Status: The VPN service is planned for December 2026; details may change before then.
One connection in the Free plan. Up to five devices in the paid plans.
How many devices can use the VPN at the same time depends on the plan.
| Plan | At the same time | Speed |
|---|---|---|
| Free | 1 connection | at most 10 Mbit/s |
| Personal, Pro, Team | up to 5 devices | at most 1 Gbit/s |
The speeds are upper limits, not commitments.
What "at the same time" means
It refers to connections that exist at the same moment. In the Free plan that means: while your phone is connected, your laptop cannot be connected as well. In the paid plans, a phone, a laptop and further devices can be connected side by side, up to five in total.
Each connected device has its own tunnel. A device without a connection takes the ordinary route to the internet, even while another one is protected.
Which devices the VPN runs on
The VPN needs no app of its own. It runs wherever there is an app for WireGuard or OpenVPN:
- Computers: Windows, macOS and Linux.
- Phones and tablets: Android and iOS.
- Routers: devices whose software supports WireGuard or OpenVPN as a client, for example with OpenWrt.
- Network storage: devices with a built-in OpenVPN client.
Which app goes with which device is listed under Setting up the VPN.
A router connects the whole home network
A router sets up a single tunnel; to the VPN it is one connected device. Everything that goes online through it shares this tunnel, including devices on which no VPN app can be installed.
The downside is speed. The router then does the encryption, and the processors of most home routers are weak for that: with OpenVPN, often only 10 to 20 Mbit/s remain.
Port forwarding: reaching a device from outside
On the VPN you share the VPN server's public IPv4 address with other users. Connections from outside therefore do not reach your device at first. In the paid plans this can be changed for individual ports:
- up to seven ports,
- TCP, UDP or both for each port,
- port numbers from 49152 to 65535.
A forwarded port leads to the device that is connected to the VPN. That lets you reach a computer, network storage or a server at home while you are away, even if your internet provider blocks incoming connections. What is visible to the outside is the VPN server's address, not that of your own line.
An open port is an open door. The service listening behind it can be reached from the internet and has to be secured in its own right; the VPN does not protect it.
What a device needs to connect
With both protocols, a configuration describes which VPN server a device connects to and how it identifies itself. With WireGuard, that is a few lines of keys and addresses. With OpenVPN, it is a file with the server address, certificates and settings; on top of that come a user name and password when connecting.
A configuration names one particular VPN server and therefore one country. If you change country, you need a further configuration.
A WireGuard configuration contains the device's secret key. Anyone who copies it can connect in your place; treat it like a password.
Which protocol suits which device
- Phone and laptop on the move. WireGuard keeps the tunnel when the device changes networks and needs little computing time.
- Networks that let little through. OpenVPN can run over TCP and then often gets through where UDP is blocked.
- Routers. WireGuard, if the router supports it: it asks less of the processor than OpenVPN.
Questions
Does every device count separately?
Yes. Every device that is connected takes up one connection.
Does the connection on my phone also protect my laptop?
No. The tunnel protects the traffic of the device on which it is set up. Only a router is different: its tunnel covers everything that goes online through it.
Can I open ports below 49152?
No. Port forwarding covers port numbers from 49152 to 65535.
All differences between the plans are listed under VPN, the plans themselves under Pricing. What a VPN does not do is listed under VPN security.
WireGuard is a registered trademark of Jason A. Donenfeld.