Summary
This privacy policy describes how Codivo Labs (“Codivo Labs”, “we”, “us”) handles information in connection with the NetCap: Internet Speed Limiter application for iOS (the “App”).
The App applies a download and upload speed limit - and, if you ask for it, additional latency and packet loss - to network traffic leaving and entering your device. It does this through a network extension that runs on the device itself. We do not operate a proxy, a VPN server, or any other backend service for the App. There is no server of ours in the path your traffic takes, and no mechanism in the App by which your traffic or information about it could reach us.
Because we collect nothing, there is no data of yours for us to sell, share, lose, or hand to anybody else.
Data we do not collect
To be unambiguous, the App does not collect, transmit, or store any of the following:
- Your name, email address, phone number, or any other contact information
- Account credentials - the App has no accounts and no sign-in
- The addresses, domains, hostnames or IP addresses you connect to, and no history or log of them
- The contents of your network traffic, in any form - not the payloads, not headers, not copies, not hashes, and not summaries
- A list of the apps installed on your device, or which of them use the network
- Usage analytics, event logs, session recordings, or feature telemetry
- Crash reports or diagnostic logs sent to us
- Advertising identifiers (including the Identifier for Advertisers), device fingerprints, or any other tracking identifiers
- Location data of any kind, precise or approximate
- Photos, contacts, calendars, health data, or microphone or camera input
- Payment or financial information
The App contains no advertising, no third-party trackers, and no cross-app tracking. We do not build profiles of users, because we have no users to profile.
How your traffic is handled
This is the section worth reading carefully, because the App does necessarily process network traffic - that is what a speed limiter is. What matters is what happens to it.
- Where the shaping happens. iOS hands packets to a network extension bundled inside the App, running on your device. The extension queues, delays, meters and - if you configured packet loss - discards packets in order to match the profile you selected, then forwards the rest directly to their destination.
- Nothing is proxied through us. There is no remote endpoint of ours involved. We could not read your traffic even if we wanted to, because it never travels to us.
- Nothing is logged. The extension does not record the addresses you visit, the names of the services you use, or the contents of what you send and receive. It does not write a traffic log to disk, and it does not keep packet contents after forwarding them.
- What the App counts. While the limiter is running, the App shows you total bytes downloaded and uploaded, how long the session has run, how many connections are open, and how many packets were dropped. These are plain counters held in memory. They are shown only to you, they are never transmitted, and they are cleared when the limiter stops.
- Diagnostics. The Diagnostics screen shows the same kind of information - counts of TCP connections and UDP bindings, queue depth, and how many packets the limiter could not carry. It is a live view of counters, not a stored record, and nothing on that screen is sent anywhere.
- No encryption claim. The App does not encrypt your traffic and does not change its security properties. Traffic that was already encrypted stays encrypted; traffic that was not, is not. See the Terms on this point - the App is not a privacy tool.
What is stored on your device
The App keeps a small amount of state so that it works the way you left it. All of it lives on your device, inside the App's own protected storage container, which the operating system keeps inaccessible to us and to other apps.
| What | Why | How long |
|---|---|---|
| Your speed profiles | So your saved download, upload, latency and packet-loss values are there next time, along with the name and icon you gave them. | Until you delete the profile or the App |
| Which profile is selected | So the App reopens on the profile you were last using. | Until you change it or delete the App |
| Preferences | Appearance (system, light or dark), haptic feedback, and whether you have seen the introduction. | Until you change them or delete the App |
| Purchase state | A local flag recording that the one-time unlock has been verified for your Apple Account, so paid features stay available offline. | Until you delete the App; restorable from Apple afterwards |
| Live session counters | To show you the current session's byte, connection and drop figures. | Held in memory; cleared when the limiter stops |
Removing the App from your device deletes its storage container and everything in the table above along with it.
The network permission
Before the App can shape traffic, iOS asks you to allow it to add a network configuration. This is the operating system's gate on the Network Extension framework - the same gate a VPN app passes through - and the App cannot function without it.
- What granting it does. It permits the App's own extension, on your device, to receive and forward your traffic. It does not grant access to us.
- Where it is recorded. The configuration is stored by iOS in your device's system settings. We do not receive a copy of it and cannot read it.
- The VPN indicator. While the limiter runs, iOS displays its VPN status indicator, because that indicator reflects the framework in use rather than the presence of a remote server. Your traffic is still going straight to the internet.
- Withdrawing it. You can stop the limiter at any time, remove the configuration from within the App, or revoke it in Settings › General › VPN & Device Management. If you decline the permission, the App simply cannot limit traffic; nothing else about it changes.
Purchases
One preset is free to use so that you can confirm the App works on your device. The remaining features are unlocked by a single one-time purchase.
- The transaction is handled entirely by Apple through the App Store. We never see your payment card details, your billing address, or your Apple Account credentials.
- The App asks Apple's on-device StoreKit framework whether a purchase exists for the signed-in Apple Account, and stores the answer as a local flag. It does not send an identifier to us, and we do not maintain a customer database.
- “Restore Purchase” asks Apple the same question again. It involves no server of ours.
Information Apple may collect
The App is distributed through the Apple App Store. Apple operates the store, the payment mechanism and the platform, and Apple collects its own information under its own privacy policy - which we do not control.
- If you choose to share diagnostics and usage information with developers in your device settings, Apple may make aggregated, anonymised reports available to us through App Store Connect - for example total downloads, crash counts by app version, or aggregate performance metrics. These reports do not identify you and we cannot link them to any individual.
- Apple handles any purchase or refund entirely. We do not receive your name or email address from Apple in connection with a purchase.
- If you leave a review on the App Store, that review and the display name attached to it are published by Apple.
For details of what Apple collects, see Apple's privacy policy at apple.com/legal/privacy.
Third parties and SDKs
The App bundles no third-party analytics, advertising, attribution, or crash reporting software development kits. It makes no network requests of its own to any such service, and the only network activity attributable to the App is the forwarding of your own traffic to the destinations you chose.
We do not sell, rent, trade or otherwise disclose personal information to third parties, because we do not hold any. We do not share personal information for cross-context behavioural advertising.
If a future version of the App introduces any feature that requires data collection or a server of ours, we will update this policy before that version is released and make the change clear in the App itself.
If you email support
The one situation in which we hold information about you is when you choose to contact us. If you email support@codivolabs.com, we receive whatever you send: your email address, your message, and anything you attach such as a screenshot or a copy of the Diagnostics figures.
- Purpose. We use it solely to answer you and to fix the problem you reported.
- Legal basis (where the UK GDPR or EU GDPR applies). Our legitimate interest in providing support for our software, and in some cases the performance of our agreement with you.
- Retention. Support correspondence is kept for up to 24 months so that we have context if you write again, then deleted.
- Recipients. Our email provider processes the message in order to deliver and store it. We do not pass it to anyone else.
Please do not send us packet captures, traffic logs or anything else that reveals what you were connecting to. We do not need it to diagnose a speed limiting problem, and we would rather not have it.
Children's privacy
The App does not collect personal information from anybody, including children. We do not knowingly collect information from children under 13 (or the equivalent minimum age in your jurisdiction), and because the App has no data collection mechanism at all, there is nothing for a parent or guardian to request the deletion of. If you believe we hold information about a child through support correspondence, contact us and we will delete it.
Security
Your traffic stays on the path it was already taking, and the App's own state stays on your device inside the operating system's sandbox. This substantially reduces your exposure: there is no server of ours to breach, no traffic log to leak, and no user database to steal.
You remain responsible for the security of the device itself - a device passcode and up-to-date system software. Note also what the App is not: it does not encrypt your traffic and provides no protection on an untrusted network. Do not treat a running speed limiter as a security measure.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, to object to processing, and to lodge a complaint with a supervisory authority. These rights arise under laws including the EU and UK General Data Protection Regulation, the California Consumer Privacy Act as amended, and India's Digital Personal Data Protection Act.
For the App itself these rights are satisfied by design: we hold no personal data about you, so there is nothing to access, export, correct or erase. We do not sell personal information and we do not share it for targeted advertising, so there is no opt-out to exercise. We do not use personal data for automated decision-making or profiling.
If you have emailed us, you may ask us to provide a copy of that correspondence or to delete it. Write to privacy@codivolabs.com and we will respond within 30 days. We will not charge you or degrade your use of the App for exercising any right.
Changes to this policy
If we change this policy we will update the “Last updated” date at the top of this page and, where the change is material - for example if a future release began collecting any data at all, or introduced a server of ours into the traffic path - we will make it prominent in the App and in the App Store release notes before the change takes effect. Your continued use of the App after a change indicates acceptance of the revised policy.
Earlier versions of this policy are available on request from privacy@codivolabs.com.
Contact us
If any part of this document is unclear, or you want to exercise a right described in it, write to us and a person will reply.
Email: privacy@codivolabs.com