Zypop
Privacy Policy

Zypop collects nothing.

There is no account, no analytics, no advertising SDK, and no server that belongs to us. Nothing Zypop learns about your browsing ever leaves your device, because there is nothing in the app capable of sending it.

Last updated 15 September 2026 Zypop for Android 1.1.0 and later
0
bytes of personal data collected
0
servers that belong to us
0
analytics, ad or crash SDKs
1
local address in the tunnel, on your phone

The rest of this page says exactly how that is true, and where the limits are, because a privacy policy that only makes promises is worth very little.

What Zypop does

Zypop is a DNS filter. When an app on your phone looks up a domain name, Zypop compares that name against filter lists you have chosen and either answers "this does not exist" or passes the lookup on to the DNS resolver your network was already using.

To see those lookups it uses Android's VPN interface. This is a local VPN: the tunnel carries exactly one address, 10.111.222.2, which is Zypop's own resolver running inside the app on your phone. No traffic is routed to a remote server. Zypop is not a proxy, it is not an anonymity tool, and it does not hide your IP address.

What data Zypop collects

None.

No personal data, no device identifiers, no usage analytics, no crash reporting.

Zypop has no backend. There is no server to which data could be sent, and no third-party SDK in the app that could send it elsewhere.

What Zypop stores on your device

All of this lives in Zypop's private app storage, readable only by Zypop. Android's backup is disabled for the app (allowBackup="false"), so none of it reaches Google Drive or any other cloud backup. Uninstalling Zypop deletes all of it.

Your settings

Protection on/off, blocking mode, update preferences, whether the activity log is on. So the app behaves the way you set it up.

Filter lists

Which lists you have enabled, any lists you added by URL, and their downloaded contents. These are the rules. Without them nothing is blocked. A list you add is fetched from the address you gave and its terms are yours to check.

Custom rules you type in yourself

You entered these deliberately, and they are the only place a domain name you chose is written down. They are never uploaded.

Excluded apps, by package name

So the tunnel can be built without them. The list of installed apps that the Excluded apps screen shows is read from Android when you open that screen and is not stored.

Counters

How many requests were blocked or allowed, by category. So the app can show you a total.

The activity log Only if you switch it on

See below. Off by default; nothing is written until you turn it on.

The counters are worth being precise about, because "blocking statistics" often means a log of visited sites. In Zypop they are integers and nothing else. Out of the box there is no structure anywhere in the app that records which domains were blocked, or when, or in what order. That is why the app can show you "1,284 blocked" but cannot show you a browsing history — the history was never kept.

The activity log

The one exception, and you have to ask for it. Settings has a switch called Record activity, off by default. While it is on, Zypop keeps, for each domain this device looks up, how many times that domain was blocked, how many times it was allowed, and when it was last seen. The Activity tab shows this list so you can see what an app talks to, find out why a site broke, and block a whole domain from there.

What it is, precisely:

  • Counts per domain, not a timeline. There is no record of individual lookups, their order, or their timing beyond "last seen", and no record of which app made them.
  • Why, for a refused domain. Which filter list or which of your own rules refused it most recently, and — when the block came from an alias in the DNS answer rather than the name itself — that alias name, so you can see what a site was really talking to.
  • Capped. The 1,000 most recently seen root domains are kept; older ones are discarded automatically.
  • On this device only. It lives in Zypop's private storage like everything else, with backup disabled, and is never transmitted anywhere. Nothing in the app is capable of uploading it.
  • Yours to delete. The Activity tab has a Clear the log button. Switching the log off stops recording immediately; what was already recorded stays until you clear it, so that turning it off is never the thing that destroys something you wanted to read. Uninstalling deletes it.

If you never switch it on, this section describes nothing that happens on your phone.

What leaves your device

Two kinds of network traffic, and no others.

1

DNS lookups Zypop allows

These go to the DNS resolver your device and network were already using — the one configured by your Wi-Fi router or your mobile carrier. Zypop never substitutes a public resolver of its own choosing and never sends your lookups to a resolver you did not already have. If Zypop were switched off, these exact lookups would go to the exact same place.

2

Filter list downloads

Periodically, and only when your settings allow it, Zypop downloads the filter lists you have enabled over HTTPS from their publishers. This is a plain request for a file. It carries no body, no query parameters, no cookies and no identifier — there is no field in it capable of carrying a domain you visited. Data flows towards you, not away.

Those publishers, like any web server, will see the IP address making the request, as they would for any file download. They are listed below so you can read their own terms.

Permissions, and what each one is for

VPN access

Asked the first time you turn protection on. The only way an app on Android can see DNS queries. Routes one local address; no remote server.

INTERNET

To forward the lookups Zypop allows, and to download filter lists.

ACCESS_NETWORK_STATE

To read which resolver your network already uses, so Zypop never quietly substitutes a third party's, and to tell a metered connection from an unmetered one.

POST_NOTIFICATIONS

For the ongoing "protection is on" status. Refusing it costs the notification and nothing else.

RECEIVE_BOOT_COMPLETED

To switch protection back on after a restart, if it was on before. Nothing else uses it.

FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE

To keep the filter running while you use your phone, rather than being killed in the background.

App visibility (a <queries> declaration, not a runtime permission)

So the Excluded apps screen can list the apps that have a home-screen icon. Zypop does not ask to see every package on the device; apps without an icon are not listed and cannot be excluded. Nothing read here leaves the device.

Filter lists and their terms

Zypop bundles no list content. Each list is downloaded by your device from its publisher, who remains its author. Every list below except URLhaus is switched on when you install Zypop, so on first run your device fetches all of them from the publishers listed below (about 75 MB in total); each is refreshed afterwards only as your update settings allow. Any list can be switched off on the Filters screen.

ListPublished byTerms
StevenBlack unified hosts StevenBlack/hostsMIT
AdGuard DNS filter AdGuardGPL-3.0
URLhaus malware hosts abuse.chabuse.ch Terms of Use — not an open licence
HaGeZi Multi LIGHT, Multi PRO, Multi ULTIMATE, Threat Intelligence (mini and medium), Pop-Up Ads, Fake, DynDNS, Badware Hoster, Encrypted DNS Bypass, DoH/VPN/Proxy Bypass, URL Shortener, Social, Gambling (mini and full), NSFW, Anti-Piracy, No Safe Search, and Native Tracker for Samsung, Xiaomi, Huawei, OPPO/Realme, Vivo, TikTok (and extended), Amazon, Apple, LG webOS, Roku and Windows/Office hagezi/dns-blocklistsGPL-3.0
oisd small, oisd big, oisd NSFW oisd.nlGPL-3.0
1Hosts Lite badmojr/1HostsMPL-2.0
AdAway mobile ad providers AdAwayCC BY 3.0

The URLhaus list ships switched off. abuse.ch publish it under their own Terms of Use rather than an open licence, and those terms restrict commercial use and automated bulk access. Turning it on is your decision to make after reading their terms, so Zypop does not make it for you.

Backups you make

Settings → Backup writes your configuration — settings, which lists are on, lists you added, your own rules, excluded apps — to a file you choose the location of, through Android's file picker. Zypop never sees the path and has no storage permission. The file never contains the activity log, the counters, or anything else derived from what you browsed; it is safe to keep, move or share. Importing merges it in and never turns protection on by itself.

Diagnostics reports you make

Settings → Diagnostics → Save a diagnostics report writes one plain-text file, through the same file picker, to a location you choose. It exists to attach to a bug report. It contains the app version, the Android version and device model, whether protection is running and why it is not, your settings as on/off switches, each filter list with its rule counts and the code of its last failed update, the block and allow counters as totals, and the last few hundred lines the app has logged about itself since it started — things like "index assembled" and "update failed: 404".

It does not contain any domain your device looked up, any entry from the activity log, your own rules (only how many), or which apps you excluded (only how many). The only address in it is the URL of a filter list you added yourself, since a list that will not download is the usual reason to send one.

Those log lines are held in the app's memory only, and only while it is running. Release builds write nothing to Android's system log, to disk, or to the network; the report is the one way they leave the device, and only when you save it.

Children

Zypop is not directed at children and collects no data from anyone, including children.

Limits you should know about

An honest privacy policy states what the tool cannot do.

Encrypted DNS can bypass Zypop

Apps and browsers that use DNS-over-HTTPS or DNS-over-TLS with a resolver of their own resolve names on their own. By default Zypop refuses the well-known encrypted resolvers by name, which makes such clients fall back to the system DNS it filters; a client that reaches its resolver by IP address is still invisible to it. Treat the block counter as a floor, not a total.

Domain-level blocking has a ceiling

Zypop cannot remove an ad served from the same domain as the content around it.

One active VPN at a time

Android allows one active VPN at a time, so Zypop cannot run alongside another VPN app.

Zypop is not a privacy VPN

It does not hide your IP address, does not encrypt your traffic, and does not change which country you appear to be in.

Changes to this policy

If this policy changes in a way that affects what Zypop does with your data, the change will appear here with a new date, and in the release notes for the version it applies to.

  1. 15 SEPTEMBER 2026 · 1.1.0

    Added the Diagnostics reports you make section. The app now keeps its last few hundred log lines in memory so you can save them as a report; nothing is written or sent unless you do.

  2. 19 SEPTEMBER 2026 · 1.1.0

    Every openly licensed list is now on by default, so a new install contacts every list publisher below on first run rather than one. Ten HaGeZi lists and oisd NSFW were added, including adult and gambling lists that block those sites outright. What is sent to a publisher is unchanged: a request for the list.

  3. 19 SEPTEMBER 2026 · 1.1.0

    Sixteen more HaGeZi lists are on by default — every list that publisher offers in DNS syntax, save two the app cannot apply. Among them are Anti-Piracy and Social, which block piracy sites and the social networks outright the way the adult and gambling lists do, and a bypass list that blocks VPN, Tor and proxy providers. Same publisher, same terms; what is sent is unchanged.

Questions about this policy?

Write to the developer directly. There is no form, so there is nothing in between.

ayushtimalsina2002@gmail.com