Privacy

What the app collects, what it never sees, and what we commit to.

Lux-World PC publishes Paart. This page is short because there is little to say, and that is the point.

We are not on the path

Paart is a client. We operate no VPN server. The tunnel runs from your device to a network that is not ours, so there is no browsing history to keep, no lookup to log and no connection record to hand over — not as a policy we could change, but as a consequence of where the tunnel ends.

Your configurations, keys and profiles stay on your device. If you turn on sync they travel between your own devices and nowhere else, through your own iCloud, sealed with a key derived from a passphrase you choose, which stays in that device’s keychain. Apple holds an opaque block it cannot open. A managed connection never syncs: it is tied to one device on the firewall that issued it.

Our commitment

We do not sell, rent or trade any of your data. We do not disclose it to third parties for their own purposes. We do not use it for advertising, profiling or analytics — only to answer the message you sent us.

There is no advertising identifier in Paart, no analytics SDK, no tracking pixel, and no third-party code that reports back.

What we collect, and only when you write to us

The app sends us nothing until you press send. When you do, this is the whole of it:

WhatWhy
The message you wroteNothing else would let us answer it.
The kind of message you pickedBug, request, or a request for updates — from a fixed list.
Your email address, if you give oneSo we can reply. Leave it out and the message still arrives; we then have no way to reach you.
App version, build number and operating system versionA bug is usually specific to a version.
Whether the message carried a valid App Attest proof, and which environmentIt tells us the message came from a real copy of Paart rather than a script. It identifies a copy of the app, never you.

Nothing else is attached. In particular: no device identifier or name, no location, no contact list, no photos, no files, no account, and no IP address — the address your message arrives from enforces a rate limit and is never written to the database.

Never send us a private key

We do not need it, and we will never ask for it. Before your message is stored, our endpoint finds the lines that carry a secret — PrivateKey and PresharedKey — and replaces their values, so they never reach the database, the backups or the logs.

⚠️ That check works by name, deliberately. A key pasted on its own, with no label, looks exactly like a public key, and stripping every 44-character string would destroy the public keys that make your message answerable. So replace the PrivateKey line with REDACTED yourself. See Keeping your private key safe.

When you write from this website

The form sends to the same endpoint as the app, and everything above applies unchanged. Three differences, all narrower rather than wider:

The site uses localStorage three times: for your theme, to remember that you pressed one of the vote buttons, and — only if you ask for it — to remember that counting is off. None of these values leaves your browser.

You can switch counting off for this browser, and it stops from that moment on:

That sets umami.disabled to 1 in this browser. You can set it yourself instead, and a content blocker stops the counter just as well.

Who else handles it

Two, and no more. Mailgun, on its European infrastructure, delivers your message to us as an email notification, on our instructions and for no purpose of its own. Apple, only inasmuch as App Attest is Apple’s: the proof is checked against Apple’s published keys, and the receipt is not sent to Apple, so Apple learns nothing about your message. Nobody else — not advertisers, not data brokers, not analytics firms. The page-view counter is not on this list because it is our own software on our own server.

How long, and where

Messages are kept for twelve months, then deleted automatically. Ask us to delete yours sooner and we will. Page-view figures are kept for thirteen months — long enough to compare one year with the one before — and a job on our own server deletes them every day, whether or not there is anything to delete.

Everything is held on a server we operate ourselves, in the European Union, in a single file only the endpoint and its administrators can read.

Your rights

If you gave us an email address, ask us from that address through the contact form to show, correct or delete what we hold, and we will act on it. If you wrote anonymously we hold nothing we could connect to you, so there is nothing to look up — that is the consequence of not asking who you are. If you believe we have handled your data wrongly, you may complain to the Luxembourg data protection authority, the Commission nationale pour la protection des données (CNPD).

Paart is not directed at children and collects nothing that would identify one.

Changes

If what we collect changes, this page changes first, and the date below moves. We will not start collecting something and describe it afterwards.

Last updated: