Back matter — Privacy
Privacy Policy
Last updated: August 2, 2026
LastApollo is a network proxy client for iPhone, iPad, and Apple TV. This policy explains what information the app handles, which services receive it, what stays on your device, and what you can do about it. LastApollo does not operate VPN relay or exit servers; the app contacts an activation directory, your chosen provider, and support services only as described below.
01 What We Handle
Making the app work takes a short list, and this is all of it:
- Account identifier
- The email address you sign in with, used to authenticate you against the provider you chose. If you set the app up with a subscription URL instead of a site code, there is no account and no sign-in at all, and this does not apply to you.
- Subscription URL and provider login
- A subscription URL is requested directly from the host named in that URL. If your provider uses accounts, your email address and password are sent to that provider to sign you in. Your password is not stored by the app; the session token returned by the provider is kept instead. A site code is not sent to the provider or to us — its separate lookup is described next.
- Activation lookup
- A site code is resolved on your device. The app downloads one small, static directory file from our storage bucket and looks the code up locally, so the code itself is never sent to us. As with any web request, the storage host receives your IP address and the LastApollo User-Agent, which identifies the app version, platform, and build.
- On-device data
- Your subscription configuration, the node you selected, your custom routing entries, and a diagnostic log for troubleshooting. The log is kept at warning level rather than recording every connection, but a failure entry may contain a technical address involved in that failure. This data stays on your device and leaves it only if you choose to copy or send it.
- Customer support
- On iPhone and iPad, online support uses the native Crisp SDK for a provider-operated support workspace. The app configures Crisp only after you explicitly agree and then open the chat. It does not send your provider login token, email address, account ID, or a Crisp Token ID to Crisp. Your provider and Crisp process the messages you send, your IP address, app/SDK and device-network technical information, an anonymous Crisp session identifier, and any photos or files you choose to attach. The attachment picker lets you select an item from Photos or Files; nothing is attached until you choose it. LastApollo does not receive or store support content on servers it operates. The relationship between LastApollo, your provider, and Crisp is explained in §05.
02 What We Do Not Collect
LastApollo does not send tunnel payloads, browsing history, a DNS-query history, location, hardware identifiers, or usage analytics to systems we operate. The on-device tunnel engine necessarily processes packets and DNS information to establish the connection and apply your routing rules, and warning-level diagnostic entries may record technical details of failures as described in §01. The app contains no advertising, attribution, analytics, or tracking SDK. On iPhone and iPad it does include the Crisp customer-support SDK, which is initialized only after the consent and user action described in §01; Crisp is not used for LastApollo analytics or advertising.
03 Why We Handle It
Everything in §01 serves app functionality: resolving your setup, authenticating with your provider, fetching configuration, opening the connection, and answering support requests you choose to submit. None of it is monetized. We run no advertising, marketing, behavioral analytics, or profiling against your data. We do not sell or rent personal data, or disclose it to data brokers or advertising networks. Functional disclosures are limited to the storage host, your chosen provider, and its support processor as described in this policy.
04 The Tunnel
LastApollo operates no VPN relay or exit servers and provides no network access of its own. It uses Apple's Network Extension framework to establish the connection locally, on your device. Depending on your routing rules, traffic either connects directly to its destination or travels through nodes operated by your chosen provider. Tunnel traffic does not pass through the activation directory or any VPN node we operate.
05 Your Provider
Your provider independently operates the account system, subscription endpoint, support workspace, and network nodes that you choose to use. For in-app online support, the provider controls its Crisp workspace and decides the support purpose, who may access conversations, and the applicable retention and deletion process. Crisp provides the third-party messaging platform and processes end-user support data for the provider. LastApollo controls when its app initializes the SDK and which account fields it does not send, but it does not operate the provider's workspace or receive support content on servers it operates.
This LastApollo policy explains the app integration and LastApollo's own handling. Your provider's privacy policy governs the provider's support operation, and the Crisp Privacy Statement describes Crisp's own processing and data-protection practices. Those policies apply to their respective activities and do not replace one another. Please read them before using online support.
06 Backups
If you enable device or iCloud backups, the app's on-device data may be included, according to your Apple settings. Items successfully stored in the system Keychain are marked device-only and are not copied to iCloud or restored onto a different device. Backups themselves are controlled by Apple and by your settings, and are outside our control.
07 Security
Your password is not written to persistent storage. It is sent to your provider when you sign in, and only the session token that comes back is kept. That token, your account email, subscription URL, and the key material the app needs to communicate with your provider are stored through the system Keychain and marked device-only when the Keychain write succeeds. Other sensitive data at rest is encrypted with AES-GCM: the cached node configuration, which contains the credentials your nodes need, and any external credentials you enter yourself. Account and provider API endpoints require HTTPS and use the system TLS checks. A subscription URL is contacted according to the URL you enter; use an HTTPS subscription URL so that request is protected by TLS. No method of storage or transmission is completely secure, and we do not claim otherwise.
08 Retention and Deletion
Signing out erases your session token and email from local credential storage, clears the cached subscription configuration, and, after the app safely disables any on-demand VPN rule, deletes the tunnel configuration and diagnostic logs written while you were signed in. If the system VPN preference cannot be safely updated, those tunnel files are retained instead of being deleted while an on-demand rule may still reference them.
If anything is left in the Keychain after a reinstall, the app clears it the next time it starts without a local setup, so a fresh install never begins signed in.
You can request account deletion from inside the app: open Settings, go to your account, and choose “Delete Account”. You confirm with your login password. When the provider reports that the request succeeded, the app signs you out and clears the account, activation, routing, cached configuration, tunnel files, and diagnostic logs it kept on the device, subject to the system VPN safety condition above. Server-side deletion and any legally required retention are handled by your chosen provider under their policy.
Support conversations and attachments are separate from your provider account and the app data described above. Signing out, resetting the app, deleting the provider account, or withdrawing support consent detaches the anonymous Crisp session on this device; none of those actions automatically deletes the remote conversation. Ask your provider through its published privacy contact channel to access or delete remote support data.
If an authorized provider operator deletes a conversation in the Crisp dashboard, the chat already displayed from the SDK's device-local state is not erased immediately. If you withdraw support consent, agree again, and reopen support after that remote deletion, the app starts a new anonymous conversation. This local display behavior is not evidence that the remote conversation still exists, just as losing access to a chat is not evidence that the remote copy was deleted.
09 Your Choices and Requests
Online support is optional. If you leave the disclosure screen or choose “Not Now”, the app does not configure Crisp. If you previously agreed, you can withdraw support consent from the Contact Support screen; this blocks future chat access and detaches the anonymous session on that device unless you agree again.
To delete a provider account, open Settings, go to your account, and choose “Delete Account”. For access to or deletion of provider account data or remote Crisp conversations and attachments, contact your provider through its published privacy channel. Withdrawing support consent or deleting the provider account does not itself delete the remote Crisp conversation.
For questions or requests about this LastApollo policy or information controlled by LastApollo, contact us using §12. LastApollo cannot provide a copy of support content it does not receive or store on servers it operates.
10 Children
LastApollo is not directed to children. If a child submits information to a provider or its support processor, that information is handled as described in §01 and §05. Contact the provider about data held in its account or support systems, or contact us with questions about this policy.
11 Changes
We may revise this policy from time to time. Any update is reflected in the date shown beneath the title above, and significant changes will be surfaced in the app or on this site where appropriate.
12 Contact
Questions about this policy: feedback@lastapollo.app