SKYFOM VPN privacy policy
Updated: October 4, 2026. Developer and service operator: KODZIMA LLC (ООО «КОДЗИМА»).
1. Who we are and what this policy covers
This policy explains which data the SkyfomVPN app collects and processes when you use the SkyfomVPN service operated by KODZIMA LLC. For questions about data processing, contact the support chat: https://t.me/TheSCYFOMGuild.
2. No accounts — the app does not know who you are
You do not need a name, phone number, or email address to use the app. Your device is identified using a system identifier: ANDROID_ID on Android, MachineGuid on Windows, and IOPlatformUUID on macOS. It is sent to the server to provide VPN settings, plans, and limits, and it may persist after reinstalling the app. On platforms without a system identifier, a randomly generated code is used. You may optionally link your device to a Telegram profile using a code; the server then associates the device identifier with your Telegram profile and subscription. The device identifier used for VPN access is not shared with the advertising SDK.
3. What the server sees and stores
The server processes your device identifier, plan, access expiration, limits, and traffic usage, and, if you voluntarily link Telegram, the Telegram profile identifier and profile information. Payment records include the amount, order identifier, payment status, and crediting information. The VPN server receives your connection IP address and forwards network traffic to provide the service. The app does not send your list of installed applications; it uses that list locally for split tunneling. Your browsing history and traffic contents are not used by the app for advertising.
4. Connection logs stay on your device
The app keeps a log of the most recent connection attempt, available as “Connection log” in settings, to help troubleshoot connection issues. The log is stored locally, is not sent automatically, and is erased on the next connection attempt. It leaves the device only if you copy it and send it to support yourself.
5. The backup DNS channel
If the primary server that provides the server list is unavailable, for example because it is blocked, the app may request the current list through ordinary DNS queries. The data inside the request is encrypted, but network intermediaries, including your internet provider, can generally see that a DNS query occurred. The device identifier is not included in the query address. Instead, the app sends a derived code produced by a one-way cryptographic transformation, allowing the server to recognize a device without exposing the original identifier in the address. This channel is used only as a fallback when the primary method fails.
6. Advertising and the advertising identifier
The app includes the Yandex Mobile Ads SDK to show advertising banners on Android only. The banner is at the top of the main screen and is labeled as an advertisement; it does not obscure connection controls. No full-screen ads or videos are shown when connecting or disconnecting the VPN.
For ad selection, frequency limits, and effectiveness measurement, the SDK processes the advertising identifier (the Google Play advertising identifier, for which the app requests the AD_ID permission), device model, operating system and app versions, screen size, language, IP address, and ad impressions and clicks. The app itself does not analyze this information, build user profiles, or sell it to advertisers; the ad network selects the ad. Yandex describes its advertising services in the Yandex Advertising Network participation rules and its privacy policy. You can reset the advertising identifier and disable personalization in Google Play system settings. Ads will still appear but may be less relevant, and advertising revenue may decrease. Questions about processing or withdrawal of consent can be sent to support.
Advertising SDK requests go directly, outside the VPN tunnel, so the advertising network sees the device’s actual IP address rather than the VPN server’s address. This allows ads to be selected for your country rather than the server’s country. Other requests made by the app itself may also go directly to support service operation; this does not redirect traffic from other apps for advertising. The app’s built-in ad blocker does not apply to its own advertising banners: it blocks third-party advertising domains, not the app’s own ad units.
7. Third-party services
The SkyfomVPN server provides the list of connection servers. The app also uses an open IP geolocation database from the v2fly project on GitHub to display the country of a server. The database does not contain or receive information about individual users. To show the connection country after the tunnel is established, the app contacts Cloudflare’s public service at 1.1.1.1. It sees only the IP address in use at that time and receives no device identifier or plan data; the country is not stored. Ads are supplied by the Yandex Advertising Network (Yandex LLC), including third-party advertising networks. These networks receive information about ad impressions and clicks described in section 6, not the contents of websites you visit or your connection history.
8. Plan payments
Users of Google Play in Russia can pay through WATA. The app receives a payment-page link from the server and opens it in a browser. Card details are entered on the payment provider’s page; the app does not receive the card number, expiration date, or security code. The server processes the amount, order identifier, and payment status to credit the payment. To determine whether this payment option is available, the app requests the Google Play account country. It is not stored, sent to our server, or used for advertising. If Google Play does not confirm Russia, purchases are hidden in the Android app.
9. How to delete your data
Uninstalling the app clears its local data but does not delete the server’s device record or change the Android system identifier. To delete server data associated with a device or linked profile, submit a request at https://delete.skyfom.ru/ or contact support. You can copy the device identifier from your profile. The deletion page describes verification, processing times, and information retained to meet legal requirements. Payment records may be retained for mandatory accounting periods.
10. Changes to this policy
This policy may be updated as the app develops, for example when payment features are introduced. The date of the latest revision appears at the top of this page. Significant changes affecting the scope of data collection will be announced in the app.
11. Website support requests
The form at vpn.skyfom.ru sends your name, email, topic, and message for the support team to answer your request. Requests are delivered to support@skyfom.ru. Sent requests are kept on the website server for up to 30 days; emails may remain in the support mailbox to handle your request. If delivery temporarily fails, the request stays queued until it can be sent. Anti-spam measures include a one-time browser verification and rate limits. The rate-limit database stores a keyed code derived from the IP address instead of the IP address itself; rate-limit records are removed after one day. Do not include passwords or bank card details. Your consent to processing your request data is required before submission. To request deletion of support-request data, email support@skyfom.ru.