TTumbler

Privacy Policy

Last updated: June 30, 2026

SUNSHINE NETWORK S.R.L. operates Tumbler, including the Tumbler apps, the public API at api.tumbler.app, and this website. This Privacy Policy explains what data Tumbler collects, how it is used, how long it is retained, and how users can request export or deletion.

Data controller

Controller: SUNSHINE NETWORK S.R.L.

Privacy contact: privacy@tumbler.app

Data we collect

VPN traffic and tracking

Tumbler does not sell, rent, or use VPN traffic data, browsing history, DNS query content, diagnostics, or session metadata for advertising or cross-app tracking. The Tumbler control plane is designed to operate subscriptions, sessions, diagnostics, security, and support. It does not intentionally collect the contents of websites, apps, messages, or files a user accesses through a VPN tunnel.

How we use data

Third parties and service providers

We use service providers only as needed to operate and support Tumbler, including cloud hosting, storage, databases, analytics/observability infrastructure, push notification platforms, app distribution platforms, and payment or subscription platforms where applicable. We require service providers that process user data for Tumbler to protect it at least as strongly as described in this policy.

If a user adds a third-party VPN subscription URL or provider configuration, Tumbler may contact that provider endpoint to fetch or refresh the configuration chosen by the user. Tumbler does not sell user data to VPN providers, advertisers, data brokers, or analytics networks.

Retention

We retain data only for the purposes described above. Unless a shorter period is configured or a longer period is required for security, legal, or abuse-prevention reasons, operational events, session records, and subscription snapshots are retained for up to 365 days. VPN diagnostics events are retained for up to 90 days. Privacy export links are temporary and expire after the configured export period.

When a user requests deletion, Tumbler marks the installation as deleted, invalidates signing keys, removes or disassociates installation-scoped records, clears push tokens and routing policies, and schedules deletion of related analytics records. Some backup copies, logs, or provider-side records may persist for a limited period according to the relevant provider's retention and legal requirements.

User choices and deletion

Users can request a copy of their Tumbler data or deletion of installation-scoped data from the app privacy controls where available. Users may also contact privacy@tumbler.app to request access, correction, export, deletion, or withdrawal of consent. We may ask for information needed to verify the installation or request.

Security

Tumbler uses signed API requests, authentication tokens, request replay protection, encrypted payload delivery, access controls, and operational monitoring to protect user data. No system is perfectly secure, but we design the service to minimize access and retain only data needed for the service.

Children

Tumbler is not directed to children. We do not knowingly collect personal data from children.

International processing

Data may be processed in countries where SUNSHINE NETWORK S.R.L. or its service providers operate. When data is transferred internationally, we use appropriate contractual, technical, and organizational safeguards.

Changes

We may update this policy when Tumbler's data practices change. The updated version will be posted on this page with a new "Last updated" date.