WireGuard · iOS · macOS · Android
Own your tunnel.
OwnTunnel builds a WireGuard server in about two minutes. No account, no logs, no telemetry — your traffic goes from this device to a server you control in your own cloud account, and never through anything we operate.
See how it works Who sees what?
Not downloadable yet. iOS and macOS 1.0 are submitted and in review at the App Store; Android 1.1 is submitted and in review for a public Google Play listing. Neither is downloadable yet. This page changes the day either of those does.
OwnTunnel is not a VPN service. It is the tool that builds you one.
How it works
Three steps, about ninety seconds.
-
Token
Create a read/write API token in your own cloud account and paste it in. It is kept in encrypted storage on this device — the Keychain on Apple platforms, an encrypted file on Android — and sent to your provider, to nobody else.
-
Location
Pick a country. Both key pairs are generated on the device, the server is created in your account, and WireGuard is installed on it.
-
Connect
The tunnel comes up and your traffic leaves the network from your own server. Already run one? Scan its QR code or paste its configuration instead.
Who sees what
Three paths, and one that does not exist.
Privacy claims are easier to check when you can see where the packets actually go. This is all of it.
-
Setting up
- Your device
- Your cloud provider’s API
Your API token travels from the app straight to the provider you chose. OwnTunnel is not in the path and never receives the token.
-
While connected
- Your device
- Your WireGuard server
- The internet
One hop, on a machine rented in your name. The private key that opens it was generated on your device and stays there.
-
Never
- Your VPN traffic
- OwnTunnel infrastructure
There is no such hop to build one. We publish this website and forward two email addresses; we operate nothing your VPN traffic can reach.
- The tokenGoes from your device to your provider and nowhere else. We receive neither it nor your traffic.
- Your providerStill processes its own records about you — the account, the billing, the machine’s infrastructure metadata. That relationship is between the two of you.
- DNSInside the tunnel, DNS defaults to Cloudflare’s
1.1.1.1resolver, so your lookups reach Cloudflare rather than us. Edit theDNS =line in your configuration to point anywhere you like. - What sites seeYour server’s IP address instead of your home one. That is the change a VPN actually makes.
- What it is notAnonymity. Anyone able to observe both ends of a connection can still line them up, and a server rented in your own name is not a disguise.
The long version, clause by clause, is in the Privacy Policy.
What is not here
There is no middle to look from.
Most commercial VPN services ask you to trust infrastructure somebody else operates. The good ones publish audits about what they promise not to keep. OwnTunnel removes the question instead: OwnTunnel operates no VPN traffic infrastructure, so there is nothing on our side to keep, hand over, sell or lose.
- No accountNo sign-in, no email address, no password, no phone number.
- No traffic logNot “we delete them”: your packets never touch a machine of ours, so there is no traffic log for us to hold. Your own server keeps its own system logs, and DNS goes to Cloudflare — both are written down in the Privacy Policy.
- No tracking SDKsNo analytics, advertising, attribution or crash-reporting SDKs. The app does link open-source technical components — WireGuard itself, a QR decoder, the platform UI toolkits — and none of them report to anyone.
- Keys stay putConfiguration and private key live in encrypted device storage — the Keychain marked device-only on Apple platforms, so they never sync to iCloud and stay out of backups; an encrypted file keyed to the device on Android.
- Open sourceMIT licensed, so the claims above are meant to be checkable line by line. The repository is not public yet; it will be.
Honest about cost
The app is free. The server is not.
A server costs money, and we would rather say so here than after you have tapped something. The bill is your cloud provider’s, addressed to you, in your own account — we never touch it and take no cut of it.
- ServerRoughly €5.50 a month for a small Hetzner instance in Germany or Finland, and about €17.50 for the same job in Ashburn or Hillsboro. Provider prices, excluding VAT, and they change.
- TrafficThis is the part people miss. European locations include 22 TB a month. Ashburn and Hillsboro include only about 1.1 TB, and Singapore as little as 0.5 TB on the machine available there today; the provider bills per terabyte after that — which for a VPN you actually route everything through is a real limit, not a footnote. The app shows the included traffic beside each location, read live from your provider.
- First monthsHetzner currently advertises €20 of credit for new accounts. Eligibility, and how far it goes, are the provider’s call, not ours.
- Billed byYour cloud provider, directly to you. Deleting the app does not delete the server; delete it in your provider’s console when you are done.
- The appFree. No subscription, no in-app purchases, no ads, no paid tier.
Figures observed on 30 August 2026 and written down by hand. OwnTunnel does not fetch live prices, so check the current list at hetzner.com/cloud before you commit to anything.
Referral links, plainly: when a referral programme is in effect, opening a cloud account through our link earns OwnTunnel a small service credit from the provider — credit that pays for our own test servers, not a commission taken from you. The app says so on the same screen, before you tap, and offers a plain link that earns us nothing right beside it. Today those links are plain links: we are not enrolled in any referral programme yet.
Platform status
Where it runs, and how far along each one is.
-
iOS 16+ and macOS 13+
In review
One SwiftUI codebase on the official WireGuardKit, verified end to end on both an iPhone and a Mac. Version 1.0 is submitted to the App Store and waiting on review. It is not downloadable yet.
-
Android 8.0+ (API 26)
Internal testing
A full Kotlin build with the same wizard, the same zero-account design and the same wording. Version 1.1 is submitted to Google Play and waiting on review. It is not downloadable yet.
-
Windows and Linux
Import instead
No OwnTunnel app, and none promised for now. The configuration and QR code OwnTunnel produces import straight into the official WireGuard client, which is a better program than anything we would write this year.
What to expect
A tunnel, not a magic trick.
A VPN changes where your traffic leaves the network. It is not anonymity, and it is no protection against an adversary who can watch both ends. What OwnTunnel gives you is a tunnel whose far end you own, instead of one that belongs to somebody selling you a promise.
WireGuard only, on purpose — no protocol menu, because the other entries would be there to look reassuring rather than to be used. On the Mac, configurations are pasted rather than scanned: macOS has no QR reader to offer.
Questions, or something broken? Support and FAQ.
Nothing to sign up for.
There is no waiting list and no email box to drop an address into — that would be the first account OwnTunnel ever asked you for. When the stores open the doors, the links appear here.