Privacy model
Clash is an on-device client. You configure the profile URLs, servers, and network services you choose, while its account-free architecture keeps the experience local-first.
On your device
Profiles, settings, connection history, logs, and diagnostics are handled locally. Sensitive local proxy-sharing credentials are stored in the device Keychain. Profiles are stored in the app container with the corresponding Apple platform's data protection.
At your direction
Clash makes external requests only to provide features you configure or start, including:
- remote-profile, provider, proxy, and DNS servers named by your configuration;
- resource-update sources shown in the app;
- network-quality, STUN, and latency-test endpoints you select on platforms that provide those features;
- your iCloud account when you explicitly create a backup on a platform that supports iCloud Drive backup.
Those services receive the network information needed to perform the operation, such as your IP address. Data travels directly to the services you choose, with the developer outside that path.
Verifiable by design
The Clash client and Hako core are both fully open source. The privacy model can be checked against the code the client and core actually execute instead of treated only as a promise.
The Privacy Policy is the authoritative legal description.