Privacy Policy

Last updated: October 1, 2026

Overview

Repel ("the App") is developed and maintained by LL Cloud Development & Operations ("we", "us", "our"). The App blocks ads, trackers and malware domains, lets you cut off internet access per app, and sets your phone's Private DNS. This policy explains what the App accesses, what leaves your device, and your rights.

The short version

The domains your apps look up, and the apps that look them up, stay on your phone. Repel has no server of its own. It never sells, shares or uploads your browsing or app activity, and it never inspects the content of your traffic.

How each protection handles your data

DNS filter (VPN)

When you turn the filter on, Android asks you to allow a local VPN. Repel uses it only for DNS: the address lookups apps make before they connect. All other traffic goes straight to your network and never passes through Repel. Lookups that match a blocklist are answered on the phone. The others are forwarded, encrypted over DNS-over-HTTPS, to the resolver you choose in the App (Cloudflare, Quad9, Google or AdGuard), which sees them as it would for any DNS query and is governed by its own privacy policy. The VPN does not route your traffic to us or to any remote server.

Activity log

So you can see what was blocked, Repel keeps a list of recent lookups: the domain, the app that asked, the time and whether it was blocked. It holds the last 2,000 lookups in a private file on the phone, so it survives restarts, and it is excluded from backups and never sent anywhere. Daily totals (numbers, no domains) are kept for the stats chart. Clear the log any time in Activity. Turning it off in Settings deletes it.

Firewall and Wireless debugging

Optional. To block apps without using the VPN, Repel pairs once with your phone's own Wireless debugging, using the code Android shows you, and runs a small helper with the same rights as a developer's computer would have. The pairing happens entirely on the phone over the loopback interface, and the pairing key never leaves the device. The helper accepts only a fixed set of firewall commands from Repel, and only turns an app's network access on or off. It never reads your traffic. Root can be used instead if your phone has it.

Hosts mode (root only)

Optional, on rooted phones. Repel writes your enabled blocklists, your own rules and your custom DNS records into the system hosts file, through your root manager's module folder, so the phone itself answers blocked names. The file stays on the phone. Turning hosts mode off removes it and restores the original.

Your rules, custom DNS records and Family mode

Block and allow rules, per-app domain rules and custom DNS records are stored on the phone and applied there. Family mode's safe search points search engines and YouTube at their own safe-search addresses. It sends nothing extra to them or to us.

Private DNS

With the connection above, Repel grants itself permission to change secure system settings, and uses it only to set the Private DNS provider you pick, to restore your previous choice, and to turn Wireless debugging back on when it was on before. Your phone then sends its lookups to that provider directly, under the provider's own policy.

List of installed apps

Repel reads which apps are installed so you can set a rule for each one and so the log can name the app behind a lookup. The list stays on the device.

Blocklist downloads

Repel downloads the blocklists you enable from their publishers (for example HaGeZi, OISD, StevenBlack or AdGuard) and any list address you add yourself. Those servers see an ordinary download request from your connection.

Notifications

Used for the pairing code field, the filter's status while it runs, and to tell you when protection has stopped, for example after a restart.

Data we collect

The App collects a small amount of technical data through the services below, tied to a random per-install identifier rather than to you. It never contains the domains you visit, the apps you block, your activity log or your network traffic.

  • Usage analytics (Google Firebase Analytics): anonymous events such as "setup completed", "protection turned on" or "pairing failed", with the phone model, Android version, app version and country. A daily health event says which protections are on, which Private DNS preset is selected (its name, never a custom host or NextDNS ID) and rounded counts of blocked lookups and restricted apps, never which apps or domains. We use them to see where setup fails.
  • Crash reports (Sentry): if the App crashes, a technical report with the stack trace, device model and app version is sent so we can fix it.
  • Purchases (RevenueCat): the Pro purchase is processed entirely by Google Play. RevenueCat receives an anonymous app user ID to verify and restore the purchase. We never see your payment details.

Diagnostics you send us. If you tap Email in the App's diagnostics, your email app opens with a report you can read before sending: device model, Android version, settings, the state of each protection and a timeline of recent app events. It includes the package names of apps with firewall rules and counts of your other rules, but no activity log and no domains you visited. Nothing is sent unless you send it.

We do not use advertising identifiers, advertising SDKs, or any form of tracking across apps. The App shows no ads.

Third-party services

  • Google Firebase Analytics (Google LLC) for usage analytics. Google Privacy Policy
  • Sentry (Functional Software, Inc.) for crash reports, hosted in the EU. Sentry Privacy Policy
  • RevenueCat (RevenueCat, Inc.) for purchase verification. RevenueCat Privacy Policy
  • The DNS resolver you choose receives the lookups Repel does not block, under its own policy. We have no agreement with or data from any resolver.

Backup

If Android backup is on for your phone, your settings, rules, custom lists and custom DNS records are included in your Google account backup so a new phone keeps them. That backup is Google's, encrypted, and never reaches us. The pairing key, the activity log, downloaded lists and the diagnostics timeline are excluded. The App's own Export creates a file only where you choose to save it.

Data retention and deletion

Settings, rules and downloaded lists live on your device and are deleted when you uninstall the App or clear its data. Android gives an app no chance to act when it is uninstalled, so firewall blocks already in place stay until the next restart, and Private DNS stays on the provider you picked until you change it in Android's settings. Turn the firewall and Private DNS off in Repel before uninstalling to lift both at once. Analytics and crash data are retained by the services above under their own retention periods and are not linked to your identity. To have any data deleted, contact us at the address below.

Children

The App is not directed at children under 13 and we do not knowingly collect data from them.

Changes

We will update this page when the policy changes and update the date at the top.

Contact

Questions about this policy: support@llcloud.app