Status: The VPN service is planned for December 2026; details may change before then.
No app of its own. The apps that already exist.
privymail.eu has no VPN app of its own. The VPN works with the apps that are widely used for WireGuard and OpenVPN; they exist for almost every device. You need two things: the app and a configuration.
The configuration
A configuration belongs to your VPN access. It describes which VPN server a device connects to and how it identifies itself, and it applies to:
- one country, where your tunnel ends,
- one protocol: WireGuard or OpenVPN, and with OpenVPN also UDP or TCP,
- particular DNS servers: those of the VPN service; in the paid plans optionally ones that block ads and trackers.
With WireGuard, the device's secret key is in the configuration; nothing more is needed to connect. With OpenVPN, the app additionally asks for the user name and password of your VPN access when connecting.
Treat a configuration like a password. Anyone who copies a WireGuard configuration can connect in your place.
Which app on which device
| Device | WireGuard | OpenVPN |
|---|---|---|
| Windows | WireGuard for Windows | OpenVPN GUI |
| macOS | WireGuard for macOS | Tunnelblick |
| Linux | wg-quick on the command line | openvpn on the command line or the network settings |
| Android | WireGuard app | OpenVPN Connect |
| iPhone and iPad | WireGuard app | OpenVPN Connect |
| Router | for example OpenWrt, OPNsense, pfSense or a FRITZ!Box | for example OpenWrt, DD-WRT, OPNsense or pfSense |
Many network storage devices also have an OpenVPN client built in. Which protocol suits what is covered under Devices on the VPN.
On a computer
- Install the app for your protocol.
- Import the configuration file into the app.
- Connect. An OpenVPN app asks for a user name and password at this point.
Depending on the system, there is a little more:
- Windows. WireGuard can block all traffic outside the tunnel; the option is in the tunnel's settings. OpenVPN GUI sits as an icon in the notification area of the taskbar; that is where you import the file and connect.
- macOS. Tunnelblick takes a configuration file with a double-click and can keep the credentials in the keychain. WireGuard asks on import whether it may add a VPN configuration.
- Linux. You control WireGuard with wg-quick: one command brings the tunnel up, one takes it down, and as a system service it starts at boot. OpenVPN runs from the command line; many desktop environments also import the configuration file in their network settings.
On a phone
- WireGuard. The app reads a configuration as a QR code or as a file. You give the tunnel a name and switch it on.
- OpenVPN Connect. You open the configuration file with the app, confirm the import and enter the user name and password.
The first time, the operating system asks whether the app may set up a VPN connection. On an iPhone you confirm this with your device passcode.
On a router
A router brings the whole home network into the tunnel, with a single connection. For that, its software has to support WireGuard or OpenVPN as a client. Setting it up takes more steps than on a computer:
- Install the client for WireGuard or OpenVPN if it is missing.
- Enter the configuration or upload it as a file.
- Set the firewall so that the home network reaches the internet only through the tunnel, not around it.
- Enter the VPN service's DNS servers by hand.
There are two limits you should know. The processors of most home routers are weak for encryption; with OpenVPN, often only 10 to 20 Mbit/s remain. And on some routers and network storage devices, IPv6 has to be switched off before a connection over OpenVPN can be established.
Checking afterwards
- The IP address. Open a site that shows your IP address, once without and once with the VPN. The address has to change.
- The DNS servers. A DNS leak test shows who answers your name queries. It should be the VPN service's DNS servers, not those of your internet provider.
- The block when the connection drops. If your app has a kill switch, switch it on.
- IPv6. Check whether IPv6 also runs through the tunnel or is switched off.
What lies behind these points is explained under VPN security.
What is up to you without a dedicated app
A dedicated app would take a few tasks off your hands. With the widely used apps you do them yourself:
- Changing country. A configuration applies to one country. For several countries you keep several configurations side by side and switch between them; more under Choosing a VPN country.
- Closing gaps. Whether a block takes effect when the connection drops and whether DNS queries stay in the tunnel depends on your app and its settings.
- Staying up to date. You update the app yourself. With OpenVPN, the version determines which method protects the data channel.
In return you are not tied to any one app: you choose the app you trust and can swap it for another.
Questions
Is there a privymail.eu VPN app?
No. The VPN works with the widely used apps for WireGuard and OpenVPN.
Do I need a separate configuration for each device?
For WireGuard, yes. Each device identifies itself with a key of its own, and two devices with the same key interfere with each other.
Do I have to set something up again for each country?
Yes, one configuration per country. You can keep several side by side and switch between them.
WireGuard or OpenVPN: which do I start with?
With WireGuard, if there is an app for your device: as a rule it is faster, and setting it up is shorter. Use OpenVPN if a network does not let WireGuard through or your device only knows OpenVPN.
Can I set up the VPN on my router?
Yes, if its software supports WireGuard or OpenVPN as a client. Expect less speed than on a computer.
The overview is under VPN, the handling of connection data under VPN and privacy.
WireGuard is a registered trademark of Jason A. Donenfeld.