CipherShift

Privacy Policy

Last updated: August 28, 2026

Who Operates CipherShift

CipherShift is operated by Crackthump Pty Ltd, a company registered in Australia, which is the data controller for the information described here. Privacy questions: support@ciphershiftvpn.com.

We Do Not Sell or Disclose Your Data

CipherShift does not sell, share, or disclose any user data to third parties for any purpose.

We do not sell personal information. We do not share it for advertising, marketing, profiling, analytics resale, data brokerage or any other commercial purpose. We do not disclose it to data brokers, advertising networks or affiliates. We do not use your data to build advertising profiles, and we do not share it with any parent, subsidiary or related entity.

There are exactly two exceptions, and neither is a sale or a disclosure for anyone else's benefit. The service providers named below process data solely on our written instructions in order to run the service, and are contractually required to protect it to the same standard set out in this policy and to use it for no other purpose. Separately, we would disclose data if compelled by a valid legal order under Australian law, which no privacy policy can override.

What Zero Logging Means

We do not log your VPN traffic. Specifically, the CipherShift VPN data plane does not record:

  • Browsing history or the websites and services you visit
  • Traffic destinations, whether by IP address or hostname
  • DNS queries
  • The contents of your traffic or communications
  • Connection timestamps tied to your activity, and no record that links a session to what was done during it

Separately from your VPN traffic, running an account requires some data. We describe every category we collect in the next section. Both statements are true at once: we hold no record of what you do through the tunnel, and we do hold the limited account information needed to give you a server, keep your subscription working.

What We Collect

These are the only categories of data the CipherShift app collects. They match the data types declared in our App Store privacy disclosure and the app's privacy manifest.

  • Email address. Used as your account identity, to authenticate you and to provision your own private server against your account. We use it to send account, security and service messages. Held by the CipherShift backend, operated by Crackthump Pty Ltd.
  • Purchase history. Your subscription state, plan and renewal status, which determine what your account is entitled to. Processed by RevenueCat on our behalf. Card numbers never reach us: payment is handled by Apple, Google or the payment processor you buy through.

That is the complete list. We run no analytics and no crash reporting: the app sends us no record of which screens you open, what you tap or how you use it, and no diagnostic or crash reports. There is no analytics setting to turn off, because there is nothing collecting.

We do not collect your name, postal address, phone number, contacts, photos, precise location, health data or advertising identifiers. We do not use tracking as defined by Apple's App Tracking Transparency framework, and we do not link your data to third-party data for advertising purposes.

We Do Not Track You

There is no analytics in the CipherShift app. No product analytics, no crash reporting, no advertising or attribution SDK, no session recording, no behavioural profiling. We do not measure which screens you visit, which features you use or how often you connect. There is no consent prompt and no opt-out, because there is nothing to consent to or opt out of.

Service Providers We Use

These providers process data strictly on our instructions, under contract, and only for the purpose listed. None of them is permitted to use your data for their own purposes, and none of them receives your VPN traffic.

  • RevenueCat. Subscription and entitlement management. Receives purchase history and an account identifier.
  • Cloudflare. Hosting and protection for this website only. It does not carry VPN traffic.

Your Own Private Server

CipherShift provisions your own private server for your account rather than placing you in a shared exit pool. Sensitive VPN configuration is held in memory rather than written to disk, and the data plane is configured without traffic, DNS or destination logging.

Where the app offers a stealth transport, it carries your VPN connection as Shadowsocks over WebSocket on port 443, so it resembles ordinary encrypted web traffic. This makes the connection harder to identify on restrictive networks. It is not a guarantee of undetectability, and we do not claim it cannot be blocked.

How Long We Keep Data

Start from what does not exist. There is no record of anything you did through the VPN: no browsing history, no destinations, no DNS queries, no traffic contents, no connection logs, no bandwidth records tied to activity. None of it is written down, so none of it can be kept, handed over, subpoenaed or leaked. A retention period only applies to something that was recorded in the first place.

What does exist is the small amount of account data needed to run a subscription, and it is kept only as long as the account:

  • Email address and account record: kept while your account is open, then deleted within 30 days of account deletion.
  • Purchase history: kept while your account is open. After deletion, transaction records are retained for seven years where Australian tax and corporate record-keeping law requires it, and are not used for any other purpose.
  • Your private server: destroyed when your subscription ends or you delete your account. Its keys and configuration lived in memory rather than on disk, and are gone with it. Nothing about it is archived, imaged or backed up.

We keep no analytics, no crash reports, no behavioural profile, no advertising identifiers and no shadow copy of a deleted account. When it is gone it is gone.

Deleting Your Account

You can delete your account and its data from inside the app. Open CipherShift, tap the menu icon on the home screen, and choose Delete Account. You will be asked to confirm. This is a real deletion, not a deactivation. Step-by-step instructions are at ciphershiftvpn.com/delete-account.

When you delete your account we destroy your private server, revoke your sessions and keys, erase your email address and account record, and instruct RevenueCat to delete the data it holds for you. This completes within 30 days. The only thing that survives is the transaction record described above, where law requires us to keep it.

If you would rather not use the in-app flow, email support@ciphershiftvpn.com from your account address and we will carry out the same deletion.

Your Rights

You may request a copy of the personal information we hold about you, ask us to correct anything inaccurate, request deletion of your data, or withdraw any consent you previously gave. The fastest route to deletion is in the app, from the home screen menu, then Delete Account. Otherwise email support@ciphershiftvpn.com from your account address. We respond within 30 days and do not charge for these requests.

If you are unhappy with how we have handled a privacy matter, tell us first at support@ciphershiftvpn.com. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Legal Requests

If we receive a valid legal order, we can produce only what we actually hold, which is the account data described in this policy. Because we do not log VPN traffic, we have no browsing history, destinations, DNS queries or traffic contents to produce. We maintain a warrant canary and will signal through it if the circumstances covered by its statement change.

Jurisdiction and Governing Law

Crackthump Pty Ltd is established in Australia, and this policy is governed by Australian law. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Your account data is held in Australia. Your private server runs in the region you pick, which affects speed and which local services you can reach, and it holds no record of your activity to store anywhere. Where any personal information is handled outside Australia, we require it to be protected to a standard consistent with the Australian Privacy Principles.

Children

CipherShift is for adults. Our terms require account holders to be at least 18, the service is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact support@ciphershiftvpn.com and we will delete it.

Changes to This Policy

If we change this policy we will update the date at the top of this page, and for changes that affect how we handle your data we will notify you in the app or by email before the change takes effect.

Contact

Crackthump Pty Ltd, Australia. Privacy enquiries and requests: support@ciphershiftvpn.com.