Privacy Policy
The short version. FluxMoat has no accounts and no servers that hold your data. Every packet it inspects is inspected on your iPhone and stays there. We do not receive your browsing history, your DNS lookups, your rules, or any identifier for you or your device — not in aggregate, not anonymised, not at all. There is no analytics SDK and no advertising SDK in the app.
This page also lists every server the app can contact, and what makes it happen. That list is short and it is complete. The app asks for exactly one system permission beyond the VPN itself — approximate location, only when you open the world map, only to draw the near end of the lines on it.
What we collect
Nothing. We operate no account system, no telemetry endpoint, and no backend that receives data from the app. There is no sign-up, no email address, no device identifier, and no advertising identifier.
Because there is no collection, there is also nothing for us to sell, share, disclose to a partner, or hand over on request. We cannot produce your traffic history because we have never had it.
What stays on your device
All traffic analysis happens on-device, inside the packet tunnel extension. FluxMoat records a compact summary of each connection into a local database on your iPhone, so that the Dashboard, Live Traffic and Insights screens have something to show you.
Per connection, it stores: timestamp, remote IP address, DNS-derived domain (when available), port, protocol number, byte counts, verdict, matched rule, profile, country code, and network type — and nothing else.
It never stores packet payloads, HTTP bodies, TLS plaintext, URLs beyond hostnames, anything you type, or credentials.
You choose how long that local history is kept: 7 days, 30 days, 90 days, 6 months, or 12 months. The default is 30 days. Anything older is pruned automatically. Settings has a one-tap clear for traffic history and a one-tap clear for all configuration.
What FluxMoat cannot do
These are structural limits, not policy choices, and the app states them at first launch:
- Network activity is shown for the whole device. iOS doesn't identify the originating app.
- Encrypted content stays encrypted.
- Alerts don't pause a connection while waiting for your response.
- Locations are estimates and may be inaccurate.
- iOS allows one VPN of this kind at a time.
FluxMoat does not decrypt HTTPS, does not install a root certificate, and does not inspect the contents of encrypted connections. It cannot, and it never asks you to let it. Your traffic is not routed through any server we operate — the tunnel begins and ends on your iPhone.
Every server the app can contact
FluxMoat itself reaches the network in exactly the situations below. As with any HTTPS request, whoever operates the server on the other end can see your IP address and the time of the request. All list downloads are HTTPS-only; plain HTTP is rejected.
| Destination | What triggers it | What is sent |
|---|---|---|
feeds.hominexis.comThreatFox mirror (ours, on GitHub Pages) |
The subscription is present after install, but nothing downloads until you tap Update. After your first download, the app re-checks it at most once every six hours while it is in the foreground. | An ordinary HTTPS GET, plus an If-None-Match caching header so an
unchanged list costs nothing. No account, no key. |
raw.githubusercontent.comStevenBlack hosts list |
Same: your first tap, then six-hourly re-checks of a list you already chose to download. | An ordinary HTTPS GET plus the caching header. No account, no key. |
feodotracker.abuse.chFeodo Tracker botnet C2 list |
Same: your first tap, then six-hourly re-checks. | An ordinary HTTPS GET plus the caching header. No key needed for this list. |
abuse.ch and its subdomains |
Only if you have chosen to paste a free abuse.ch Auth-Key into Settings and subscribed to a feed hosted there. Optional; the app works fully without it. | The key, as an Auth-Key header. The key is stored in the Keychain
and only ever sent to abuse.ch. The app checks a subscription's host before it will
attach the key, so it cannot reach a third-party list URL. |
| The DNS-over-HTTPS resolver you pick | Off by default; FluxMoat uses system DNS until you choose otherwise. If you select Quad9, Cloudflare, or your own endpoint, hostname lookups go there. | Your DNS queries. The resolver you choose sees them, exactly as it would for any DoH client. We are not in that path and never see them. |
| Apple iCloud (CloudKit) container iCloud.Hominexis.fluxmoat |
Opt-in and off by default. Only if you turn on config sync in Settings. | Configuration only — see below. It goes to your private CloudKit database, scoped to your Apple Account. We operate no server in this path and can read none of it. |
That is the complete list of destinations the app ships with. One more can exist only
because you create it: if you add your own blocklist subscription, FluxMoat downloads it
from whatever HTTPS address you entered, on the same terms as the rows above. Your
abuse.ch key is never attached to such a request unless the address is on
abuse.ch itself — the app checks the host before it will send the key
anywhere.
Beyond those, there is no other network destination in the app. No telemetry ping, no licence check, no update check, no crash upload, no push registration.
A note on the first row, because we would rather say it than have you find it: the
ThreatFox mirror is ours, but the server is not. feeds.hominexis.com is our
domain pointed at GitHub Pages, and GitHub serves the list as a static file over HTTPS.
So when your phone fetches that list, the request arrives at GitHub's servers, and GitHub
receives what any web server necessarily sees — an IP address, a timestamp, a user agent,
and the name of the file requested. That is covered by
GitHub's
privacy statement rather than by this one.
There is no account and no key anywhere on that path. We run no server of our own here and hold no logs, so there is nothing on our side to inspect, to join to anything, or to hand over — we could not produce a record of your downloads if we were asked for one.
The 1.1.1.1 you will see
While the tunnel is on, iOS reports 1.1.1.1 as its DNS server — in
Settings, and on any DNS-leak test site you might point at it. We would rather explain
that than let it look like something it is not. That address is where the system is told
to send DNS so that the tunnel can intercept it in the first place. The hostname lookups
your browsing depends on are answered on the device, by FluxMoat, and are not forwarded
to 1.1.1.1.
One claim we will not make is that no DNS ever leaves your phone. FluxMoat answers the address lookups; other kinds of DNS query ride the tunnel as ordinary traffic, to whichever resolver the app that asked them is using. And if you switch DNS-over-HTTPS on and choose a resolver, your lookups go to that resolver by design — as the table above says.
Blocklists and threat intelligence
FluxMoat arrives with three subscriptions already listed: an ads-and-malware hosts list, and two threat-intelligence feeds. None of them is downloaded until you ask for it. The rule the app holds itself to is that the first download of a subscription is always your own tap — a blocklist nobody asked for must never appear out of a silent fetch. After that, keeping it fresh is maintenance of a decision you already made, so the app does it for you at most every six hours while it is open.
The ThreatFox mirror republishes indicators from abuse.ch ThreatFox, released under CC0 1.0, rebuilt every six hours. It is an unofficial third-party mirror and is not operated, endorsed, or supported by abuse.ch.
Matching happens entirely on your device. The lists come to your phone; your traffic never goes to the lists.
iCloud sync
Config sync is opt-in and off by default. When you turn it on, this is what the app tells you, and it is the term the opt-in is given against:
Syncs rules, settings, Wi-Fi automation and blocklist subscriptions between your devices through your private iCloud database. Traffic history and the abuse.ch key never sync. A rule deleted on one device stays deleted; if a device was offline for more than 30 days, the rule may reappear there and need deleting again.
In more detail. What syncs: your rules, rule deletion tombstones, run mode, DoH choice, the encrypted-DNS-block switch, retention setting, quiet hours, Wi-Fi-to-profile assignments (including SSIDs you typed into the configuration), blocklist subscription metadata (name, URL, format, category, enabled), and manual blocklist domains.
Worth being blunt about what that means, because "rules and settings" sounds smaller than it is: a rule is written about something, so your rules carry the domain names, IP addresses and network ranges you wrote them about, along with any note you typed on them. Wi-Fi automation carries the names of your networks. If you set a custom DNS resolver, its URL goes too. None of that reaches us — it goes to your private iCloud database — but it does leave the phone, and you should turn the switch on knowing that.
What never syncs: traffic history and events, the downloaded contents of any blocklist, and the abuse.ch Auth-Key or any other credential.
Retention in iCloud: one current-state record, overwritten in place. Deletion tombstones expire after 30 days — which is where the caveat above comes from. Turning sync off stops writes; data already in your iCloud account stays until you clear it through iOS Settings, because it is yours and not ours to delete.
The destination is your own private CloudKit database, scoped to your Apple Account. Hominexis operates no server in this path and cannot read its contents. The packet tunnel extension has no CloudKit entitlement at all, by design.
Country estimates, and the one location prompt
FluxMoat labels connections with a country so the Insights map and country rules can work. That label is estimated from the remote IP address using a database bundled inside the app. No geolocation lookup touches the network — your IP addresses are never sent anywhere to be resolved into places.
IP-to-country estimation is inherently approximate — VPNs, CDNs, cloud regions, and stale registry data all move the answer. Treat the map as an indication, not a fact about where anyone is.
Your own location
There is exactly one place FluxMoat asks for your location, and we would rather name it than let you meet it unannounced. The world map draws each connection as a line from roughly where you are to roughly where the other end is. To draw the near end of those lines, the map asks for when-in-use location access, at iOS's reduced (city-level) accuracy — the prompt appears only when you first open Insights → Map, not at launch.
As the permission prompt itself says: Your approximate location is used only to draw connection lines on the world map. It never leaves this device. The coordinate is held in memory while the map is on screen. It is never written to disk, never logged, never attached to a connection record, and never transmitted.
Declining is a first-class option. If you say no, the map simply draws no origin lines and everything else keeps working. You are not asked again and nothing nags you.
Separately: reading the name of the Wi-Fi network you are on, for Wi-Fi automation, does not use location access. That name is read through the active VPN session.
IP Geolocation by DB-IP. Country data © DB-IP, licensed under CC BY 4.0. Lookups happen entirely on this device.
Diagnostic reports
Settings can generate a diagnostic report to help us with a support question. It is never sent automatically. It is generated on demand, shown to you, and goes nowhere unless you share it yourself through the iOS share sheet.
Its scope, as printed on the report itself: Settings and counts only. No logs, domains, IP addresses, network names or keys are included.
Third-party code and tracking
FluxMoat contains no analytics SDK, no advertising SDK, no crash-reporting SDK, and no attribution or A/B-testing SDK. The app's only third-party component is the open-source leaf tunnel engine, which is compiled into the app when we build it.
Because that engine sits closest to your lookups, it is worth being exact about what
it does with them. It routes every connection to FluxMoat's own on-device proxy at
127.0.0.1. That is a literal IP address rather than a name, so the engine
performs no name resolution of its own: it does not send DNS queries to the public
resolvers named in its configuration, nor to any other third-party resolver. The
plaintext lookups that apps inside the tunnel make are answered on the device, with
placeholder addresses from a reserved, non-routable range.
There are no cookies, no web views used for tracking, and no third party that receives a copy of anything.
Children
FluxMoat is not directed at children and collects no personal information from anyone, regardless of age.
Your data rights
Data-protection law gives you rights to access, correct, export, and delete the personal data a company holds about you. We hold none, so there is nothing for us to produce or erase. The data the app creates is on your device and under your control: Settings offers rule export, one-tap clearing of traffic history, and one-tap clearing of all configuration. Deleting the app removes it all.
Changes to this policy
If the app's behaviour changes in a way that affects this page — a new endpoint, a new stored field — we will update this page and move the effective date. The endpoint table above is meant to stay exhaustive, and we would rather revise it than quietly outgrow it.
Contact
Questions about this policy, or about anything the app does: connect@hominexis.com.