Maxfiylik siyosati

Psiphon jamoasi – mijozlar, foydalanuvchilar, distribyuterlar va ta’minotchilar shaxsiy ma’lumotlarini himoya qilishni o‘z burchi deb biladi. Ushbu maxfiylik siyosati sizga shaxsiy ma’lumotlaringiz qanday ishlatilishi haqida umumiy axborot beradi. Psiphon – Kanada korporatsiyasi bo‘lib, bosh ofisi Ontarioda joylashgan. Ushbu maxfiylik siyosati shaxsiy ma’lumotlarning maxfiyligiga oid Kanada va Ontario qonunlari va meyoriy hujjatlari asosida tuzilgan.

Shaxsiy ma’lumotlarni himoya qiluvchi Kanada va Ontario qonunlari haqida batafsil axborot olish uchun mana bu sahifaga o‘ting:

Psiphon onlayn kontentga ochiq ruxsat berish uchun ishlab chiqilgan. Psiphondan foydalanish Internetdagi maxfiylikni oshirmaydi va uni onlayn xavfsizlik vositasi sifatida ko‘rish yoki ishlatish tavsiya etilmaydi.

Psiphon qanday foydalanuvchi ma’lumotlarini yig‘adi?

Vaqti-vaqti bilan Psiphon muammolarni yechish uchun qo‘shimcha ma’lumotlarni yozib turishi mumkin. Bunday holatlarda biz nimalar, qancha vaqtga, nega yozib olinganligini maxfiylik xabarnomasida xabar qilamiz.

Psiphon mijoz-dasturi

Reklama tarmoqlari

Biz xizmatimizni qo‘llab-quvvatlash uchun ba’zida cookie-fayllar va veb-mayaklar ishlatuvchi reklamalardan foydalanamiz. Reklama hamkorlarimizning cookie-fayllari ular va ularning hamkorlariga Internetdan foydalanishingiz asosidagi reklamalarni ko‘rsatishga yordam beradi. Bu jarayondagi barcha ma’lumotlar hamkorlarimizning maxfiylik siyosatlar asosida yig‘iladi.

Qiziqishlaringiz asosida reklama ko‘rsatilishini quyidagi sahifa orqali o‘chirib qo‘yishingiz mumkin:

Psiphon Websites

Google Analytics

Ba’zi saytlarimizda tashriflar haqidagi axborotni to‘plashda Google Analytics xizmatidan foydalanamiz. Google Analytics orqali yig‘ilgan ma’lumotlar faqat kerakli saytlardagi foydalanuvchilar harakatini statistik tahlil qilish uchun foydalaniladi va hech qachon shaxslarni aniqlash maqsadlarida ishlatilmaydi.

Google Analytics brauzeringizga saytga keyingi tashrifingizni aniqlovchi cookie-fayl o‘rnatadi, lekin bu ma’lumotlar faqat Google serverlariga ko‘rinadi va boshqa xizmat yoki domenlar uchun berk bo‘ladi.

Google uchun Google Analytics xizmati orqali yig‘ilgan axborotdan foydalanish yoki boshqalarga ulashish Google xizmatlaridan foydalanish shartlari va Google maxfiylik siyosati bilan cheklangan. Bu kuzatuvni brauzer sozlamalarida cookie-fayllarni o‘chirib qo‘yish orqali to‘xtatishingiz mumkin.

Xotira jurnaliga qaydlar yozilishi

Biz Amazon S3 serverlaridan sayt fayllari va Psiphon mavjud serverlari ro‘yxatini saqlashda foydalanamiz. Ba’zida bu fayllar yuklab olinishi jurnalimizga yoziladi. Bu qaydlarning tahlili bizga “nechta foydalanuvchi mavjud serverlar ro‘yxatini so‘radi lekin yuklab olmadi?”, “yuklanmalarda sayt manbalari va mavjud serverlar ro‘yxati qanday ajratiladi”, “saytlarimizga ddos hujumlar bo‘lyaptimi?” kabi savollarga berishimiz uchun yordam beradi.

S3 qutisida yoziladigan jurnal qaydlari IP manzillar, foydalanuvchi agentlari va ulanish vaqtlaridan iborat bo‘ladi. Qaydlar S3 qutisini o‘zida saqlanib, Amazon ularni ko‘ra oladi. (chunki Amazon bu fayllar bilan ishlaydi.) Psiphon dasturchilari jurnal qaydlarini yuklab oladi va tahlil qiladi, tahlildan keyin qaydlar tozalanadi. Manba kodli axborot ko‘proq saqlanishi mumkin, lekin hech kimga ulashilmaydi.

Psiphon serverlari

Quyidagi ma’lumotlar Psiphon qanchalik yaxshi ishlayotganligi, qaysi saytlar ommaviyligi va qaysi tarqatish strategiyalari ijobiyligini aniqlashimiz uchun yig‘iladi. Masalan, bu axborotdagi hamkorlarimizga ularning saytlariga Psiphon orqali qachon va qaysi davlatlardan tashriflar bo‘lganligi ko‘rsatiladi.

  • Mijoz-dasturni e-pochta orqali yuklab olish havolasi so‘rovlari soni
  • Yangilanishlar soni
  • Protokollar necha marta ishlatilishi va ishdan chiqish xatoligi kodlari
  • Yangi serverlarning aniqlanish chastotasi
  • Foydalanish seanslari va ularning davomiyligi
  • Umumiy va ba’zi saytlarga uzatilgan baytlar soni
  • Mijoz-dastur platformasi (brauzer foydalanuvchi klienti kabi tafsilotlarsiz sodda operatsion tizimlar ro‘yxati)

Psiphon serverlari foydalanuvchilar IP manzillarini yig‘ishi odatiy faoliyat hisoblanadi. Psiphon foydalanuvchilardan hisob talab qilmaydi va birlamchi holatda ularning e-pochta manzillari, login va parollari kabi ma’lumotlari yig‘ilmaydi.

Hodisalar jurnalida vaqt, minaqa kodi (mamlakat va shaxar), homiy identifikatori (Psiphon mijoz-dastur yig‘ma raqami asosida), mijoz-dastur versiyasi va protokol turi kabi axborotlar bo‘ladi. Sahifaga tashriflar vaqt va/yoki boshlanmagan seans asosida tuziladi.

Butun statistika homiylar aro sana, homiy va mintaqa bo‘yicha ulashiladi.

User VPN Data

Why should you care?

When using a VPN or proxy you should be concerned about what the provider can see in your data, collect from it, and do to it. For some web and email connections, it is theoretically possible for a VPN to see, collect, and modify the contents.

What does Psiphon do with your VPN data?

Psiphon looks at your data only to the degree necessary to collect statistics about the usage of our system. We record the total bytes transferred for a user connection, as well as the bytes transferred for some specific domains. These statistics are discarded after 60 days.

Psiphon does not inspect or record full URLs (only domain names), and does not further inspect your data. Psiphon does not modify your data as it passes through the VPN.

Even this coarse data would be difficult to link back to you, since we immediately convert your IP address to geographical info and then discard the IP. Nor is any other identifying information stored.

Why does Psiphon need these statistics?

This data is used by us to determine how our network is being used. This allows us to do things like:

  • Estimate future costs: The huge amount of user data we transfer each month is a major factor in our costs. It is vital for us to see and understand usage fluctuations.
  • Optimize for traffic types: Video streaming has different network requirements than web browsing does, which is different than chat, which is different than voice, and so on. Statistics about the number of bytes transferred for some major media providers helps us to understand how to provide the best experience to our users.
  • Determine the nature of major censorship events: Sites and services often get blocked suddenly and without warning, which can lead to huge variations in regional usage of Psiphon. For example, we had up to 20x surges in usage within a day when Brazil blocked WhatsApp or Turkey blocked social media.
  • Understand who we need to help: Some sites and services will never get blocked anywhere, some will always be blocked in certain countries, and some will occasionally be blocked in some countries. To make sure that our users are able to communicate and learn freely, we need to understand these patterns, see who is affected, and work with partners to make sure their services work best with Psiphon.

Who does Psiphon share these statistics with?

When sharing with third parties, Psiphon only ever provides coarse, aggregate domain-bytes statistics. We never share per-session information or any other possibly-identifying information.

This sharing is typically done with services or organizations we collaborate with — as we did with DW a few years ago. These statistics help us and them answer questions like, “how many bytes were transferred through Psiphon for DW.com to all users in Iran in April?”

Again, we specifically do not give detailed or potentially user-identifying information to partners or any other third parties.

PsiCash

The PsiCash system only collects information necessary for the functioning of the system, monitoring the health of the system, and ensuring the security of the system.

The PsiCash server stores per-user information to allow for operation of the system, including:

  • generated user access tokens
  • balance
  • last activity timestamp
  • PsiCash earning history, including what the actions the rewards were granted for
  • PsiCash spending history, including what purchases were made

In the user's web browser, some data is stored to allow for earning rewards and making purchases. This data includes:

  • generated user access tokens
  • when a PsiCash reward is allowed to be claimed again

For monitoring system health and security, system activity data is collected and aggregated. This data includes:

  • user country
  • balance
  • user agent string
  • client version
  • PsiCash earning and spending details

Individual user data is never shared with third parties. Coarse aggregate statistics may be shared, but never in a form that can possibly identify users.

Fikr-mulohaza

Psiphon haqida fikr-mulohaza yuborish vaqtida diagnostika hisoboti faylini biriktirishingiz mumkin. Diagnostika ma’lumotlari foydalanuvchilar duch kelgan har qanday muammolarni yechishimiz va Psiphon yanada yaxshi ishlashini ta’minlashimizga yordam beradi. Hisobotni yuborish majburiy emas. Axborot yuborilishidan oldin shifrlanadi va uni faqat biz shifrdan chiqara olamiz. Diagnostika platformasi bo‘yicha quyidagi qiymatlardan iborat bo‘ladi:

Windows:

  • Operatsion tizim versiyasi
  • Antivirus versiyasi
  • Internetga ulanish turi (masalan, telefon modemi yoki proksi-server orqali ulangan bo‘lishingiz mumkin)
  • Kompyuteringizdagi bo‘sh xotira

Android:

  • Android versiyasi
  • Qurilma modeli
  • Qurilmangiz rutlanganmi

E-pochta avtomatik javob bergichi

Bizga e-pochta so‘rovi yuborilganda xatlar avtomatik javob berish serverida ko‘rinadi. E-pochta manzillari xatlar tahlil qilinayotganda vaqtincha serverga yoziladi, lekin tahlil yakunlanishi bilan (odatda bir necha soniyada) o‘chirib tashlanadi. Biz o‘z serverlarimiz jurnallarida e-pochta manzillar saqlanishiga yo‘l qo‘ymaymiz.

E-pochta xatlariga avtomatik javob berish serverimiz Amazon EC2 bulutida joylashgan. Biz har birga ikkita javob yuboramiz, ulardan biri Amazon SES xizmatiga yuboriladi. Bu faqat Amazon sizning xatingizni ko‘rib sizga javob berishi uchun bajariladi.

Xat bir kelgan e-pochta xatlari uchun biz quyidagi ma’lumotlarni saqlaymiz:

  • Xat so‘rovining qabul qilinish sanasi va vaqti.
  • Javob xatining sanasi va vaqti.
  • Xat hajmi.
  • Xatni yuborgan e-pochta serveri. (Domenning so‘ngi 3 qismlik manzili. Masalan, to‘g‘risi: ne1.example.com, notog‘risi: web120113.mail.ne1.example.com.)

Muammoni o‘rganib chiqishimiz uchun xatlaringizni qisqa muddatga pochta jurnaliga yozib turishimiz mumkin. Siz xat yuborgan vaqtda e-pochta manzilingiz tizim jurnalida yoziladi. Bu jurnal qaydlari bir haftadan keyin tozalanadi.

Dasturlar do‘koni

Unutmangki, Psiphon “app store”, Google Play market yoki Amazon AppStoredan o‘rnatilganda, do‘kon asisda qo‘shimcha statistika yig‘ilishi mumkin. Masalan, Google Play Market quyidagi qo‘shimcha ma’lumotlarni yig‘adi: https://support.google.com/googleplay/android-developer/answer/139628?hl=uz