{"id":48986721,"url":"https://github.com/hoep/privycs-vpn","last_synced_at":"2026-06-14T21:01:12.074Z","repository":{"id":351129293,"uuid":"1209692023","full_name":"hoep/privycs-vpn","owner":"hoep","description":"Privycs VPN Client - Multi-Protocol VPN for Android and iOS (WireGuard + OpenVPN + IPSec)","archived":false,"fork":false,"pushed_at":"2026-06-10T14:14:03.000Z","size":15249,"stargazers_count":1,"open_issues_count":0,"forks_count":1,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-10T16:10:56.314Z","etag":null,"topics":["client","ipsec","multi-protocol","openvpn","strongswan","vpn","wireguard"],"latest_commit_sha":null,"homepage":"https://www.privycs.com/app","language":"Kotlin","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/hoep.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-04-13T17:26:28.000Z","updated_at":"2026-06-10T14:18:07.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/hoep/privycs-vpn","commit_stats":null,"previous_names":["hoep/privycs-vpn"],"tags_count":495,"template":false,"template_full_name":null,"purl":"pkg:github/hoep/privycs-vpn","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hoep%2Fprivycs-vpn","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hoep%2Fprivycs-vpn/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hoep%2Fprivycs-vpn/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hoep%2Fprivycs-vpn/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/hoep","download_url":"https://codeload.github.com/hoep/privycs-vpn/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hoep%2Fprivycs-vpn/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34337551,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-14T02:00:07.365Z","response_time":62,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["client","ipsec","multi-protocol","openvpn","strongswan","vpn","wireguard"],"created_at":"2026-04-18T13:03:03.256Z","updated_at":"2026-06-14T21:01:12.068Z","avatar_url":"https://github.com/hoep.png","language":"Kotlin","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Privycs VPN\n\n**One app, four protocols, your servers.** A multi-protocol VPN\nmanagement client for Android and Desktop (Windows / macOS / Linux),\nwith iOS planned. Works with any standards-compliant VPN server — not\ntied to a single provider.\n\n[![Latest release](https://img.shields.io/github/v/release/hoep/privycs-vpn?include_prereleases\u0026label=release\u0026color=3DDC84)](https://github.com/hoep/privycs-vpn/releases)\n[![Android CI](https://img.shields.io/github/actions/workflow/status/hoep/privycs-vpn/android-release.yml?event=push\u0026label=Android%20build)](https://github.com/hoep/privycs-vpn/actions/workflows/android-release.yml)\n[![Desktop CI](https://img.shields.io/github/actions/workflow/status/hoep/privycs-vpn/desktop-release.yml?event=push\u0026label=Desktop%20build)](https://github.com/hoep/privycs-vpn/actions/workflows/desktop-release.yml)\n[![iOS CI](https://img.shields.io/github/actions/workflow/status/hoep/privycs-vpn/ios-release.yml?event=push\u0026label=iOS%20build)](https://github.com/hoep/privycs-vpn/actions/workflows/ios-release.yml)\n[![License: GPL-3.0](https://img.shields.io/badge/license-GPL--3.0-orange)](LICENSE)\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"screenshots/connect.png\"      alt=\"Connect screen\"           width=\"200\"/\u003e\n  \u003cimg src=\"screenshots/multi-config.png\" alt=\"Multi-config connections\" width=\"200\"/\u003e\n  \u003cimg src=\"screenshots/pool.png\"         alt=\"Connection pool\"          width=\"200\"/\u003e\n  \u003cimg src=\"screenshots/tunnel-health.png\" alt=\"Tunnel health monitor\"   width=\"200\"/\u003e\n\u003c/p\u003e\n\n---\n\n## What this is — and isn't\n\n**Privycs is a VPN management client, not a VPN service.** You bring your\nown server (or commercial-provider configs); Privycs does the work of\n*managing* them: multi-protocol switching, connection pools with\nrotation, per-pool split tunnel, a real kill switch, per-app routing,\nencrypted backup.\n\nIf you have ever opened a 600-config archive from a commercial VPN\nprovider and wished there were one sane way to manage it — this is that\ntool.\n\n---\n\n## Why this exists\n\nThere is no shortage of VPN apps. There is a shortage of VPN apps that:\n\n- **Speak every real-world protocol in one binary** — AmneziaWG,\n  WireGuard, OpenVPN and IPSec/IKEv2. Most clients pick one. Privycs runs\n  all four through a single `VpnService` slot on Android and the same\n  daemon on Desktop, and switches protocol on a live connection with one\n  tap.\n- **Treat 600 configs as one thing.** The Connection Pool feature\n  collapses a whole archive into a single virtual connection with three\n  rotation policies (Geo-Nearest, Round-Robin, Random), pre-warm probes\n  and recovery against dead servers.\n- **Offer a per-pool split tunnel** — a bypass-CIDR list per pool that\n  routes specific IP ranges (your home LAN, a captive-portal range)\n  around the tunnel, IPv4 + IPv6.\n- **Have a real kill switch** — a sinkhole `VpnService` / OS-firewall\n  ruleset that blocks all traffic if the tunnel drops unexpectedly, not\n  just \"disconnect on drop\".\n- **Carry no telemetry** — no tracking, no analytics, no crash SDK, no\n  cloud dependency. Configs stay on your device unless you explicitly\n  export an encrypted backup.\n\n---\n\n## Features\n\n### Free\n- **Multi-protocol** — AmneziaWG, WireGuard, OpenVPN, IPSec/IKEv2 in one app\n- **Config import** — `.conf` (WireGuard / AmneziaWG), `.ovpn` (OpenVPN),\n  `.sswan` (Android IPSec), `.mobileconfig` (iOS IPSec)\n- **QR-code import** — scan a code from your gateway\n- **One saved connection, one protocol**\n- **Manual connect / disconnect** with live transfer stats and a sparkline\n- **Kill switch** — sinkhole-based traffic blocking on tunnel drop\n- **Tunnel health monitor** — periodic ICMP probe with a status indicator\n- **Home-screen widget + Quick Settings tile** (Android)\n- **Encrypted local backup** — AES-256-GCM with PBKDF2\n\n### Pro\n- **Multi-protocol per connection** — one connection holding WireGuard +\n  OpenVPN + IPSec, switchable live, with automatic health-driven failover\n- **Multiple connections** — unlimited saved connections\n- **Connect-on-Demand \u0026 network rules** — auto-connect by Wi-Fi network or\n  mobile data, with per-network trusted/untrusted rules\n- **Gateway sync** — pull config updates from your own Privycs server\n- **Connection pools** — import large config archives, three rotation\n  policies, pre-warm and dead-server recovery\n- **Per-pool split tunnel** — bypass-CIDR list, IPv4 + IPv6\n\nPricing and Pro details are on [privycs.com](https://www.privycs.com).\n\n---\n\n## Compatibility\n\nWorks with any VPN server speaking standard protocols:\n\n| Protocol | Tested with |\n|----------|-------------|\n| WireGuard | wg-quick, Mullvad, ProtonVPN, IVPN, Synology, OPNsense, OpenWrt |\n| AmneziaWG | AmneziaWG servers and the Privycs gateway (DPI-resistant WireGuard) |\n| OpenVPN | OpenVPN Community, Access Server, pfSense, OPNsense, Synology, AirVPN |\n| IPSec/IKEv2 | strongSwan, native macOS / iOS profiles, MikroTik, enterprise IKEv2 |\n\nPrivycs is gateway-agnostic — it imports and runs any standards-compliant\nconfig file. It also has first-class support for\n[Privycs](https://github.com/hoep/privycs), the companion self-hosted VPN\nmanagement server, for users running their own infrastructure.\n\n---\n\n## Download\n\nStable releases are on the\n**[GitHub Releases page](https://github.com/hoep/privycs-vpn/releases/latest)**\n— signed Android APK (ARMv8 / ARMv7 / x86_64) and Desktop builds for\nLinux, macOS and Windows.\n\nGoogle Play, Apple App Store and Microsoft Store listings are planned.\n\n---\n\n## Building from source\n\n### Desktop (Windows / macOS / Linux)\n\n```bash\ncd desktop\ngo install github.com/wailsapp/wails/v2/cmd/wails@latest\nwails build                 # produces ./build/bin/privycs-vpn\n```\n\nRequires Go 1.23+, Node.js 20+ and the Wails v2 CLI. Platform\ndependencies: GTK3 + WebKit2GTK (Linux), Xcode Command Line Tools\n(macOS), WebView2 (Windows, bundled). `go build ./...` is a quick way to\nverify the Go backend compiles.\n\n### Android\n\n```bash\ncd android\n\n# One-time submodule prep — autogen strongSwan, build OpenSSL, apply the\n# vendor patches. Re-run after every `git submodule update`.\nANDROID_NDK_ROOT=/path/to/ndk ./scripts/prepare-strongswan.sh\n./scripts/prepare-amneziawg.sh\n\n./gradlew assembleDebug\n```\n\nRequires Android Studio, Android SDK 35, JDK 17 and NDK 27.3.13750724.\nThe vendor-patch workflow is documented in\n[`android/vendor/strongswan-patches/README.md`](android/vendor/strongswan-patches/README.md).\n\n### iOS *(planned)*\n\nA SwiftUI app with a Network Extension — WireGuardKit and the native\n`NEVPNProtocolIKEv2` API. OpenVPN is initially excluded: the open-source\niOS OpenVPN wrapper is AGPL-3.0, which would relicense the whole iOS app.\n\n---\n\n## FAQ\n\n**Is Privycs a VPN service?**\nNo. Privycs is a *client* for VPN servers you already have or obtain\nelsewhere. It runs no servers and sees no traffic. You bring the config\n(`.conf`, `.ovpn`, `.sswan`, `.mobileconfig`); Privycs manages the\nconnection.\n\n**Why not just use the WireGuard / OpenVPN / strongSwan apps?**\nEach speaks one protocol. If your server exposes WireGuard *and* OpenVPN\nas failover, you would otherwise need two apps and switch manually.\nPrivycs does both in one app, on the same connection, with a tap.\n\n**Does it log anything?**\nNo analytics, no crash reporters, no telemetry. The apps make no network\ncalls outside the tunnel except optional gateway sync (if you configure\nan API key) and one-time DNS lookups during pool import.\n\n**Does it work on a rooted / jailbroken device?**\nYes. There are no root checks, attestation or device fingerprinting.\n\n**Where do I report a bug?**\n[Open an issue](https://github.com/hoep/privycs-vpn/issues/new). Logs\nhelp — Settings → View Logs, with any secrets redacted.\n\n---\n\n## Architecture\n\n```\ndesktop/      Desktop app — Go backend + Vue 3 frontend (Wails v2)\nandroid/      Android app — Kotlin + Jetpack Compose\n  vendor/     pinned ics-openvpn, strongSwan and AmneziaWG submodules\nios/          iOS app (planned)\nscreenshots/  README assets\n```\n\n---\n\n## Contributing\n\nContributions are welcome — see [CONTRIBUTING.md](CONTRIBUTING.md).\nPlease open an issue to discuss significant changes first. For security\nreports, see [SECURITY.md](SECURITY.md).\n\n---\n\n## License\n\n**GPL-3.0** — see [LICENSE](LICENSE). The Android app links GPL-2.0\nlibraries (ics-openvpn, strongSwan), which makes the combined work\nGPL-3.0. WireGuard and AmneziaWG components are MIT / permissively\nlicensed. Full open-source attributions are listed in-app under\nSettings → About → Open-Source Licenses.\n\n---\n\n## Related projects\n\n- [Privycs](https://github.com/hoep/privycs) — the self-hosted VPN\n  management server this client optionally pairs with\n- [privycs.com](https://www.privycs.com) — website and documentation\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhoep%2Fprivycs-vpn","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhoep%2Fprivycs-vpn","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhoep%2Fprivycs-vpn/lists"}