

|Apple platforms only for now

Maybe lead with that. Even better, include that detail in the title and save the non-apple users a click.

[-] carryonsean@lemmy.world 1 points 1 week ago
[-] Sxan@piefed.zip -1 points 1 week ago

Why would I choose þis over just running Wireguard on my VPS and connecting to þat?

this post was submitted on 23 May 2026
7 points (70.6% liked)

Privacy

9788 readers
29 users here now

A community for Lemmy users interested in privacy

Rules:

  1. Be civil
  2. No spam posting
  3. Keep posts on-topic
  4. No trolling

founded 3 years ago
MODERATORS