500 MB once when your account is first created — it does not expire — plus 100 MB for each rewarded ad you choose to watch, up to ten ads per UTC day. Seven exit servers across seven countries, all of them open to the free plan. No traffic logs and no DNS logs, described precisely rather than slogan-shaped.
Every VPN page asks you to trust an adjective. Here are three mechanisms instead. Each one is a thing the software does, not a thing we say about it — and each one is capable of reporting a bad answer, which is what makes it worth reading.
Connection Health compares the IP address the internet answers to with the IP address of the server you actually connected to, and prints both. On an iPhone 14 Pro Max through our Nuremberg server on 22 August 2026, both read 78.46.123.40 — Matches. The same test on a simulator, where no tunnel exists, reads Mismatch and scores 40. A check that cannot fail is not a check.
The caveat, because it belongs with the claim: the exit address is reported by our own control plane, which sees where your request came from. It is a self-check, not a third-party audit, and we call it one.
A DNS test that comes back with nothing costs 10 points, not zero. An exit IP we could not confirm costs 15. Traffic leaving from an address that is not the server you picked costs 60 — picked so that no amount of good latency can lift the result back into the green.
We found that bug in our own screen. It once printed a green 100 directly beside the words “DNS leak: Not verified”, because the arithmetic charged for a leak found and not for a leak never ruled out. Fixed on 22 August 2026.
The app does not credit you for finishing a video. It credits you when Google's signed server-to-server confirmation reaches our ledger, and the megabyte figure you see is the change the ledger actually made — not this build's copy of a constant.
When the confirmation does not arrive, the app says so: “Ad finished, but the server did not confirm the reward, so no data was added.” And a build that cannot verify rewards server-side does not offer the button at all, because taking thirty seconds of your time for nothing is worse than showing no button.
Most VPNs open with “no-log”. We do not use that phrase, because it is an absolute nobody can verify from the outside — and because the free plan uses a third-party advertising SDK, which necessarily receives ad-request data even though every request is non-personalised. Here is the accurate version.
The sites and services you reach are not recorded anywhere. Our servers run no proxy and no deep packet inspection — they translate addresses and forward packets.
No resolver on an exit server is reachable from the tunnel, and none logs a user query. Queries go through the tunnel to Cloudflare and Quad9.
Peers are never written to a config file, packet logging is off, network flow logs are off, and no log agent runs. Exit-server journals are memory-only; ordinary SSH attack noise may appear there, but user peer addresses and handshakes do not.
Request-IP logging on the control-plane API is switched off, and the code never reads the caller's address. Application logs hold server-health counters and error traces; they contain no user identifier and no IP address.
WireGuard cannot reply to you without knowing where you are. While a session is live the kernel holds your public IP, last handshake and byte counters. A scrubber wipes them ~3 minutes after your device goes quiet, and immediately when you disconnect. Never written to disk.
Rewarded ads are served by Google AdMob. Every request is non-personalised and the build does not request IDFA or Android advertising-ID permissions, but Google still receives the ad request, IP-derived approximate location, basic app/device information and ad interactions. The app requests an ad only after you tap the reward button and runs the applicable consent flow first.
Accounts use random identifiers: no username, password or email is required. The current release does not offer cross-device sign-in. On a supported device, reinstalling the app restores the same account and its remaining allowance rather than granting another 500 MB. The full field-by-field list, with retention periods, is in the Privacy Policy.
The free service remains available on Android and iOS. Suphuzi Pro is sold on Android through Google Play only. The iOS app remains free and ad-supported, with no subscription or in-app purchase.
The dollar amounts are reference prices. The price shown by Google Play at checkout in your local currency, including applicable tax, is authoritative. Monthly and yearly subscriptions renew automatically until cancelled in Google Play. Android users can restore an active purchase from the app.
Reinstalling is not a new-account reward mechanism. Where the operating system preserves the Suphuzi identity, the same account and remaining balance return. Deleting the account from inside the app clears that identity; uninstalling the app by itself does not request deletion.
Seven exit servers in seven countries: Germany (Nuremberg), Finland (Helsinki), the United States (Ashburn), Singapore, France (Gravelines), India (Mumbai) and Brazil (São Paulo). Every one of them is available on the current free service. Capacity is added and retired over time. The machines are rented from three infrastructure providers — Hetzner, OVH and Vultr — and which provider hosts which location is listed in the privacy policy.
WireGuard key pairs are generated on your own device; only the public half ever reaches us. The control plane holds a short-lived lease record that contains no account field and no real IP address. The lease stops authorising your peer 24 hours after it is issued, and the record itself is deleted at most 48 hours after it is issued — the 24-hour lease plus a 24-hour purge grace period — sooner when you disconnect.
Installer with WireGuard bundled, plus a portable build
Coming soon
AppImage and tar.gz
Coming soon
Need help? The support page has setup notes, the known limits of each feature, and how to reach a human.