Legal and advertising transparency
Privacy Policy
The AROT privacy policy explains data collected by website pages, blog posts, VPN token services, manual downloads, Android app listing links, support mailboxes, advertising systems, backend services, and cloud infrastructure.
The policy discloses advertising and consent practices for Google AdSense, AdMob, cookies, mobile advertising identifiers, approximate location, consent signals, ad measurement, and fraud-prevention events where those features are enabled.
AROT VPN is described as a privacy-focused connectivity utility. The policy states that AROT does not intentionally retain browsing history, DNS query contents, page payloads, or tunnel traffic content for profiling, while limited operational logs may be used for token access, bandwidth accounting, abuse prevention, server health, and support.
The page links vendor policies for Google, Supabase, Vercel, Cloudflare, and Telegram so readers can review the third-party processors involved in ads, hosting, backend operations, security challenges, and support communities.
Users can manage ad personalization through Google My Ad Center, use browser or device controls for cookies and advertising identifiers, and contact privacy@arot.tech for privacy requests.
The policy separates website data, VPN data, support data, and advertising data so readers can understand why each category exists. Website data helps serve pages and diagnose broken routes. VPN data supports token issuance, session status, bandwidth limits, and abuse prevention.
Support emails may include addresses, screenshots, page URLs, device details, token errors, checksum results, and source references supplied by the user. Those details are used to answer the request and investigate the reported issue.
Advertising disclosures are explicit because ad-supported pages can involve third-party cookies, device identifiers, consent strings, ad delivery events, and measurement signals. Turning off personalized ads may change ad selection but does not remove all advertising.
The policy explains that consent should be requested where legally required, including for personalized advertising and local storage in regions such as the European Economic Area, the UK, and Switzerland.
Data retention is described as functional rather than indefinite. Records should be kept only as long as needed for service operation, security, support, legal compliance, dispute resolution, or abuse prevention.
The security section points to HTTPS, token-based access, challenge checks where configured, checksum publication, and backend controls while making clear that no networked service can promise perfect security.
Children, international transfers, user choices, and update procedures are covered so the page is not just an ad-cookie notice. The contact route gives a direct mailbox for access, correction, deletion, consent, and privacy questions.