Privacy Policy
Last updated: 2026-08-27
This policy explains what the dnsetter Android app
(name.gpm.dnsetter) does with data. It covers the app only.
The short version: dnsetter changes one system setting on your phone and remembers what it changed, so that it can put it back. Nothing about your DNS, your VPN, your rules or your settings ever leaves the device. The only thing that leaves it is what you type into the report screen or the messages screen, and neither of those runs on its own.
Who is responsible
Gabriele Proietti Mattia is the data controller for the processing described here. Contact: apps@gpm.name.
What the app does, in data terms
To do its one job, dnsetter reads and writes Android’s Private DNS setting
(private_dns_mode and private_dns_specifier), watches for a VPN connection through the
system’s network callback, and asks Android which apps on the phone can create a VPN, so
that a rule can be attached to one. That last question is answered on the device and the answer
is used on the device: the list of your installed apps is never sent anywhere.
All of it happens on your phone, and none of it is transmitted.
Writing in, and reading the answers
dnsetter has a report screen — something is wrong, or an idea — and a messages screen where you can read what was written back. Both are in the Info tab, both are optional, and neither runs on its own: nothing is sent until you write something and press send.
This is the only reason the app asks for internet access at all.
What a report carries
- What you wrote: whether it is a bug or an idea, the title and the description.
- What makes it fixable: the app’s version, your Android version, the phone’s manufacturer and model, and your language tag. Typed into the message by the app — none of it is read from an identifier.
- A screenshot, only if you pick one. Nothing is captured for you. The picture is shrunk and re-encoded on your phone, and what you see before sending is exactly what leaves it — so if part of the screen has nothing to do with the problem, remove it first.
- Your email address, only if you type one. Without it a report is anonymous and cannot be answered; with it, it is how you get a reply.
- A random identifier for that single report, so that sending twice on a bad connection is not counted as two. It is not a device id, it is not stored on your phone, and a second report gets a different one.
It goes to apps-management.gpm.name, a service run by the author. It is not shared with
anyone, not used to build a profile and not published: reports are read, given a state and
answered by hand.
No advertising id and no install id, ever — in a report or anywhere else. And nothing about what dnsetter does on your phone is attached to a report: not which VPN you use, not which resolver you had configured, not what the app has switched.
Reading the answers, and the key that costs
A report is answered by email, to the address you typed into it. That is the whole of what is needed, and if you never open the messages screen nothing below applies to you.
That screen shows what you sent and everything written back, without going to find the mail. Since your reports are yours, it has to be sure it is you: it asks for the address and sends a six-digit code there. Once the code is checked the app keeps a key, and it is the one thing here that resembles a login, so it is worth being exact about it:
- it hangs from the address you proved, never from your phone — nothing about the device goes into it, two phones that prove the same address get two separate keys, and removing the app throws the key away rather than recovering it;
- it works for dnsetter only, and opens nothing in any other app;
- the service stores a one-way hash of it, not the key itself;
- it stops working after a year without use, and Sign out withdraws it at the service and not only on your phone.
Sending a report needs none of this. You can report something having proved nothing, and that report carries no identifier of any kind.
Your name on the supporters list
The app can show who paid for it, and that list is public — on this site and in the app. Being on it is a separate decision from paying, taken on a screen of its own, and both defaults are no: somebody who never opens that screen is never listed.
- What is published is the name you typed, and nothing else. Never your address, never an amount, never a date, and never a position — the list is shuffled every time it is drawn.
- How you prove it is yours depends on how you paid. If you subscribed on Google Play, the app presents the purchase token it is holding — Play never tells an app who bought, so there is nothing to type and no address involved. If you donated, you prove the address you donated from, exactly as above, and the service checks whether a donation is recorded against it.
- The choice belongs to this app. Supporting dnsetter is not asking to be named anywhere else, and the name you pick here is not carried to another app.
- It is reversible in one tap, from the same screen, and the name is gone from the public list on its next load.
Feature requests and votes
The same screen lists what people have asked for in dnsetter, and lets you ask for something and vote. Reading that list costs nothing and needs no address. Asking and voting do, for one reason: one vote per person is a promise, and without something to hang it on the count would mean nothing.
What is published is the request itself, once it has been read. Never your address, and never who voted for what.
What stays on your device
- Whether the app is armed, and what it should do about a VPN that has no rule of its own.
- Your rules: one per VPN app you have given one to, keyed by that app’s package name.
- The setting the app is holding on your behalf — the Private DNS mode and, where you had one, the hostname. This is the value the app exists to give back to you, and it is kept in plain form on purpose, so that it can be recovered by hand if something ever goes wrong with it. It is not a credential and it is not a secret: it is the address of the resolver you chose.
- What the app last did, and when, which is what the Status tab shows you.
All of it is in the app’s private storage. Uninstalling removes it, as for any app, and it is included in Android’s backup so that a new phone starts where the old one left off.
The permissions, and what each is for
WRITE_SECURE_SETTINGS— changing Private DNS. It is the whole app, no dialog can grant it, and you give it once over ADB or Shizuku. It is a powerful permission and it is worth knowing what this app does with it: it writesprivate_dns_modeandprivate_dns_specifier, and nothing else.- A foreground service, and its notification — Android publishes no broadcast for “a VPN came up”, so the only way to hear about one is to be running. That is what the permanent notification is.
- Notifications — the permanent one above, and the notice when a switch happens.
- Start at boot — so the app is watching again after a restart, which is the failure it exists to prevent.
- Internet — the report and messages screens, and nothing else. See above.
- The VPN app query — not a permission but a declaration, and the reason the rules screen can put a name to a tunnel. Answered and used entirely on the device.
Diagnostics
There are none, in either build. No crash reporting, no analytics, no usage counters, and nothing switched off that could be switched on. The Play build differs from the F-Droid build in one thing only: it contains Google Play Billing.
What the app never does
- No account and no sign-up, and no password anywhere. An email address only if you type one in yourself — to be answered about a report, to read those answers in the app, or to vote for a request — and never for anything else.
- No advertising, and no sale or sharing of data with anyone.
- No tracking, across this app or any other.
- No location, no movement history, no contacts, messages, call history, photos or files — beyond the single screenshot you choose to attach to a report.
- No record of your DNS or VPN activity anywhere but your phone, and no lookups of its own: dnsetter resolves nothing and proxies nothing. It changes a setting and gets out of the way.
- It never creates a VPN of its own.
Legal basis (GDPR)
For readers in the EU/EEA and the UK: what the app does on your device involves no transmission to Gabriele Proietti Mattia and so no processing on that side to which a legal basis under Article 6 would attach.
Where you write in — a report, the messages screen, a feature request or a vote — the processing is based on your request (Article 6(1)(b) and 6(1)(f)): you asked for an answer, and answering you requires keeping what you sent for as long as the question is open.
Retention
A listing — your chosen name — is kept until you take it down, which is one tap on the same screen that put it up.
Reports are kept while they are useful — an open one until it is answered, a closed one as the record of a decision. A screenshot is part of the report it came with and goes when it goes. Ask and yours is deleted, including the address you sent it from.
A sign-in key stops working a year after you last use it, and is withdrawn the moment you press Sign out. Deleting the app removes the copy on your phone.
On your device, your rules and the setting being held remain until you delete them or uninstall the app.
Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data. For anything you sent from the report or messages screen, write to apps@gpm.name and it is done by hand. For what is on your device, deleting it is a matter of clearing the app’s data or uninstalling it. You retain the right to lodge a complaint with a supervisory authority.
Children
dnsetter is not directed at children under 13 and knowingly collects no data from them — or from anyone.
Changes
Material changes will be published on this page with a new date at the top, and significant ones will be noted in the app’s changelog.
Last updated: 2026-08-27