ThrottlyNetwork debugging for Android

Your data

Privacy policy

Effective · Free & paid editions

Throttly applies network conditions and records network activity on your Android device. It does not route your traffic through a Throttly VPN server. The app automatically sends crash diagnostics to Google Firebase Crashlytics. This policy explains these separate data flows and the controls available to you.

1. What this policy covers

This policy covers the free and paid editions of Throttly for Android, including the Pro purchase available in the free edition, and this privacy website. Throttly is a network debugging tool. It does not require a Throttly account and does not include advertising or a product-analytics SDK.

2. Local VPN and network activity

When you start a session, Throttly uses Android's VpnService to process traffic from all apps in its VPN scope or the apps you selected. It reads and forwards network packets locally to apply bandwidth limits, delay, jitter, packet loss, or offline conditions. Monitoring continues while the session runs, including when Throttly is in the background. Stopping the session stops this monitoring.

Throttly records DNS query names and types, returned IP addresses, query and response times, connection destinations and ports, TCP/UDP protocol, connection start and end times, outcome, traffic totals, and the originating app's package name when Android can identify it. It also stores the session's selected apps, DNS configuration, network conditions, and condition changes. These records power the Session view and remain in the app's local database; the app does not upload that database to us.

Packet contents are processed in memory to provide the VPN function. Throttly does not save packet captures or HTTP request and response bodies, install a certificate to decrypt HTTPS, or provide a remote VPN tunnel. Ordinary traffic goes to its original destinations through your existing network. DNS queries go to your current network's resolver or the resolver you configure, which receives the queried domains and your network address.

The local VPN does not hide your public IP address or add encryption to traffic. Protection in transit depends on the protocols used by the originating app and destination. The built-in DNS forwarding uses ordinary UDP/TCP DNS, not DNS-over-HTTPS or DNS-over-TLS. Destination services, network operators, and DNS providers handle data under their own terms and policies.

3. App selection and saved settings

Throttly reads launcher-visible installed apps, including their names, package names, and icons, so you can select targets and recognize activity. The free edition also checks whether the matching paid edition is installed and signed by the same developer to unlock Pro. The app does not upload an installed-app inventory to us.

Your target selection, custom network conditions, DNS settings, appearance preferences, and last confirmed Pro entitlement are stored on your device. Network and VPN permissions enable routing and monitoring. Notification permission enables session controls, and local-network permission is used where required for local-network access.

4. Automatic crash diagnostics

Firebase Crashlytics, a Google service, automatically receives crash and app-stability diagnostics to help us identify and fix failures. These may include crash and handled-exception stack traces and messages, app version and state, timestamps (including when the app enters the foreground), Android version, device model, resource and network-type information, and installation and session identifiers used by Firebase. This reporting is enabled automatically; Throttly currently does not offer an in-app opt-out.

We do not attach the Session database, packet captures, installed-app inventory, or ordinary application logs to these reports, and we do not set an account name, email address, or custom user ID in Crashlytics. Exception messages can nevertheless contain context from the operation that failed. These reports are diagnostics, not anonymous data, and may be available to the developer through Firebase.

Firebase encrypts diagnostic data in transit using HTTPS. Its documented retention for crash traces and associated identifiers is 90 days before it begins removal from live and backup systems. Crash reporting also uses Firebase Installations and Firebase Sessions; their identifier and diagnostic processing follows the Firebase documentation linked below. Locally queued reports can be sent on a later launch when a connection is available. Clearing Session activity does not delete reports already sent to Firebase.

Firebase privacy and retention

Firebase Android data disclosure

5. Google Play purchases

In the free edition, Google Play Billing provides product prices and purchase information so Throttly can offer, confirm, and restore the one-time Pro upgrade. The app processes purchase status and purchase tokens on the device and acknowledges purchases through Google Play. It caches the last confirmed entitlement for offline use. There is no Throttly purchase-validation server.

Google Play handles checkout and payment details. Throttly does not receive your full payment-card details. Buying the paid edition is also handled by the store; that edition does not include the in-app Billing library. Google processes store, account, and transaction data under its own policies. Clearing Throttly's local data does not erase Google's transaction records or cancel a purchase.

Google Privacy Policy

6. Local retention and deletion

Detailed DNS, connection, and condition-change records belong to the most recent session. Starting a new session removes the previous session's detailed activity. DNS and connection records are periodically trimmed to about 500 DNS records and 2,000 connections; batching can temporarily keep more. Up to 50 session summaries, including their configuration snapshots and traffic totals, are retained separately. These are count-based limits, not a promise of deletion after a fixed number of days.

Use Clear activity in Session to delete that session's DNS and connection records. This leaves its summary, configuration snapshot, and condition timeline intact. If the session is still running, new activity continues to be recorded. Stop the session first if you do not want more activity to appear.

Use Android Settings to clear Throttly's app storage, or uninstall the app, to remove its local database and preferences. Saved settings otherwise remain until you change or delete them or clear the app's storage. Throttly disables Android cloud backup. Device-to-device migration can depend on the Android version and device manufacturer's behavior. Local deletion does not remove diagnostics or transaction records already held by Google.

7. Data protection and recipients

Local records are kept in Throttly's Android app storage, protected by Android's application sandbox and your device's security controls. Throttly does not add a separate encryption layer to its local database. Device access, operating-system security, and backups outside the app's control can affect confidentiality.

We use Google Firebase for diagnostics, Google Play for purchases, and Cloudflare to host this website. They and their service providers may process data outside your country. Throttly does not sell network activity, use it for advertising, or redirect other apps' traffic for monetization. This policy does not change the data practices of the apps whose traffic you choose to monitor.

This privacy page is hosted by Cloudflare, which processes IP addresses and technical request information to deliver and protect the website. We do not add advertising or analytics scripts to this page.

Cloudflare Privacy Policy

8. Your controls

You decide when to start and stop a VPN session and which available monitoring scope to use. You can revoke Throttly's VPN authorization in Android Settings. Declining the VPN disclosure prevents a session from starting. It does not disable the separate automatic crash-reporting service.

You can inspect and clear local network activity as described above, change your settings, and remove local app data through Android. Throttly has no user account to delete. Rights to access, correct, delete, restrict, object to, or obtain a copy of personal data may also apply under the laws where you live; local app controls do not themselves delete data already processed by external services.

9. Policy updates

We update this policy when Throttly's data practices change and revise the effective date. The latest policy is available on this page and through the Privacy policy link in the app settings. Changes that require a new in-app disclosure or consent will be presented before the affected processing where required.