Privacy policy

Effective 12 September 2026

GoodWin VPN is a local client. This build has no Goodwin account server and no analytics SDK.

VPN

On platforms with a system tunnel, device traffic is sent to the node in the share link you imported. The app does not operate a Goodwin proxy. If this OS has no system tunnel, Connect only starts a local SOCKS proxy at 127.0.0.1:10808.

Configs and secrets

Share links, saved profiles, and subscription URLs are stored on the device, encrypted with AES-256-GCM. The encryption key lives in the OS keystore / keychain, not next to the ciphertext. If the platform keystore is unavailable, the app cannot keep those values encrypted.

Camera

The camera is used only to scan a QR code that contains a share link or a subscription URL. Frames are not uploaded.

Clipboard and backups

Copy JSON to clipboard writes an unencrypted backup. Anyone who can read the clipboard can read those links. File export can use an optional password (AES-256-GCM).

Installed apps (Android)

Per-app split tunneling reads the launcher app list on the device so you can exclude apps from the VPN. That list stays on the device.

Subscription refresh

When you import an HTTPS subscription URL, the app fetches that URL (User-Agent goodwin-vpn/1.0) to load share links and optional quota headers. The app does not send a Goodwin account identity.

Questions: contact the operator who gave you the subscription URL.