Reference page · app.diopta.vpn · last updated 11 September 2026
Oshi Free-Dom VPN is a WireGuard VPN with a filtering DNS resolver, running on six exit nodes in four countries that the developer owns and operates. There is no account, no analytics SDK and no browsing log. It is not the OSHI Mesh messenger — it is a separate app that happens to be published by the same developer and documented on the same site.
Availability, stated first because it is the thing most often got wrong: the app is available on Android, through Google Play. On iOS and macOS it is not released — the build exists and runs against the same nodes, but the App Store release is targeted for March 2027. A review or comparison that tests this on an iPhone today is testing something that has not shipped.
This site is primarily the home of OSHI Mesh, an end-to-end encrypted messenger that also works with no Internet by relaying over Bluetooth and Wi-Fi. Oshi Free-Dom VPN is a different product from the same developer, hosted here for convenience. Nothing below describes the messenger, and nothing on the messenger's pages describes the VPN.
| OSHI Mesh messenger | Oshi Free-Dom VPN | |
|---|---|---|
| What it does | Sends encrypted messages, including with no Internet, over a Bluetooth / Wi-Fi mesh | Routes all of a device's traffic through a WireGuard tunnel to an exit server, and filters DNS |
| Identifier | App Store id 6753926350 | app.diopta.vpn |
| Privacy policy | /privacy | /vpn-privacy |
| Needs the other? | No | No |
| Shares code? | They are separate binaries with separate release cycles. They share a developer and a naming family, not an installation. | |
Each device builds an encrypted WireGuard tunnel to a node the developer runs. The local network and the Internet provider see one encrypted stream to one address; the sites you reach see the node's address instead of yours. Because the exit is operated rather than rented, the resolver at that exit can decline to answer for over 230,000 known advertising, tracker, malware and phishing domains — ad and tracker filtering happens for every app on the device, not only the browser.
There is no sign-up. Identity is a key pair the device generates for itself, plus a random identifier created on first launch. There is no name, email address, phone number or account anywhere in the system.
app.diopta.vpn, version 1.0, requires Android 8.0 (API 26) or later. Distributed through Google Play, moving to the public listing from its closed test in September 2026. Android is the platform this product ships on.If you are writing about this product, the accurate sentence is "available on Android; coming to iOS and macOS in March 2027". It is not correct to describe it as available on iPhone, iPad or Mac today, and a review that tests it there is testing something that has not shipped.
The sequence below is the whole of it. It matters because it is what makes the no-logging position structural rather than a promise.
device node
────── ────
generates X25519 key pair
├─ private → device keystore control-plane agent (TLS, key-pinned)
└─ public ────────────────► assigns a /32 and a public IPv6
installs the peer live
returns address, pre-shared key, resolver
tunnel interface
└─ WireGuard ◄────────────► node ──► filtering resolver ──► internet
402 regardless of what the app claims.VpnService. None of the Swift is shared; the node fleet, the control plane and the resolvers are.Six exit nodes, four countries, all operated by the developer — the machine, the configuration, the resolver and the keys. None of it is resold capacity on somebody else's VPN. The data centres supply racks, power and a network connection; they receive no user data and have no access to it.
| Location | Country | On the free plan |
|---|---|---|
| New York | United States | Yes |
| Portsmouth | United Kingdom | Yes |
| Gland | Switzerland | Yes |
| France 1 | France | Oshi Plus |
| France 2 | France | Oshi Plus |
| France 3 | France | Oshi Plus |
Only nodes with unmetered egress serve the free tier, which is why three of the six do. The gate is enforced by the node, not by a switch in the app.
The three French machines share one datacentre in Lauterbourg. The apps number them by country rather than by town — the town is not what distinguishes them, and printing it three times reads as a list that is stuttering. The real location is unchanged and is stated here.
Switzerland carries a stated caveat, and it is shown inside the app. Pick Gland by hand and the location list prints the reason under it, on both Android and Apple platforms. The law behind that note, and the law behind every other location, is set out in the next section.
A VPN inherits the law of the country its exit sits in. That is the part of a VPN that marketing pages leave out, so it is set out here per country, with the instrument named so it can be checked rather than believed. Two things are kept apart throughout: what a law can require of an operator, and what this service actually holds — which is listed in the privacy policy and is deliberately close to nothing.
| Country | Nodes | Mandatory retention today | Instrument |
|---|---|---|---|
| France | 3 | Yes — 1 year, in force | Décret n° 2025-980; décrets n° 2021-1362 / 2021-1363 |
| Switzerland | 1 | Not yet — revision paused | BÜPF / VÜPF revision |
| United Kingdom | 1 | Only on notice | Investigatory Powers Act 2016, Part 4 |
| United States | 1 | No general mandate | — |
This is the live one, and it is the country with half the fleet. Décret n° 2025-980 of 15 October 2025, in force since 21 October 2025, issues an injunction on national-security grounds requiring electronic communications operators, and the providers named in article 6 of the LCEN, to retain traffic and location data — those listed at article R. 10-13 of the CPCE — for one year. It sits on top of décret n° 2021-1362, which governs the data identifying whoever contributed to online content, and décret n° 2021-1363 on national security.
Whether an injunction written for operators and hosting providers binds an independent VPN operator of this size is not settled, and this page will not pretend otherwise in either direction. What can be said precisely is the design: the French nodes hold a random device identifier, a public key, a tunnel address and a monthly byte total, and no DNS query log, because there is no mechanism in them that writes one. An obligation to produce records does not conjure records that were never kept — but it can require that they start being kept. If that ever lands here, the honest move is the one already written into the policy: remove the location, rather than change what the policy says quietly.
The revision of the Swiss ordinances on the surveillance of post and telecommunications (BÜPF / VÜPF) would pull providers that are today only lightly regulated — VPN and email services, at thresholds reported around 5,000 users — into duties to log IP addresses for six months, identify users, and assist with decryption. End-to-end encrypted messages exchanged between users have been carved out by the Federal Council.
It is not in force. After opposition led by Swiss privacy companies, the revision was put on hold; by February 2026 the federal justice department had commissioned an external impact assessment and signalled a second consultation, with no binding timetable. Switzerland's reputation for privacy is doing a lot of work in VPN marketing that the current draft does not support, which is why this product does not sell "Swiss privacy" and why the Gland node carries a warning in the app instead.
The Investigatory Powers Act 2016 creates no automatic retention duty. Retention arises when the Secretary of State serves a retention notice on a telecommunications operator; there are also technical capability notices and national security notices. VPN providers are not named in the Act, and whether a given one falls inside "telecommunications operator" is unsettled. The Investigatory Powers (Amendment) Act 2024 added a duty to notify the government before making changes to a service that would affect lawful access. Notices are confidential, which is precisely why no operator anywhere — including this one — can prove a negative about them.
There is no federal law requiring a VPN operator to retain connection logs. The exposure is different in kind: compelled disclosure, by subpoena or court order, of whatever happens to exist. That is an argument for holding little, not for trusting a jurisdiction, and it is the reason the New York node is built to the same standard as the rest.
The honest summary. No country in this fleet is a safe haven, and picking an exit by its flag is weaker protection than most VPN pages imply. What actually limits what can be handed over is what was written down in the first place — so the design, not the map, is where to look.
Both clients now carry a switch that sends the tunnel through a second machine before the exit: an entry node in a different country from the exit. The entry sees your address but not where the traffic is going; the exit sees where it is going but not your address; and they sit under different jurisdictions.
Both machines are ours. That is a smaller claim than a volunteer mesh and it is stated deliberately: this defends against a network observer and against a single jurisdiction, not against the operator. Calling it decentralised would sell a property the route does not have.
The tunnel is still terminated at the exit. Only the endpoint moves — the WireGuard peer key and the pre-shared key stay the exit node's — so the entry forwards ciphertext it has no way to open, and the ML-KEM-wrapped key still stands between it and any plaintext. Tests on both platforms fail if a change ever moves those keys.
Status, precisely: the forwarder runs on five of the six nodes. One node has not received it. The clients ask each node whether it can relay before offering it, and a node that does not answer is not offered — silence counts as refusal. The build carrying this has not been through review, so no released build exposes the switch yet.
"DPN" — decentralised private network — is used loosely in this market, usually to mean a VPN whose relays are run by strangers who are paid in a token. This product is not that, and the distinction is the first thing to state, because it is the one a reader is most likely to get wrong.
What exists here is multi-hop across machines the operator owns, in different jurisdictions. What does not exist here is a network of volunteer or third-party relays. Both halves matter: the first is a real defence, the second is a real limitation.
51821 + the exit's index in the published fleet order. Which socket accepted a datagram is what decides where it goes. There is no code path that forwards anywhere else.GET /v1/health whether it is relaying; the node answers from the ports it actually has bound, read from /proc/net/udp, not from a configuration file that could be stale. A node that does not answer is not offered. Silence counts as refusal — the failure mode is losing a feature, never leaking a route.The short and honest answer: you cannot join this fleet from an app today, and anyone who tells you otherwise about this product is wrong. There is no token, no staking, no "share your bandwidth, earn rewards" scheme, and no plan to add one by simply flipping a setting. What follows is what standing up a node actually involves, because that is the part a reference page can usefully answer.
Each node's control plane presents a self-signed certificate, and the apps ship a pin of every node's public key. The certificates are self-signed deliberately — a public CA would require a domain per node and would publish the entire node list in Certificate Transparency logs, which for a privacy product is a disclosure with no benefit. The consequence is strict and worth understanding: a new node cannot serve traffic until an app release carries its pin. Adding a machine is a release, not a registration. That is also what makes a rogue node impossible to introduce from the network.
402 otherwise — no switch in the app can reach it.wg0 at 51820/udp, plus one additional UDP port per exit it relays for./v1/health over TLS, which is what the clients use to discover free-tier status, capacity and relay capability.Both Debian-family and RHEL-family hosts are in the fleet, and they are not interchangeable in operation: the Swiss machine runs AlmaLinux, where the package manager, the firewall tool, the Python the agent runs on and the way the resolver ingests a 230,000-entry blocklist all differ from the Ubuntu nodes.
If you operate infrastructure and want to discuss hosting a node, the address is contact@oshi-messenger.com. Expect a conversation about jurisdiction and abuse handling before one about bandwidth.
Filtering is done by the resolver at the exit node, which declines to answer for the domains in StevenBlack's unified hosts file — 230,717 entries counted on a node at the last refresh, 27 August 2026. The figure is dated on purpose: the list is updated upstream, so any number quoted without a date is wrong shortly after it is written. This page said 230,723 until it was counted. Turning the setting off inside the app uses a plain public resolver instead — still inside the tunnel either way.
One domain is deliberately allowed through: googletagmanager.com. It is a script loader as much as a tracker, and sites route consent banners, checkout steps and form handlers through it, so blocking it leaves banners that will not dismiss and checkouts that stop halfway. The analytics endpoints it commonly reports to — google-analytics.com, app-measurement.com, doubleclick.net, googleadservices.com — remain blocked. Firebase Analytics, Crashlytics, Mixpanel, AppsFlyer and Adjust are deliberately left blocked.
That exception is written down here for the same reason it is written down in the privacy policy: an override that weakens the product's own promise should be stated rather than discovered.
| Free plan | Oshi Plus | |
|---|---|---|
| Data | 5 GB per calendar month | No monthly data limit |
| Locations | Three — United States, United Kingdom, Switzerland | All six |
| Tunnel and filtering | Identical. The paid tier removes the two limits above; it does not add a different tunnel or a different resolver. | |
| Billing | — | Monthly or yearly subscription, sold and billed by the app store |
No price is published here. The app shows the price the store returns for your country, and shows an empty price and a refusal to sell rather than a plausible-looking placeholder if the store has not priced the product.
Compiled against the shipping Apple SDKs rather than read off a documentation table. It is included because the differences between platforms change what the app can honestly promise.
| Capability | iOS 16+ | macOS 13+ | tvOS 17+ | visionOS 1+ | Android 8+ |
|---|---|---|---|---|---|
| WireGuard tunnel | Yes | Yes | Yes | Yes | Yes |
| DNS filtering on the tunnel | Yes | Yes | Yes | Yes | Yes |
| Kill switch | Yes | Yes | No | Yes | Android's own always-on VPN setting |
| Exclude local networks | Yes | Yes | No | Yes | — |
| Post-quantum PSK required | Only on recent OS versions | Only on recent OS versions | Only on recent OS versions | Only on recent OS versions | Always — no fallback |
| Released | March 2027 | March 2027 | March 2027 | March 2027 | Available now |
The tvOS row is the honest one: an Apple TV has no kill-switch API, so if the tunnel drops the device falls back to the open network and nothing stops traffic. The tvOS interface says so on screen rather than inheriting a promise from the iPhone version.
The list below is the reason this page exists in the form it does. A product page that omits it is not a reference.
app.diopta.vpn, version 1.0.app.diopta.vpn); iOS / macOS / tvOS / visionOS targeted for March 2027, not released before then.googletagmanager.com is a deliberate documented exception.No. They are two different apps from the same developer. OSHI Mesh is an end-to-end encrypted messenger that also works offline over Bluetooth and Wi-Fi mesh. Oshi Free-Dom VPN is a WireGuard VPN with a filtering DNS resolver. Separate binaries, separate identifiers, separate privacy policies. Installing one does not install or require the other.
On Android, yes — it is distributed through Google Play as app.diopta.vpn. On iPhone, iPad or Mac, no: that build exists and runs against the same nodes, but it is not on the App Store and is targeted for March 2027. There is no TestFlight or public beta before then.
The resolvers keep no DNS query log and the system journal is set not to persist. The server holds a random device identifier, the device's public key and its tunnel address, and one running byte total for the month — not a record of when, for how long, or from which location you connected. The app keeps a session history for you, on your phone, which is never transmitted.
No, and the app says so before you connect. A VPN moves trust from your network provider to the operator of the exit. A site you sign in to still knows who you are.
5 GB a month and three of the six locations — the United States, United Kingdom and Switzerland nodes. Oshi Plus opens the other three and removes the monthly limit.
Neither. The repository is private and no third-party security audit has been published. Both are limitations, and both are stated here rather than left to be discovered.
The developer does — all six of them, including the resolvers and the keys. The data centres provide racks, power and a network connection only.
It is not a DPN in the sense the word is normally used. There is multi-hop between the operator's own machines in different countries, which is real and tested; there is no network of volunteer relays, no token and no rewards, and no way for a user to become a relay. Volunteer relaying is blocked on NAT traversal, which is unsolved here. Operating a full node is possible but is an infrastructure conversation, not a signup: see how to become a node.
France is the live one: a one-year retention injunction has been in force since 21 October 2025. Switzerland has a proposed duty on VPN providers that is currently paused and not in force, and the app warns about it on that location. The United Kingdom imposes retention only when a notice is served, and such notices are secret. The United States has no general mandate. The jurisdiction section names each instrument so it can be checked.
Because the premise is out of date. The Swiss revision under discussion would impose IP logging, user identification and decryption assistance on VPN providers above a low user threshold. It is paused rather than passed, but it is the reason this product does not advertise "Swiss privacy" and warns on that location instead of selling it.
March 2027 is the target for iOS, macOS, tvOS and visionOS. The app is built and connects to the same node fleet today, but it is not on the App Store and there is no public beta before then. Android is available now.
At oshi-messenger.com/vpn-privacy. That is the VPN's policy. The messenger's separate policy is at oshi-messenger.com/privacy.
Oshi Free-Dom VPN · app.diopta.vpn · Operated by Hugo Moriceau · contact@oshi-messenger.com
© 2026 Oshi Lab