Legal

Privacy Policy — Valenius Apps

Effective date: 05.07.2026 · Publisher: Stranto Business Solutions GmbH (“Stranto”, “we”) · Contact: info@valenius.com

Binding version. This privacy policy is provided in German and English. Only the German version is legally binding; this English text is a non-binding translation provided for your convenience. Switch to DE above for the binding text.

1. What Valenius is

The Valenius mobile app is a client for the Valenius VPN platform. It lets you connect your device to the private network of the organization that operates the Valenius server you use (“your organization”). Valenius is not a public or anonymizing VPN, and it does not route your traffic through Stranto’s (the developer of this software) servers.

2. Who controls your data

Your organization decides why and how Valenius is used, and is the controller of the data processed through the app.

The Valenius server your device connects to is either operated by your organization itself (“self-hosted”), or run as a Managed Cloud service by Stranto on your organization’s behalf. In the self-hosted case, Stranto has no access to the data listed in Section 3. Where Stranto operates the Managed Cloud, Stranto processes that data as a processor, strictly on instruction and under a data processing agreement (DPA) with your organization — not for its own purposes.

3. What the app collects, and why

The app sends the following to your organization’s Valenius server — whether that server is operated by your organization itself, or run as a Managed Cloud service by Stranto on your organization’s behalf (see Section 2) — only to provide its functionality:

  • Device identifier — a random identifier generated on first run (an app-generated install ID; not your hardware ID, device serial, or advertising ID), used to register and identify your device to your administrator.
  • Device name — your device model (on Android) or your device name (on iOS), so the device is identifiable in the administration panel.
  • Push token — where multi-factor push approval is enabled, a Firebase Cloud Messaging token, used only to deliver a contentless notification asking you to approve a sign-in.
  • Authentication data (only during sign-in) — a one-time code, or an approval number match, used to authorize your VPN session. This is not retained as profile data.
  • Diagnostic logs (only when you send them) — if you choose “Send logs”, a redacted, Valenius-only diagnostic bundle (your operating-system version and a short in-app event log) is uploaded to your organization’s server for support. Secrets are removed on the device before upload.

The app does not collect your location, does not send your IP address, and does not use an advertising identifier. It may read local network information on the device to decide whether to auto-connect on trusted networks; this evaluation happens entirely on the device.

4. Camera

The app requests camera access only to scan a QR code during setup or device pairing. The camera image is processed on the device to read the QR code and is not stored or transmitted.

5. VPN

When you connect, the app establishes a WireGuard® VPN tunnel using the operating system’s VPN service so your device can reach your organization’s private network. The app does not inspect, log, or sell the contents of your network traffic. Traffic routing is determined by the configuration your organization provides.

6. How data is shared

We do not sell your data and do not share it with third parties for advertising. Data you send through the app goes to your organization’s Valenius server. Where multi-factor push approval is enabled, push notifications are delivered through Google Firebase Cloud Messaging as a service provider (a wake signal only, without sensitive content).

7. Security

Data in transit is encrypted using HTTPS/TLS. VPN configuration is stored encrypted on the device using the operating system’s secure key store.

8. Retention and deletion

Your organization’s administrator controls retention and can remove your device and its record from the Valenius server. To request deletion, contact your administrator.

9. Children

Valenius is intended for use by members of an organization and is not directed to children.

10. Changes to this policy

We may update this policy; the effective date above will change. Material changes will be communicated as appropriate.

11. Contact

Questions about this policy: info@valenius.com — Stranto Business Solutions GmbH.

WireGuard® is a registered trademark of Jason A. Donenfeld.