Android lets one app at a time act as a VPN and decide which apps’ traffic passes through it. NetCage takes that slot and points it at nothing: packets from the apps you caged are read and discarded, so those apps see a network that never answers. No server is involved, and nothing leaves the phone.
A normal VPN forwards your traffic to a server somewhere else. NetCage forwards it nowhere: the tunnel is a sinkhole on the device itself, so a caged app’s connections fail the way they would on a phone with no signal. That is why NetCage needs no subscription, no account and no server — and why it cannot see anything even in principle.
Android’s VPN interface can be told exactly which packages to route. NetCage names only the apps you caged, so every other app on the phone talks to the network directly and never touches NetCage at all. That is the difference between this and a VPN you install for privacy: uncaged traffic is not filtered, not slowed and not seen.
There is nothing to log. NetCage discards packets without parsing them, and it sets no DNS server, so no hostname, URL or destination is ever resolved, recorded or forwarded. This is not a promise about a log kept carefully — it is the absence of the code that would create one.
A cage that lapses at 3am is not a cage. NetCage restores what you set as soon as Android allows it after a restart, using a snapshot stored where the system can read it before the phone is unlocked, so a scheduled block starts on time on a phone nobody has touched yet.
Almost nothing, and the reason is structural rather than a matter of tuning. A conventional VPN encrypts every packet and forwards it to a server, which costs battery, latency and sometimes bandwidth. NetCage encrypts nothing, contacts nothing and forwards nothing: it reads packets from caged apps and drops them. Uncaged apps are not routed through it at all, so their speed is exactly what it was before you installed anything.
On a rooted phone NetCage can use firewall rules instead of the VPN slot, which frees that slot for a real VPN. It ships switched off and labelled experimental for one honest reason: it has never been run on rooted hardware. Its logic is tested; its behaviour on a real rooted device is not, and the label stays until it is.
Claims about a VPN are worth what you can verify. So NetCage shows the tunnel’s real state instead of an optimistic icon, lists every permission it holds with what each one is for, records what it did in an event log you can read, and documents the mechanism in public. Where something cannot be verified — the root engine, which has never run on rooted hardware — it says so in the app rather than in a footnote.
Android gives the VPN slot to one app, so connecting another VPN replaces NetCage and its cages stop applying until you switch back. Some manufacturers also kill background apps harder than others. NetCage tells you when the tunnel is down rather than looking active while doing nothing — but do not rely on it where a failure to block would harm you.