Nest Privacy Policy
Last updated: 2026-08-13
Short version: Nest collects nothing about you. There are no accounts, no servers of ours, and no analytics. Your configuration, logs and records stay on your own device.
1. What Nest is
Nest is a network configuration and connection management tool (built on the sing-box core) that runs locally on your device and decides which route your traffic takes, according to a configuration you supply yourself.
We do not operate any servers or routes and we do not provide network access of any kind. You connect to servers you imported or entered yourself, which have nothing to do with us.
2. Personal information we collect
None. Nest has no account system and requires no registration or sign-in. It does not collect your name, email address, phone number, contacts, location or advertising identifiers.
The app bundles no third-party analytics, advertising or remote crash-reporting SDK and sends no telemetry to us — we operate no server that could receive it.
It follows that we do not sell, rent or share your personal information with anyone: we hold no data that could be sold.
3. Data stored on your device
Nest writes the following to local storage on your device (its own sandbox and App Group container). None of it leaves your device unless you export or share it yourself:
- Subscriptions and configuration — the subscription URL you imported, the converted configuration, and your current node / policy-group selection
- App settings — interface preferences, dashboard items, outbound mode and so on
- Runtime logs and connection records — for troubleshooting the current session only; not retained long-term
- Crash and memory reports — generated locally when the app or its network extension terminates unexpectedly; they leave your device only if you explicitly export or share them from within the app
Deleting the app deletes all of the above.
4. Network addresses Nest contacts
Your device makes the following requests directly. None of them pass through any server of ours:
| Destination | Purpose |
|---|---|
| Your subscription URL | Fetches nodes and configuration directly from your provider |
cdn.jsdelivr.net | Downloads routing rule sets (.srs) and the policy-group icon mapping |
| Icon image hosts | Displays policy-group icons, cached locally by the app |
www.gstatic.com | Latency tests for nodes, sent through the route you selected |
api.ipify.org | Shows your current exit IP on the dashboard. This request also goes through the tunnel, so what the service sees is the exit IP of the node you selected, not your own |
captive.apple.com | Apple's connectivity probe, used by the on-demand connection rules; it may also be used at first launch to trigger the system's local network permission prompt |
api.github.com | macOS build only, when checking for a core update |
These requests expose your IP address and other ordinary network information to the respective services. How they handle it is governed by their own privacy policies and is outside our control.
5. About the network extension permission
Nestuses Apple's Network Extension framework to handle network connections locally on your device. This is what makes routing by configuration possible, and it is why the system shows a network indicator in the status bar.
Everything is processed on your device and connects directly to the servers you configured. We neither see nor log the sites you visit, the content you transfer, or any connection information.
6. iCloud
If you choose to store a configuration file in iCloud, that file lives in your own iCloud Drive, hosted by Apple and governed by Apple's privacy policy. We cannot access its contents.
7. Children's privacy
Nest is not directed at children under 13 and does not knowingly collect their personal information — in fact it collects no personal information from anyone.
8. Changes to this policy
If this policy changes we will update the “last updated” date at the top of this page. Material changes to how data is handled will also be surfaced in the app.
9. Contact
Questions about this policy: randylu@owlltech.com