Privacy
What the app collects, what it never sees, and what we commit to.
Lux-World PC publishes Paart. This page is short because there is little to say, and that is the point.
We are not on the path
Paart is a client. We operate no VPN server. The tunnel runs from your device to a network that is not ours, so there is no browsing history to keep, no lookup to log and no connection record to hand over — not as a policy we could change, but as a consequence of where the tunnel ends.
Your configurations, keys and profiles stay on your device. If you turn on sync they travel between your own devices and nowhere else, through your own iCloud, sealed with a key derived from a passphrase you choose, which stays in that device’s keychain. Apple holds an opaque block it cannot open. A managed connection never syncs: it is tied to one device on the firewall that issued it.
Our commitment
We do not sell, rent or trade any of your data. We do not disclose it to third parties for their own purposes. We do not use it for advertising, profiling or analytics — only to answer the message you sent us.
There is no advertising identifier in Paart, no analytics SDK, no tracking pixel, and no third-party code that reports back.
What we collect, and only when you write to us
The app sends us nothing until you press send. When you do, this is the whole of it:
| What | Why |
|---|---|
| The message you wrote | Nothing else would let us answer it. |
| The kind of message you picked | Bug, request, or a request for updates — from a fixed list. |
| Your email address, if you give one | So we can reply. Leave it out and the message still arrives; we then have no way to reach you. |
| App version, build number and operating system version | A bug is usually specific to a version. |
| Whether the message carried a valid App Attest proof, and which environment | It tells us the message came from a real copy of Paart rather than a script. It identifies a copy of the app, never you. |
Nothing else is attached. In particular: no device identifier or name, no location, no contact list, no photos, no files, no account, and no IP address — the address your message arrives from enforces a rate limit and is never written to the database.
Never send us a private key
We do not need it, and we will never ask for it. Before your message is stored,
our endpoint finds the lines that carry a secret — PrivateKey and PresharedKey —
and replaces their values, so they never reach the database, the backups or the logs.
⚠️ That check works by name, deliberately. A key pasted on its own, with no label,
looks exactly like a public key, and stripping every 44-character string would destroy
the public keys that make your message answerable. So replace the PrivateKey line
with REDACTED yourself. See
Keeping your private key safe.
When you write from this website
The form sends to the same endpoint as the app, and everything above applies unchanged. Three differences, all narrower rather than wider:
- Three fixed values travel with the message, and nothing else: the literal
sitewhere the app puts its version, the literalwebwhere it puts its operating system, and the identifier of this website’s build. Nothing is read from your browser — not the user agent, not the platform, not the screen. - A message from this site is not attested. App Attest exists only inside the app. Nothing depends on it, and we add no substitute check.
- This site sets no cookies, loads no font, image or script from anywhere else,
and counts page views with Umami, on a server we own in Luxembourg. Per view it
records the page and title, the site you came from, your browser, operating system,
device type, screen size and language, and — derived from your address — country,
region and city. Your address itself is not stored. Everything after the
?in a link is removed before the count is sent, so advertising click identifiers never arrive here. Do Not Track is honoured, the counter is loaded from a separate address so any blocker stops it cleanly, and the figures go to nobody.
The site uses localStorage three times: for your theme, to remember that you
pressed one of the vote buttons, and — only if you ask for it — to remember that
counting is off. None of these values leaves your browser.
You can switch counting off for this browser, and it stops from that moment on:
That sets umami.disabled to 1 in this browser. You can set it yourself instead,
and a content blocker stops the counter just as well.
Who else handles it
Two, and no more. Mailgun, on its European infrastructure, delivers your message to us as an email notification, on our instructions and for no purpose of its own. Apple, only inasmuch as App Attest is Apple’s: the proof is checked against Apple’s published keys, and the receipt is not sent to Apple, so Apple learns nothing about your message. Nobody else — not advertisers, not data brokers, not analytics firms. The page-view counter is not on this list because it is our own software on our own server.
How long, and where
Messages are kept for twelve months, then deleted automatically. Ask us to delete yours sooner and we will. Page-view figures are kept for thirteen months — long enough to compare one year with the one before — and a job on our own server deletes them every day, whether or not there is anything to delete.
Everything is held on a server we operate ourselves, in the European Union, in a single file only the endpoint and its administrators can read.
Your rights
If you gave us an email address, ask us from that address through the contact form to show, correct or delete what we hold, and we will act on it. If you wrote anonymously we hold nothing we could connect to you, so there is nothing to look up — that is the consequence of not asking who you are. If you believe we have handled your data wrongly, you may complain to the Luxembourg data protection authority, the Commission nationale pour la protection des données (CNPD).
Paart is not directed at children and collects nothing that would identify one.
Changes
If what we collect changes, this page changes first, and the date below moves. We will not start collecting something and describe it afterwards.
Last updated: