Product · Security and privacy

Route what you choose.

FiestaVPN gives people a simple choice: route one built-in service, create a custom profile, or use All Connectivity for the whole device.

The active scope is always part of the product experience. In a selective profile, matched traffic uses FiestaVPN while other traffic stays on the normal internet path. In All Connectivity, all eligible device traffic and DNS use the tunnel.

FiestaVPN logo

FiestaVPN

Selective and full-device connectivity

Built and operated by Nolote Inc. · San Diego, California

A profile-first VPN

Most VPN interfaces start with a country or server list. FiestaVPN starts with the thing the user wants to route.

The product design includes built-in profiles for:

  • Telegram.
  • YouTube.
  • WhatsApp.
  • Instagram.
  • Facebook.
  • LinkedIn.
  • Slack.
  • Discord.
  • All Connectivity.
  • Custom application and destination profiles.

Only one profile is active at a time, so the connected state remains understandable.

Select one service without changing everything else

A selective profile is intended for the moments when a person needs one application or service to use a private route but does not want unrelated banking, work, local, gaming, or general device traffic to follow it.

The connected screen says what is active and what happens to everything else.

Example:

VPN active for Telegram. Everything else is using your normal internet connection.

The product never uses selective-profile language while silently routing the whole device.

Use All Connectivity when the whole device should be routed

All Connectivity is an explicit full-device profile. It installs a default-route VPN policy, routes eligible IPv4 and IPv6 traffic and DNS through the gateway, shows the gateway and public IP, and exposes local-network and kill-switch behavior.

The first-use flow makes that scope clear before connecting.

Example:

All Connectivity is active. All eligible traffic on this device is using FiestaVPN.

This is a different product state, not just a broader selective rule.

Android and iPhone do not work the same way

Truthful product language is one of FiestaVPN’s main differentiators.

Android

Android supports exact installed-application routing through the platform VPN service. A built-in or custom application profile can use an allowed-app list so only selected package traffic enters the VPN, unless the user deliberately enables a browser or destination-capture mode.

Consumer iOS

A normal consumer App Store VPN cannot reliably identify every packet from an arbitrary third-party application by app identity in the same way.

FiestaVPN therefore uses known service destinations, DNS and IP rules, and available network metadata for selective profiles. The product says “routes known Telegram traffic,” not “controls only the Telegram app,” and shows route confidence and rule version.

All Connectivity on iOS can use a full-device packet tunnel and does not depend on identifying the service.

Custom profiles without command-line configuration

A custom profile can be created for an installed Android application and/or defined destinations such as domains, wildcard domains, and optional IP ranges.

The builder is designed to:

  • Show installed applications where the platform supports it.
  • Validate domains and network ranges.
  • Warn about broad, local, private, or conflicting rules.
  • Explain consumer-iOS destination-based behavior.
  • Offer a route test before connection.
  • Save and version the profile safely.

The goal is advanced control without requiring a user to understand package identifiers, CIDR notation, DNS matching, or tunnel routing internals.

Signed rules that can change with the services

Service applications and content-delivery networks change over time. FiestaVPN profiles are designed as signed, backend-managed rule sets so the product can update identifiers, destinations, protocol requirements, and gateway policy without waiting for a full application release.

The app rejects expired, invalid, or incompatible rules and explains when a reconnect is required.

Diagnostics that answer the real question

A generic green shield is not enough. Diagnostics identify whether the intended traffic scope is actually working.

Checks can include:

  • Active profile and traffic scope.
  • Exact or known-destination route mode.
  • Application installation and permission.
  • Service-rule version and freshness.
  • Gateway health and latency.
  • UDP support for voice and video.
  • DNS behavior.
  • Public IP and full-device route verification.
  • Direct behavior for non-selected traffic.
  • Kill-switch or strict selected-service behavior.
  • Subscription and credential state.
  • Recent connection events.
  • A sanitized support report.

The default experience stays plain. Advanced detail remains available when needed.

Privacy and security

The product design requires:

  • No payload-content decryption.
  • No message-content logging.
  • Short-lived session credentials.
  • Signed route profiles.
  • Scope-aware failure behavior.
  • Sanitized support reports.
  • Privacy-preserving telemetry.
  • Clear notification and foreground-service behavior.
  • No green “protected” state when the selected traffic is not actually routed.

Product-specific privacy notices define exactly what connection metadata is collected, for what purpose, for how long, and in which regions.

AI behind the scenes

AI can help FiestaVPN improve diagnostics, recognize recurring failure patterns, prioritize support guidance, assist rule-quality review, and recommend a suitable gateway based on product-approved signals.

That intelligence does not require reading private message content or browsing payloads. It also never changes the visible traffic scope without the user’s explicit action.

Who FiestaVPN is for

  • People who need one supported service to use a different route.
  • Users who want to keep unrelated device traffic on the normal connection.
  • People who sometimes need a familiar full-device VPN mode.
  • Power users creating a route for a work portal, application, site, or service.
  • Teams that value visible routing scope and useful diagnostics.

What FiestaVPN does not claim

  • Selective mode is not full-device protection.
  • Consumer iOS does not provide exact arbitrary third-party-app-only routing.
  • A route profile cannot guarantee recognition of every future service destination.
  • Connection quality still depends on the local network, gateway health, service behavior, capacity, and platform limitations.
  • FiestaVPN does not inspect or decrypt application content to decide what a user is saying or viewing.

Next step

A Nolote product

FiestaVPN is built around a principle that applies across Nolote: simplify the user experience without hiding the underlying truth.

Related: Nolote Security · Nolote Technology