privacy policy

Privacy, in writing.

Effective: [release date] · Applies to: Vigila for iOS & watchOS, the Vigila relay, and the Vigila push bridge · Česká verze

the short version

Vigila collects no personal data. No account, no analytics, no tracking. Your router credentials never leave your devices, and push notifications are end-to-end encrypted so that even our own relay service cannot read them.

1. Data we collect

None. The Vigila app has no user accounts, no sign-in, no analytics SDK, no crash reporting service, and no advertising identifiers. We do not collect, store, sell, or share any personal information. The app's Apple privacy label is "Data Not Collected", and its privacy manifest declares no data collection and no tracking domains.

2. Where your data lives

  • Router credentials are stored in the iOS Keychain, never synced via iCloud Keychain; included only in your encrypted device backups. If you pair a relay, they are also stored on your own relay, encrypted at rest. They are never transmitted to us.
  • Monitoring data (interface states, traffic counters, logs) flows directly between your devices and your routers, or between your relay and your routers, over TLS with certificate pinning. It does not pass through our servers.
  • Alert history and settings are stored locally on your device.

3. Push notifications — what our bridge sees

To deliver alerts while your phone is asleep, your relay sends each alert through the Vigila bridge (our forwarding service) to Apple Push Notification service. Alerts areend-to-end encrypted on your relay with a key held only by your iPhone (X25519 key agreement, ChaCha20-Poly1305 encryption). The bridge receives only:

  • an opaque Apple device token (needed for delivery),
  • the encrypted alert (which it cannot decrypt), and
  • a delivery priority flag.

The bridge keeps no logs of notification contents, stores only the hash of a random per-device key used to authorize delivery, and cannot link tokens to identities. Unpairing a router or relay deletes its bridge registration immediately; the bridge also prunes dead device tokens and applies a 180-day retention sweep to any registration it no longer hears from.

4. Third parties

The only third party involved is Apple (Push Notification service and, if you purchase Vigila Pro, App Store payment processing under Apple's own terms). There are no analytics, advertising, or hosting partners with access to your data.

5. Our website

vigila.eu is a static site served by GitHub Pages. It sets no cookies and runs no analytics or tracking scripts.

6. Your rights & contact

Because we hold no personal data about you, there is nothing for us to export or delete — your data is under your control on your own hardware. For any privacy question, contact support@vigila.eu.

7. Changes to this policy

If Vigila's data practices ever change, we will update this page and note the change in the app's release notes before it takes effect.