Security is more than a lock icon
SanazNet separates account identity, access authorization, the VPN tunnel and operational telemetry. This page explains those boundaries without unnecessary jargon.
- 1
IKEv2
Supported clients use IKEv2 for the tunnel. The Android app disables cleartext traffic, and production client communication with the control service is HTTPS-only.
- 2
Server-side authorization
A VPN credential or profile is not an entitlement by itself. The server publishes a bounded lease for the device and selected node, and the node accepts access only while that authorization is active. This allows expiry, revocation and account changes to be enforced centrally.
- 3
Limited operational data
To operate the service, SanazNet processes data such as device details, app version, connection state, timestamps, node, technical addresses and usage counters. These support delivery, security, abuse prevention and support. The Privacy Policy publishes the categories and retention schedule.
- 4
Advertising on Free
Free Android and native iOS may use Google AdMob rewarded ads. Access remains server-authorized; a client-side reward event alone does not create entitlement. The iPhone/iPad Home Screen app uses a separate WIUNIX Ads campaign path.
- 5
Account and device controls
Tokens are bound to server-side device records. Device revocation, sign-out and replacement can invalidate that device’s credentials. Registered users manage devices, security, identity, billing and support from the account dashboard.
- 6
Deletion and retention
The official deletion flow erases or makes unusable the active data described in the Privacy Policy. Some security, support or accounting records may remain only for the published operational or legal retention period.