Privacy Policy & VpnService Disclosures
This document outlines the privacy practices, data handling, and Android VpnService disclosures for the NetSense VPN Client application.
1. Overview & Scope
The NetSense VPN Client for Android is an enterprise virtual private network application designed to work in conjunction with NetSense security appliances, firewalls, and enterprise cloud network infrastructure. The primary purpose of the application is to provide secure, encrypted network connectivity for enterprise users connecting to their organization's internal infrastructure or secure cloud gateways.
NetSense Technologies Inc. ("NetSense", "we", "us", or "our") respects your privacy and is committed to protecting it through our compliance with this policy. This Privacy Policy applies exclusively to the NetSense VPN Client Android application.
2. Prominent VpnService Disclosure & Data Handling
In compliance with Google Play Developer Program Policies regarding the use of the Android VpnService API, we provide the following explicit disclosures:
Core Purpose: NetSense VPN Client utilizes Android's native android.net.VpnService API to construct a secure, device-level encrypted virtual tunnel to designated NetSense enterprise VPN gateways. Without the VpnService API, the application cannot perform its fundamental function of protecting enterprise data in transit.
Data Encryption in Transit: All network traffic passing through the established VPN tunnel is encrypted using enterprise-grade cryptography protocols (AES-256-GCM, ChaCha20-Poly1305, WireGuard®, or IPsec/IKEv2).
Zero Traffic Content Logging: NetSense VPN Client does NOT intercept, inspect, monitor, store, log, sell, or collect the contents of your web traffic, browsing history, DNS queries, web URLs, or payload data transmitted through the VpnService tunnel.
No Advertising & No Data Monetization: We do not use the VPN connection to serve advertisements, perform behavioral profiling, or monetize user activity.
Split Tunneling Behavior
Depending on your enterprise organization's IT policy, the NetSense VPN Client may operate in Full Tunnel mode (routing all device internet traffic through the secure enterprise gateway) or Split Tunnel mode (routing only traffic destined for designated enterprise corporate subnet IP ranges through the VPN). The routing configuration is managed by your organization's NetSense gateway administrator.
3. Information We Collect
To establish, authenticate, and maintain secure VPN connections with your organization's NetSense gateway, the NetSense VPN Client collects and processes limited metadata as described below:
| Data Category | Specific Items Collected | Purpose | Storage Location |
|---|---|---|---|
| Authentication Data | Usernames, SAML/OAuth tokens, client certificates, or API keys | To verify user authorization with the enterprise gateway | Secure Android Keystore (Encrypted) |
| Connection Metadata | Server gateway IP, connection timestamp, session duration, bytes transferred | To maintain connection state and display connection diagnostics | Local device memory / Enterprise Admin Server |
| Device & OS Info | Android OS version, app version, device model, local IP address | To ensure gateway compatibility and troubleshoot tunnel stability | Ephemeral (In Memory) |
4. Data We DO NOT Collect
We adhere to a strict policy of minimal data collection. NetSense VPN Client does NOT collect or store any of the following:
- User browsing history or websites visited.
- DNS query content (unless directed to your organization's private enterprise DNS server).
- Unencrypted packet contents or network traffic payloads.
- Personal identifiers like phone numbers, contacts, emails, or personal media files.
- Real-time GPS location data.
- Advertising IDs or cross-app tracking identifiers.
5. Android Device Permissions
NetSense VPN Client requests only the minimal Android permissions necessary to function safely:
| Android Permission | Technical Name | Reason Required |
|---|---|---|
| VPN Connection | android.permission.BIND_VPN_SERVICE |
Required by Android OS to create and manage secure VPN interface tunnels. Prompts the user with the system VPN confirmation dialog. |
| Foreground Service | FOREGROUND_SERVICE_SPECIAL_USE |
Maintains active, uninterrupted VPN connectivity in the background while displaying an active status notification. |
| Notifications | android.permission.POST_NOTIFICATIONS |
Displays active connection status (Connected, Connecting, Disconnected) and connection health alerts in the notification shade. |
| Network State | android.permission.ACCESS_NETWORK_STATE |
Detects network status changes (e.g., switching between Wi-Fi and Cellular) to automatically reconnect or pause the VPN tunnel. |
6. How Information Is Used
The minimal information collected is used solely for the following business and operational purposes:
- Authenticating your device with your organization's NetSense security controller.
- Establishing, maintaining, and restoring encrypted network tunnels.
- Providing connection metrics (e.g., latency, throughput, packet loss) in the app UI for user awareness.
- Assisting enterprise IT administrators in diagnosing network connectivity or authentication issues.
7. Security & Encryption Standards
Security is the cornerstone of NetSense products. We employ industry-leading technical measures to protect all data handled by the VPN Client:
- Transport Encryption: Tunnels utilize AES-256-GCM, WireGuard®, or TLS 1.3 protocol encryption.
- Credential Storage: Authentication credentials and certificates are stored exclusively inside the Android Hardware-backed Keystore / EncryptedSharedPreferences.
- Anti-Tampering: Built-in certificate pinning to prevent Man-In-The-Middle (MITM) attacks on server authentication connections.
8. Data Sharing & Third-Party Services
No Sale of Data: NetSense Technologies Inc. does not sell, rent, trade, or monetize any user or device data collected through the application under any circumstances.
Enterprise Controller Communication: NetSense VPN Client communicates exclusively with your organization's deployed NetSense VPN appliances or designated corporate controllers. We do not transmit VPN data to third-party advertisers or analytics platforms.
9. Data Retention & User Rights
Authentication tokens stored on the Android device remain until the user logs out or uninstalls the application. Connection diagnostic logs generated on the device are automatically purged upon session termination or app exit.
Under global privacy frameworks (including GDPR, CCPA/CPRA, and LGPD), users and enterprise employees have rights regarding their personal metadata, including rights to access, rectify, or request deletion. Because this application connects to your employer's or organization's NetSense infrastructure, requests regarding server-side access logs should be directed to your organization's IT administrator.
10. Children's Privacy
The NetSense VPN Client is an enterprise software application intended for business, organizational, and professional use. It is not directed to, or intended for use by, children under the age of 16. We do not knowingly collect personal information from children.
11. Contact Us & Policy Updates
We may update this Privacy Policy from time to time to reflect changes in legal requirements, Android operating system guidelines, or application functionality. The updated version will be indicated by the "Last Updated" date at the top of this document.
If you have any questions or concerns about this Privacy Policy, please contact us at:
NetSense Technologies Inc. - Privacy Office
Email: privacy@netsense.io
Website: https://netsense.io/privacy