This policy covers the Berrynook app and the auth-server account. It is the Privacy Policy URL for the Berrynook app on the App Store / Play. Cloud file content and Berryporch calls have their own policies on this host.
Last updated: August 12, 2026
| Product | What it is | Policy |
|---|---|---|
| Berrynook VPN | Encrypted tunnel in the Berrynook app, plus the auth-server account | Privacy · AUP |
| Berrynook Cloud | Private browser workspace at berrynook.cc (VPN required in production) | Privacy · Terms |
| Berryporch | Short 1:1 browser calls at meet.berrynook.cc | Privacy · AUP |
Berrynook provides encrypted VPN connectivity for Prepaid Pass and team invite accounts, plus the auth-server account used to sign in, bill, and provision Cloud. You must be 18 or older and use a Proton sign-in address. We collect the minimum account and operational data needed to authenticate you, provision credentials, and keep the fleet healthy. We do not log VPN traffic content, DNS queries, or browsing history.
The native app (iPhone and Mac) talks to our auth server and, when you connect, to the VPN. It does not upload Cloud file contents — those live on berrynook.cc in the browser (see Cloud Privacy). Berryporch guest email and OTP live on this auth server (see Berryporch Privacy).
| Category | Examples | Purpose |
|---|---|---|
| Account | Proton email, account number, Pass expiry | Sign-in, billing, support |
| Authentication | Recovery/password hashes, token hashes | Secure login and sessions |
| VPN credentials | Credential UUID, device name, exit region | Tunnel routing |
| Preferences | Split-tunnel policy (optional) | Your routing choices |
| Billing | Stripe session metadata (no card numbers on the auth server) | Prepaid time |
| Browser-login tickets | One-time POST /v1/cloud/browser-login tickets to open Cloud in the browser | Sign you into the workspace without storing the Cloud password on the device; VPN-gated; short-lived |
| Share-upload tickets | One-time POST /v1/cloud/upload-ticket tokens | Let the app hand a file to Cloud; VPN-gated; short-lived |
| Berryporch session metadata | Guest email, session times, OTP/token hashes (hosts) | Operate invites and abuse prevention — see Berryporch Privacy |
| Operational | Redacted API logs, rate limits | Security and uptime |
| Client diagnostics (optional) | Live connection log, session log | Troubleshooting; device memory only |
We do not store websites you visit, connection destinations, traffic payload, or plaintext recovery codes.
Extra team Host storage is not offered to the public yet. Public plans are Pass 5 and Pass 80 only.
The controller is Gray Whale and Blue Heron Co., British Columbia, Canada.
Privacy and support: help@berrynook.cc (Berrynook Help Desk). Abuse and security: abuse@berrynook.cc (Berrynook Security Desk).
Berrynook accounts are for adults 18 years of age or older. You must also use a Proton sign-in address that you are allowed to hold under Proton’s terms. We do not offer Berrynook accounts for minors.
berrynook.cc (VPN in production) — Cloud PrivacyVPN exits: No traffic content logs, no session logs mapping accounts to destinations.
Live connection log (optional, VPN home): Shows per-flow routing while connected. Session log (optional): App and VPN tunnel events while enabled. Both are off by default, kept only in memory on your device, not written to disk, and not uploaded to our servers. We only receive log content if you copy a diagnostic report and email help@berrynook.cc. Enable only while troubleshooting.
| Data | Retention |
|---|---|
| Expired bootstrap, refresh, one-time tokens, and Cloud tickets | Purged daily; 24 hours after expiry (tickets are shorter) |
| Account after deletion request | Via delete-account: keep prepaid (14-day comeback) or full erasure. VPN credentials revoked on confirm; full erasure completed by ops — target within 30 days after confirmed full-erasure path (unless legal hold) |
| Berryporch auth-server session metadata | Kept for security/abuse; deleted when the host auth-server account is deleted, or earlier on request when feasible. No product archive of call content |
| Billing / Stripe metadata on the auth server | While the account is active and up to 7 years after the last payment event for tax/accounting, or until full erasure when you choose to delete payment records. Card data never stored on the auth server |
| Operational / redacted API logs | Up to 90 days unless investigating abuse |
Account export: contact help@berrynook.cc.
Account data for the auth server is stored in the United States. Entry nodes are in Japan. Exit nodes are in the United States and Germany. If you access the service from elsewhere, your data is processed in these locations. Contact help@berrynook.cc for privacy rights requests.
Infrastructure hosting provider, Proton Mail (email), Stripe (payments), Let's Encrypt / Caddy (TLS).
Request access, correction, or deletion via help@berrynook.cc or delete your VPN and auth-server account. You may keep prepaid pass time for a comeback window or delete payment records for full erasure. Re-authentication required. Cloud files are not deleted by that form — see Cloud Privacy.
Report abuse to abuse@berrynook.cc.