Privacy Policy
Last updated: September 2, 2026
The short version: Mole has no backend, no user accounts, no analytics, and no ad SDKs. We do not collect, receive, or transmit any personal data. Everything you configure — server profiles, subscription links, routing rules, settings — is stored only on your own device.
Mole ("the app", "we") is a free, open Xray-core proxy/VPN client for Android, Windows, macOS and Linux. It is a client, not a VPN service: it does not operate any servers of its own. You connect it to a server or subscription you already have — your own server, or one from a provider you choose. This policy explains what that means for your data.
Data we collect
None. Mole does not require or offer account creation, does not use analytics or crash-reporting SDKs, does not show ads, and has no server of its own to send data to. There is nothing for us to collect.
What's stored on your device
The following is saved locally in the app's private storage on your device only, and is never transmitted to us:
- Server profiles and subscription links you add
- Routing rules and per-app split-tunneling choices
- App settings and preferences
- Connection logs shown in the in-app log viewer (for your own troubleshooting)
Uninstalling the app removes this data. Nothing is backed up to us because we have nowhere to back it up to.
Network connections the app makes
- Your configured server(s). When you connect, traffic is tunneled directly between your device and the server you configured. We are not in that path and cannot see it.
- Your subscription link(s). If you add a subscription URL, the app fetches it — either when you tap refresh, or periodically in the background — from the provider you chose, to update your server list. This request goes to that provider, not to us.
- Public routing-rule updates. The app can fetch publicly published domain/IP routing rule sets to keep ad-blocking and routing behavior current. These requests carry no personal identifiers.
Because your traffic and your subscription both go to servers and providers you chose yourself, their privacy also depends on that server operator's or provider's own policy — review it separately.
Permissions (Android)
INTERNET,ACCESS_NETWORK_STATE,CHANGE_NETWORK_STATE— required to establish the proxy/VPN tunnel.android.net.VpnService(VPN permission) — required by Android to route device traffic through the tunnel you start.FOREGROUND_SERVICE,FOREGROUND_SERVICE_SPECIAL_USE,POST_NOTIFICATIONS— Android requires an active VPN to run as a foreground service with a visible status notification while connected.WAKE_LOCK— keeps the tunnel forwarding traffic while the screen is off, instead of being suspended by Doze.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS— optional, only requested if you choose to exempt the app from battery optimization so a long-lived connection isn't killed in the background.CAMERA— used only to scan a QR code containing a server config when you choose to. No photo or video is stored or leaves your device.QUERY_ALL_PACKAGES— lets the per-app split-tunneling screen list your installed apps so you can pick which ones use the tunnel. That list is read and used on your device only; it is never transmitted anywhere.
Children's privacy
Mole is not directed at children and is not knowingly used to collect data from anyone — because it does not collect data from anyone, regardless of age.
Changes to this policy
If this policy changes, the update will be posted on this page with a new "last updated" date.
Contact
Questions about this policy or the app: reach us on Telegram at t.me/moletunnel.