Privacy Policy

Effective date: August 4, 2026. Last updated: August 4, 2026.

This Privacy Policy explains how the TonBo application, websites, and related VPN and network-acceleration services (collectively, the "Service") handle personal data. Please read it before using the Service. If you do not agree with it, do not use the Service.

Who we are and our roles

The TonBo iOS application is published by SpeedLinc Innovation International co., Limited (速聯創新國際有限公司), a company incorporated in Hong Kong ("SpeedLinc"). SpeedLinc is the primary data user or controller for personal data relating to TonBo user accounts, subscription administration, and application operations.

TonBo AI LLC, a Wyoming limited liability company, acts as an affiliated service operator that provides technical, network, and infrastructure support for TonBo. It processes personal data only on SpeedLinc's documented instructions, except where it is legally required to act as an independent controller. SpeedLinc and TonBo AI LLC are collectively referred to as "TonBo," "we," "us," or "our."

This Policy does not override the allocation of responsibility imposed by applicable law. If our operational arrangements change, we will update this Policy and clearly explain each party's role.

Our core no-logs commitment

TonBo does not log, retain, analyze, or sell your VPN browsing activity. We do not create logs that can identify what you do online, and we do not use VPN traffic for advertising, profiling, or cross-context behavioral tracking.

VPN data we do not collectDetails
Browsing and destination historyWebsites, apps, services, URLs, domains, destinations, or browsing history accessed through the VPN.
Communications contentMessages, files, requests, responses, or other content transmitted through the VPN tunnel.
DNS queriesDNS queries and resolution history sent through the VPN.
Identifiable connection logsWe do not retain source IP addresses, assigned VPN IP addresses, per-session start or end times, session duration, or combinations of these data that create a user activity profile.
Advertising tracking dataWe do not combine VPN data with third-party data for targeted advertising, advertising measurement, or data brokering.

Personal data we process

We follow data-minimization principles and process only limited data needed to operate the Service. An email address and essential account data are required to create and use an account; if you do not provide them, account creation or recovery may not be possible. Diagnostic data are voluntary.

CategoryExamplesPurpose
Account dataEmail address, internal account ID, account status, verification and recovery recordsRegistration, sign-in, recovery, support, security, and abuse prevention
Subscription and transaction dataPlan, subscription status, order or transaction identifier, amount, currency, and refund statusEntitlement verification, purchases and refunds, accounting, and fraud prevention; we do not store full payment-card numbers
Device and app dataRandom installation identifier, device type, operating system and app version, language, and number of enabled devicesDevice management, compatibility, security, subscription device limits, and support
Service-metering dataAggregate traffic volume without destinations, free-data balance, and aggregate node or route loadEnforcing free-data allowances, allocating network capacity, and maintaining performance; not reconstructing browsing activity
Transient network dataSource IP during connection handshake and country or region inferred from itEligibility and attack prevention; the source IP is processed in memory and not written to VPN activity logs
Diagnostic dataCrash logs, error codes, performance metrics, and device, OS, and app versionsTroubleshooting when you choose to send them or where system settings permit; designed to exclude browsing content and DNS history
Support dataMessages, attachments, contact details, and case recordsQuestions, complaints, refunds, privacy requests, and technical support
Website dataBrowser type, page requests, cookie preferences, and IP address processed by hosting or security servicesProviding and securing the website, preventing abuse, and remembering essential preferences; not creating VPN browsing records

Regional eligibility check

To comply with trade restrictions, sanctions requirements, and service-availability rules, the system reads the source IP during the connection handshake to determine the country or region. This check occurs instantly in memory. After the decision, we do not write the source IP to VPN activity logs or use it to track your activity. We may retain a result that does not contain the source IP, such as "allowed" or "denied" and a reason code, to protect the Service and demonstrate compliance.

Purposes and legal bases

We process personal data to perform our contract with you, including account creation, VPN connectivity, subscription entitlements, device management, support, and account deletion; to comply with legal obligations, including tax, accounting, sanctions, and valid legal process; for legitimate interests in security, fraud prevention, reliability, and network protection; and with consent for diagnostics, non-essential cookies, or other processing where consent is required. You may withdraw consent at any time without affecting processing already carried out lawfully.

Apple platform information

On Apple platforms, TonBo uses Apple's Network Extension/VPN interfaces to establish the encrypted tunnel. When a purchase is completed through the App Store, Apple processes the payment. We generally receive only subscription status, product information, transaction identifiers, and receipt-validation data, not full payment-card details. Apple processes data it obtains under its own privacy policy.

TonBo does not use VPN traffic for tracking, does not sell or share personal data for cross-context behavioral advertising, and does not access Apple's advertising identifier for advertising purposes. App privacy disclosures in App Store Connect must remain consistent with this Policy, the production code, and every third-party SDK.

Sharing and service providers

We do not sell, rent, or trade personal data. Because we do not collect VPN browsing content, destinations, or DNS history, we cannot provide those data to third parties. Account and operational data are disclosed only as needed to contracted providers, such as cloud and network infrastructure, account verification and email delivery, payment and subscription processing, customer-support ticketing, and crash diagnostics that you enable. Providers may process data only on our instructions and must provide protection equivalent to this Policy and applicable law.

Data may also be disclosed in limited circumstances: between SpeedLinc and TonBo AI LLC as necessary to operate the Service; to comply with law, a court order, or a lawful government request binding on the relevant entity; to protect users, the public, or the Service against fraud, attacks, or serious harm; or to a successor in a merger, acquisition, financing, reorganization, or asset transfer that assumes the obligations in this Policy. We do not create or retain VPN activity logs in anticipation of future requests.

International processing

TonBo operates across multiple countries and regions. Account, support, payment-reference, or technical operations data may be processed in Hong Kong, the United States, and other locations where our providers maintain facilities. Local laws may differ from those in your location. We use processing agreements, access restrictions, encryption, and other appropriate measures to require recipients to protect data under applicable law and this Policy. Where required, we use standard contractual clauses, consent, or another lawful transfer mechanism.

Retention and deletion

We retain personal data only as long as needed for the stated purposes or to comply with law, after which it is deleted or irreversibly anonymized. Backup copies are removed through normal rotation. The proposed production schedule below must remain aligned with the actual system configuration.

DataTypical retention period
Account dataFor the life of the account; generally deleted from live systems within 30 days after a completed deletion request, with backups rotating out within 90 days, unless law requires retention.
Subscription, accounting, and transaction dataFor the service and dispute period and as required by applicable tax, accounting, refund, or anti-fraud laws.
Device associations and aggregate usageFor the shortest period needed to enforce device limits, allowances, and security; generally deleted or anonymized within 30 days after account deletion.
Transient source IPIn memory only during the connection eligibility check; not written to VPN activity logs.
Diagnostic dataGenerally no more than 90 days, unless longer retention is needed to resolve a specific issue.
Support recordsGenerally deleted within 24 months after case closure; longer where needed for a dispute, refund, or legal obligation.
Website security logsGenerally no more than 30 days, unless longer retention is needed to investigate an attack, security incident, or legal obligation.

Security

We use technical and organizational measures proportionate to the risks, including encryption in transit, access controls, least-privilege permissions, credential protection, system updates, log minimization, provider review, and incident response. The VPN tunnel uses industry-standard encryption to protect data in transit. No system can be guaranteed absolutely secure. If a personal-data breach requires notification, we will notify affected users and regulators as required by applicable law.

Your choices, account deletion, and privacy rights

You may manage devices, diagnostic sharing, and other available privacy choices in TonBo. Where the App supports account creation, you may initiate permanent deletion in the App through Settings > Account > Delete Account. We may conduct reasonable identity verification. Deletion removes the account and associated personal data except limited records required by law or needed for an active refund or security investigation. Uninstalling the App, disabling it, or cancelling a subscription does not by itself delete the account.

Depending on your location and applicable law, you may have rights to access, obtain a copy of, correct, delete, or restrict personal data; object to certain processing; withdraw consent; receive portable data; and complain to a regulator. Hong Kong users may request access and correction under the Personal Data (Privacy) Ordinance. European Union or EEA users have relevant rights where the GDPR applies. California residents may have rights under the CCPA to know, access, delete, correct, limit the use of sensitive personal information, and opt out of sale or sharing, without discrimination for exercising those rights.

TonBo does not sell or share personal information as those terms are defined by the CCPA, and we will not provide a lower level of service because you exercise a privacy right. You may use an authorized agent, subject to reasonable verification of identity and authority.

How to submit a request

Submit a "Privacy Request" through Customer Support/Help Center in the TonBo App or contact us through the online support function at https://www.tonbovpn.com. State the request type, account email, and your country or region. Do not send passwords, full payment-card numbers, or unnecessary identity documents. We respond within the period required by applicable law; complex requests may be extended where permitted.

Children's privacy

The Service is not directed to children under 13 or a higher minimum age required by local law. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us through the channels above. After verification, we will take appropriate deletion steps.

Cookies, analytics, and third-party links

Our website may use cookies necessary for core functions, security, and preferences. Non-essential analytics or similar technologies are used only with consent where required. TonBo does not use VPN traffic for advertising analytics. The Service may link to third-party sites or services whose privacy practices are governed by their own policies.

Legal requests and business transactions

We disclose only the limited data we actually hold when presented with valid legal process binding on the relevant entity, or where law permits disclosure to address an emergency threat to life or safety. Where lawful, we review scope, challenge inappropriate requests, or notify users. Because we do not retain VPN browsing or connection activity logs, we generally have no such information to provide. In a business transaction, a successor must follow this Policy or notify you and obtain consent where required before materially changing the processing purpose.

Changes, language, and contact

We may update this Policy as our products, laws, or operations change. We will provide advance notice of material changes through the App, website, or another appropriate channel and update the date above. Unless immediate effect is required by law or user safety, material changes will not retroactively expand how we use existing data.

This Policy may be available in multiple languages. The versions are intended to be equivalent. If they conflict, the English version controls to the extent permitted by applicable law, without reducing any mandatory rights.

Controller: SpeedLinc Innovation International co., Limited (速聯創新國際有限公司), Hong Kong. Technical service operator: TonBo AI LLC, Wyoming, USA. Privacy request channels: Customer Support/Help Center in the TonBo App, or online support at https://www.tonbovpn.com.