Privacy Policy
Last updated: 1 July 2026
In the following we inform you how the service provider Rana GmbH (registered office: Kurt-Eisner-Str. 42, 04275 Leipzig, Germany) processes personal data in connection with the OnionHop website. We act in accordance with applicable law, in particular Regulation (EU) 2016/679 (GDPR). This policy applies to the OnionHop website; the app itself is described below. We may amend this declaration at any time; changes take effect upon publication.
The OnionHop app
OnionHop is a Tor routing client that runs entirely on your own device. It has no account system and performs no analytics or tracking. Your settings and any bridge or credential data stay on your device (on Windows, secrets are protected with the OS DPAPI). The app contacts the internet only to do its job: to reach the Tor network and the bridges you configure, to fetch bridge lists and geo rule-sets for routing, and — only if you enable it — to check GitHub once a day for a newer version. None of this data is sent to us.
Data controller
Rana GmbH
Kurt-Eisner-Str. 42, 04275 Leipzig, Germany
Email: info@ranagmbh.de
Phone: +49-172-6793005
Data processed on this website
Hosting and server logs
This website is served as static files via GitHub Pages (GitHub, Inc.). When you open the site, the host automatically processes connection data — including your IP address, the requested file, and the date and time — in server log files. This is technically necessary to deliver the page and keep it secure. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, reliable delivery).
No cookies, no analytics
This website sets no cookies and uses no analytics or tracking. We do not profile visitors.
Local storage
Your interface preferences (such as the chosen download channel or platform filter) are stored
in your browser's local storage under keys beginning with onionhop. so the site
remembers them on your next visit. This stays on your device and is never sent to us. You can
clear it through your browser at any time.
Release data (GitHub API)
The Downloads section loads version, asset and download information from api.github.com directly in your browser. This transmits your IP address to GitHub
as part of that request. Legal basis: Art. 6(1)(f) GDPR.
Video showcase
The walkthrough video is embedded from Gumlet (play.gumlet.io). The embed loads from Gumlet's servers when the page is opened, which transmits your IP address to Gumlet. If you do not play it, no further data is exchanged with the video host.
External links
The site links to GitHub, Discord, Ko-fi, the Rana blog and FMHY. These are operated by third parties under their own privacy policies; this policy does not cover them.
Retention
We store data only for as long as necessary or as required by law, after which it is deleted or anonymised.
Security
We apply appropriate organisational and technical safeguards — proportionate to the risk and to current technology — to protect data against unauthorised access, loss or alteration, and we review these measures regularly.
Your rights under the GDPR
As a data subject you have the right to:
- access the data we hold about you (Art. 15),
- rectification (Art. 16) and erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing (Art. 21).
To exercise any of these, contact us at info@ranagmbh.de. As a rule we respond within one month.
Complaints
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the Federal Commissioner for Data Protection and Freedom of Information (BfDI), Graurheindorfer Straße 153, 53117 Bonn, Germany.