NetCage is a per-app firewall that runs on your device. This page sets out exactly what it does and does not collect. It is the binding version referred to by the app and by its Google Play listing.
Your browsing. Packets from caged apps are discarded without being parsed, and NetCage sets no DNS server. There is no DNS log, no URL log and no traffic record, on the device or anywhere else. Apps you have not caged never enter the tunnel at all.
That list is the most revealing thing NetCage knows, and it is treated that way. It stays on your device unless you sign in, in which case it is stored in your own row of the developer’s database so your other phones can read it. It is never sent to analytics or to crash reporting — those receive counts and fixed labels only, never a package name.
Sign-in is optional and uses Google. The account holds your email address, your name as Google supplies it, an account identifier, and your synced configuration: rules, profiles, schedules, preferences, hidden apps and any custom icons you set. Every feature of the app works without an account.
Two identifiers leave the phone, and only with the matching switch on. The Android advertising ID is read by Google Analytics for Firebase and travels with the usage data; it is used to count and group activity, never to target advertising, and nothing is sold. The push token identifies your installation to OneSignal so an announcement can reach it, and it exists only once you allow notifications. The app also shows a promotion for another app by the same developer: that list is compiled into the download, so it makes no network request and reads no identifier at all.
If you set a custom icon for an app, Android’s own picker opens and hands NetCage the single image you select — it has no access to the rest of your gallery, and it never opens the picker on its own. That image is stored in the developer’s own file storage so your other phones can show the same icon, and your row of the database keeps a reference to it. Removing the icon, or deleting your account, removes the stored file.
Supabase hosts the developer’s database and handles sign-in. Custom icons are held in FilesHub, which is the developer’s own file service rather than a third party. Google Analytics for Firebase, Amplitude and Microsoft Clarity receive usage data, and Sentry receives crash reports — each behind its own switch in Settings, and each off entirely while its key is absent. OneSignal delivers announcements if you allow notifications. The switch covering the first three is labelled “Share anonymous usage data” in Settings; what rides with it is set out under Device identifiers below.
The VPN permission is the product: Android grants it through its own dialogue, no app can bypass that, and without it NetCage cannot cage anything. Seeing your installed apps is what fills the list, so refusing it leaves nothing to choose from. Notifications carry the tunnel’s status, and Android requires that notice while a VPN is running. Starting at boot brings your cages back after a restart; refuse it and they stay off until you open the app. Exact alarms make schedules and day passes end on time rather than minutes late. The battery exemption stops Android suspending the tunnel; without it a cage can lapse while the phone is idle. Usage access is optional and only powers the per-app data totals — refuse it and every other feature is unaffected. NetCage holds no camera, microphone, location, contacts, SMS, call-log or media permission in any form.
The database and sign-in run on Supabase; icons sit in the developer’s own file storage; Google, Microsoft, Amplitude, Sentry and OneSignal all operate internationally. So data covered by this policy may be processed in a country other than yours, under each provider’s own terms. NetCage does not choose the region on your behalf and cannot promise a single jurisdiction.
What the developer holds — your synced configuration, your stored icons, the record of your devices — is kept until you change it or delete your account, and no longer; there is no archive behind the delete. Usage data and crash reports are kept by each provider under its own retention period, which NetCage does not shorten and cannot delete inside on your behalf; turning a switch off stops anything new being sent. Anything held only on the phone goes when you uninstall.
This site counts page views and a handful of actions — a sign-in, a message sent, an error — through Google Analytics, Amplitude, Microsoft Clarity and Sentry. What is recorded is the fact that something happened, plus which page it happened on. Never what you typed, never your email address, and never anything about which apps you have caged: that information is on your phone and this website has no way to reach it. There is no advertising here and nothing is sold or shared.
NetCage is for people aged 18 and over, and its Play listing says so. It is not directed at children, it is not designed to appeal to them, and no data is knowingly collected from them. If you believe a child has signed in, write to the developer and the account and its data will be deleted.
Every one of these works today, without asking anyone. To see what is held, sign in on this site and use the export — it downloads the whole of your stored configuration as JSON. To correct it, change it on the phone; the next sync overwrites what is stored. To stop the optional collection, use the switches in Settings. To erase everything, delete your account from Settings or from the deletion page. For anything this list does not cover, including a complaint, use the contact page.
Delete your account and everything stored for it from Settings in the app, or from the page below. Deletion removes your configuration, your stored icons and the account itself. Anything held only on your phone is removed when you uninstall the app.
Write to the developer using the contact page.
Last updated August 28, 2026