Security

You are installing software that gets access to your network, and handing it the traffic of a game you have played for years. Here is what you should check before you do.

What the app does on your machine

It creates a virtual network adapter and adds routes. That is where its contact with your system ends. It does not open other processes, read anyone else's memory, inject code or touch the game's files — it has neither the permissions nor a reason to. Only traffic aimed at the game servers enters the tunnel; everything else — the game login and your browser included — takes its own route. An uninstaller ships with it and removes the adapters and the driver.

The driver

We use WireGuardNT through its public API — the original wireguard.dll signed by WireGuard LLC, without a single altered line. We don't build our own driver, don't patch anyone else's, and load nothing unsigned into the kernel. You don't have to take our word for it: right-click the file, Properties, Digital Signatures.

Keys

Your device's private key is generated on your computer and never leaves it — only the public half reaches us. Even full access to our servers would not reconstruct your private key or decrypt traffic captured earlier.

What we cannot see

We don't terminate TLS, don't substitute our own certificates and don't look inside your connections. To us your traffic is a stream of bytes with a destination on the envelope. We don't have your game password — we never ask for it, and there is no point in this architecture where it could pass through us: the login itself never goes through our servers at all, it goes over your own connection, straight to CipSoft.

Why we route by address rather than by content

To tell that a given connection is going to Tibia rather than to some random service, you would have to look inside it — that is, break the encryption by substituting your own certificate. We don't do that, and we deliberately don't build ourselves the ability to. Your connection to the game server is encrypted the whole way from your computer to CipSoft, and we are blind in the middle. Not because we promise not to look, but because we have nothing to look with.

The effect is that the cut comes out narrow, and that is an advantage rather than a compromise. Only connections to the game servers' addresses enter the tunnel — and nothing besides them. The login, the game's own updates and all browser traffic go to other addresses, so they never reach us in any form: we cannot see their contents because they are encrypted, but more to the point we don't even hold them as metadata, because they never cross our network. One caveat remains and we would rather state it plainly: the address decides, not the program's name, so if another program connected to a game server's address, it would be tunnelled too. Disconnect and everything is back to normal, and whatever did pass through the tunnel is subject to one rule: we record metadata, never content.

What we do record

Metadata about connections as they are opened: time, destination address and port, and the exit address assigned at that moment. Not content — we don't have it. We keep this because the law requires it, and because without it we could not answer for an address you share with others if someone abused it. Logs have a defined lifetime and are removed after it.

Account and session

An account is one random number — there is no password, so there is nothing to steal or reset. The database holds only a hash of that number, computed with a key kept outside the database, so a dump of it alone reconstructs no account. One device is attached to an account: a further registration is refused rather than joining alongside the running session. Someone holding your number cannot throw you out of the game.

Payments

They are handled by a licensed payment operator. Card details never pass through our servers — we could not store them even if we wanted to. With a subscription we only keep identifiers issued by the operator, useless outside their system.

No bots, no account theft

Bots, gameplay automation scripts and tools for taking over other people's accounts are absolutely forbidden. A confirmed breach means the account is deleted with no refund. It belongs on this page too, because it is part of the security story: a shared address is worth exactly as much as the players behind it.

Who runs this

The service is operated by nApps.pl Patryk Nowakowski, a sole trader registered in Poland and therefore in the European Union, subject to EU law including the GDPR. There is no anonymous operator behind this: anyone can check the numbers below in the public registers.

Polish NIP 6482801746, EU VAT number PL6482801746, REGON 387613091. You can check the VAT number in the European Commission's register: VIES

Questions, complaints and withdrawal from the contract: [email protected]

Something went wrong. Reload 🗙

Rejoining the server…

Rejoin failed. Trying again in s.

Failed to rejoin. Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session. Please retry or reload the page.