LASTAPOLLO Get the app

Subscription proxy client — iPhone · iPad · Apple TV

One pad.
One tap.

LastApollo is a subscription-based setup and connection tool for a service you already pay for. Paste a subscription URL — or a site code, if that is what your provider hands out — and you are configured in one step. Either way you land on the same screen: a launchpad, and nothing else to learn.

01 Ground rules 01/06

Notice — read before use

We don't run the network.
You bring it.

What LastApollo is

An app on your device

It reads the configuration your provider issues, builds the tunnel locally with Apple's Network Extension framework, and shows you the state of it. That's the entire job.

What it isn't

A network service

LastApollo builds, owns, and operates no servers and no nodes, and it ships with none preconfigured. Every node, subscription, and quota belongs to the provider you chose — LastApollo neither sells them nor sees inside them.

Choosing a provider is your call, and so is staying inside the laws and terms that apply to you.

02 Get in 02/06

Two ways through the door.

The first screen is a single field, labeled “Site code or subscription URL”. What you paste into it decides the path.

Site code or subscription URL
ANo account
Paste a subscription URL

Paste the link your provider issued into the field. LastApollo fetches and parses that list on the spot and takes you straight to the pad — no account, no sign-in, no password. Plan and traffic show up only if your provider reports them.

No steps. No password. No account.

BIf your provider issues accounts
Site code

Some providers hand out a short code instead of a link. LastApollo looks it up on your device, inside a small directory file, and finds the right endpoint. The code itself never reaches us.

Sign in

Sign in with the account that provider issued. Your password is never written to the device — only the session token that comes back, kept in the system Keychain and marked device-only.

Launch

The pad appears. Tap it.

The pad

03 The deck 03/06

Four surfaces.
That's the whole app.

No tab bar, no dashboard, no settings maze. One home screen and three places you can go from it.

The pad

Home screen

The app opens to a single screen. A pixel launchpad sits in the middle with three unmistakable states — idle, connecting, connected — and a live timer once you're up. A chip above the pad names the node you're on. Your plan and traffic sit at the bottom when your provider reports them. Support and Settings share one compact row at the top. That's it.

The nodes

Tap the chip

Tap the chip to see every node your subscription includes. Run a latency test on demand and each node reports its measured round-trip in milliseconds, with signal bars to match. Don't want to think about it? Pick Auto — LastApollo measures first, then connects you to the fastest node that answered. The test is held while you're connected, because the numbers would be distorted.

The route

Under the pad

Two chips under the pad. Rule mode keeps local destinations on your direct connection and sends the rest through your node. Global mode sends everything through the node. Add your own entries by domain, keyword, or IP range, each marked direct or proxied — yours are matched from the top down, ahead of the built-in list. A set of advanced routing options is there for special setups. Routing changes take effect on your next connection, and the app says so when one is needed.

The panel

Settings

Settings, in four short groups. Turn on Always On and the connection comes back by itself whenever the network does. Choose Light, Dark, or Auto. Read the app in English, 简体中文, or 繁體中文 — it follows your system language and switches instantly in place, no restart. A diagnostic log stays on the device for troubleshooting. Support opens without leaving the app. And Reset puts everything back to the first screen.

04 Devices 04/06

Same subscription. Three screens.

iPhone

iOS 16 or later

One column, one thumb, one pad.

iPad

iOS 16 or later

The reading column is held to a comfortable width instead of stretching edge to edge. Turn it landscape and the home screen splits into two columns.

Apple TV

tvOS 17 or later

Import a subscription URL — a nearby iPhone can type it in for you — or enter a site code, and the remote takes over: a segmented tab bar across the top — Connect, Nodes, Settings — and a focus grid of nodes instead of a list. Dark only, drawn for the couch.

Apple TV runs the core loop on purpose: get set up, pick a node, connect. Custom routing, the light theme, and the rest of the iPhone panel aren't there — that's the design, not a gap.

05 Privacy 05/06

The whole ledger.

Not a promise — a list. Here is everything that leaves this device, everything that stays, and everything that never gets written down in the first place.

Out

Leaves the device

A subscription URL is fetched straight from your provider over HTTPS to pull the node list — on that path it is the only request the app makes, and it goes nowhere near us. Where your provider issues an account instead, your email and password go to their endpoint, once, to sign you in, and any support ticket you write goes to them too, under their policy. Looking up a site code downloads one small directory file from our storage — the lookup itself happens on your device, so the code never reaches us, but fetching that file shows the storage host your IP address, the same as any web request.

Held

Stays on the device

Your node configuration, your selected node, your custom routing entries, and the diagnostic log. Your subscription URL — plus the session token and account email, where a provider issues those — lives in the system Keychain alongside the keys the app needs to talk to your provider, marked device-only so none of it is ever copied to iCloud or restored onto another device. Cached configuration and any external credentials you enter yourself are encrypted with AES-GCM.

Nothing

Never exists

We do not inspect, log, or transmit your network traffic, the sites you visit, or your DNS lookups. The tunnel is built locally by Apple's Network Extension and never passes through a server of ours — there isn't one. No advertising, no analytics, no tracking SDKs anywhere in the app. Nothing to sell, so nothing is ever sold, rented, or handed over.

Reset the app — or sign out, where you have a provider account — and the cached configuration, the tunnel config, the diagnostic log, and any session token all go with it. Delete your account from inside the app and the same sweep runs.

Read the full Privacy Policy

06 FAQ 06/06

Straight answers.

QuestionAnswer
I have a subscription link, not an account.
That is the shorter way in. Paste it into the field on the first screen and the app skips sign-in entirely: no account, no password, straight to the pad. Plan and traffic appear only if your provider reports them.
My provider gave me a site code instead.
Same field — the app tells the two apart on its own. A code comes with a provider account, so it asks you to sign in once before the pad. LastApollo doesn't sell plans, hand out codes, or run a store of any kind.
Do you run any servers?
No. LastApollo builds, owns, and operates none, and ships with none preconfigured. Every node belongs to the provider you chose.
Can the app see my traffic?
No. The tunnel is built on your device with Apple's Network Extension and never passes through us. We don't inspect or log your traffic, browsing, or DNS lookups. The full details are in the Privacy Policy.
Why is the diagnostic log nearly empty when everything is working?
On purpose. The log is kept at warning level so the addresses you connect to are never written down. You'll find failures in there, not a browsing history.
Which protocol does it speak?
Outbound connections use anytls.
Does switching routing modes take effect right away?
On your next connection. Switch Rule and Global while you're connected and the app tells you a reconnect is needed — same for custom routing entries and Always On.
What do I need?
An iPhone or iPad on iOS 16 or later, or an Apple TV on tvOS 17 or later. One App Store listing covers all three.
How do I delete my account?
Open Settings inside the app, go to your account, and choose “Delete Account”. You confirm with your login password; the app then signs you out and clears the account state it kept on the device.
What does it cost?
Whatever your provider charges. LastApollo has no in-app purchases and sells nothing — plans are bought from your provider, not from us.