This policy covers the Berrynook app and the auth-server account. It is the Privacy Policy URL for the Berrynook app on the App Store / Play. Cloud file content and Berryporch calls have their own policies on this host.

Berrynook — Privacy Policy

Last updated: August 12, 2026

How Berrynook products differ

ProductWhat it isPolicy
Berrynook VPN Encrypted tunnel in the Berrynook app, plus the auth-server account Privacy · AUP
Berrynook Cloud Private browser workspace at berrynook.cc (VPN required in production) Privacy · Terms
Berryporch Short 1:1 browser calls at meet.berrynook.cc Privacy · AUP

1. Overview

Berrynook provides encrypted VPN connectivity for Prepaid Pass and team invite accounts, plus the auth-server account used to sign in, bill, and provision Cloud. You must be 18 or older and use a Proton sign-in address. We collect the minimum account and operational data needed to authenticate you, provision credentials, and keep the fleet healthy. We do not log VPN traffic content, DNS queries, or browsing history.

2. What the Berrynook app processes

The native app (iPhone and Mac) talks to our auth server and, when you connect, to the VPN. It does not upload Cloud file contents — those live on berrynook.cc in the browser (see Cloud Privacy). Berryporch guest email and OTP live on this auth server (see Berryporch Privacy).

CategoryExamplesPurpose
AccountProton email, account number, Pass expirySign-in, billing, support
AuthenticationRecovery/password hashes, token hashesSecure login and sessions
VPN credentialsCredential UUID, device name, exit regionTunnel routing
PreferencesSplit-tunnel policy (optional)Your routing choices
BillingStripe session metadata (no card numbers on the auth server)Prepaid time
Browser-login ticketsOne-time POST /v1/cloud/browser-login tickets to open Cloud in the browserSign you into the workspace without storing the Cloud password on the device; VPN-gated; short-lived
Share-upload ticketsOne-time POST /v1/cloud/upload-ticket tokensLet the app hand a file to Cloud; VPN-gated; short-lived
Berryporch session metadataGuest email, session times, OTP/token hashes (hosts)Operate invites and abuse prevention — see Berryporch Privacy
OperationalRedacted API logs, rate limitsSecurity and uptime
Client diagnostics (optional)Live connection log, session logTroubleshooting; device memory only

We do not store websites you visit, connection destinations, traffic payload, or plaintext recovery codes.

Extra team Host storage is not offered to the public yet. Public plans are Pass 5 and Pass 80 only.

3. Controller

The controller is Gray Whale and Blue Heron Co., British Columbia, Canada.

Privacy and support: help@berrynook.cc (Berrynook Help Desk). Abuse and security: abuse@berrynook.cc (Berrynook Security Desk).

4. Eligibility

Berrynook accounts are for adults 18 years of age or older. You must also use a Proton sign-in address that you are allowed to hold under Proton’s terms. We do not offer Berrynook accounts for minors.

5. Where data lives

6. Logging and retention

VPN exits: No traffic content logs, no session logs mapping accounts to destinations.

Live connection log (optional, VPN home): Shows per-flow routing while connected. Session log (optional): App and VPN tunnel events while enabled. Both are off by default, kept only in memory on your device, not written to disk, and not uploaded to our servers. We only receive log content if you copy a diagnostic report and email help@berrynook.cc. Enable only while troubleshooting.

DataRetention
Expired bootstrap, refresh, one-time tokens, and Cloud ticketsPurged daily; 24 hours after expiry (tickets are shorter)
Account after deletion requestVia delete-account: keep prepaid (14-day comeback) or full erasure. VPN credentials revoked on confirm; full erasure completed by ops — target within 30 days after confirmed full-erasure path (unless legal hold)
Berryporch auth-server session metadataKept for security/abuse; deleted when the host auth-server account is deleted, or earlier on request when feasible. No product archive of call content
Billing / Stripe metadata on the auth serverWhile the account is active and up to 7 years after the last payment event for tax/accounting, or until full erasure when you choose to delete payment records. Card data never stored on the auth server
Operational / redacted API logsUp to 90 days unless investigating abuse

Account export: contact help@berrynook.cc.

7. International transfers

Account data for the auth server is stored in the United States. Entry nodes are in Japan. Exit nodes are in the United States and Germany. If you access the service from elsewhere, your data is processed in these locations. Contact help@berrynook.cc for privacy rights requests.

8. Subprocessors

Infrastructure hosting provider, Proton Mail (email), Stripe (payments), Let's Encrypt / Caddy (TLS).

9. Your rights

Request access, correction, or deletion via help@berrynook.cc or delete your VPN and auth-server account. You may keep prepaid pass time for a comeback window or delete payment records for full erasure. Re-authentication required. Cloud files are not deleted by that form — see Cloud Privacy.

10. Security

Report abuse to abuse@berrynook.cc.