How WrapVPN works
The whole system from the bottom up, starting with the part that carries your traffic.
People ask what a VPN actually does, and the usual answer is a list of adjectives. This page is the other kind of answer. It goes through WrapVPN from the bottom up — the tunnel, the exit, how a server gets chosen, what happens to a name before it is resolved, and what happens when the whole thing drops — and it says where each part stops being useful.
01 · The tunnel
WireGuard, and why one round trip matters
Your traffic travels inside a WireGuard tunnel between your device and one of our servers. WireGuard is a few thousand lines of code where the older protocols are hundreds of thousands, which is the reason it is worth preferring: a smaller thing can actually be reviewed. Smaller is not automatically safer. It is the difference between an audit that finishes and one that samples.
The property you will actually notice is the handshake. WireGuard completes one in a single round trip, where older protocols need several. On a laptop that is a detail. On a phone it is the whole experience, because a phone changes network constantly — platform to street, Wi-Fi to mobile data, one access point to the next as you walk — and each change means the tunnel is rebuilt. One round trip is about a second. Several is the stall you sit and watch.
02 · The configuration
What signing in actually gets you
Signing in does one concrete thing: it gets your device a tunnel configuration — an address, a DNS resolver, an endpoint to talk to, and the key material that makes the tunnel work. We issue it. You do not assemble it.
That is a trade, and it is worth being plain about both halves. It is why there is nothing to paste, nothing to keep in sync between your phone and your laptop, and nothing to get subtly wrong. It is also why the configuration is ours to issue rather than yours alone to hold. A setup where you generated your own keys and handed us only the public half would be stronger on that one axis, and it is not what this is.
03 · The exit
The part most VPNs are vague about
Your traffic leaves our network at the exit you chose and rejoins the internet there. The sites you reach see that server's address instead of the one your network gave you.
So let us be direct about what that server knows. It is forwarding your packets, so it necessarily knows which addresses it is forwarding them to. It cannot read the contents — the tunnel is encrypted up to that point, and nearly everything inside it is HTTPS as well — but "nobody can see anything" would be false, and any VPN that tells you otherwise is describing a product that does not exist. What changes is who is in that position: the café, the hotel and the airport stop being able to see it, and the exit starts. What is retained, as opposed to momentarily handled, is a separate question, and the log ledger on the home page is where it is answered rather than promised.
04 · Choosing a server
Latency is the number, not the map
On connect the app takes the nearest healthy server. You can override it, and the region list shows live latency beside every location so you can see what you are choosing rather than guess.
Read the number, not the map. Network distance and physical distance are different things: traffic flows toward the places where networks exchange it directly, so a well-connected city further away regularly beats a poorly-connected one next door. There is also a floor you cannot argue with — light covers roughly 200 kilometres per millisecond in fibre, and a round trip pays that distance twice. A server on the other side of the world will always feel like one, whatever the protocol.
05 · Names
Blocking happens before the connection, not after
Clean Web works at name resolution. When something on your device asks for the address of a known tracker or ad host, the answer is refused, and the device never opens a socket to it. Nothing is fetched and then hidden — the request does not happen, which is why it saves data rather than just hiding clutter.
This is cheap and fast, and it has an obvious limit: it blocks by name. A tracker served from the same domain as the content you want will still arrive, because there is no name to refuse. It is not a content filter and it is not antivirus. The counter in the app is counting refused lookups, not advertisements you would otherwise have seen.
06 · When it breaks
The second you change network
The tunnel is held open by the operating system rather than by the app, so closing the app does not drop it, and neither does the app being swapped out of memory. What ends it is the configuration itself going away — you disabling the VPN profile in Settings, or another VPN app taking over, since only one can be active at a time.
Changing network drops it too, and that one is worth sitting with. Walk out of a café and your phone leaves the Wi-Fi for mobile data; the tunnel has to be rebuilt, and for that second there is no tunnel. Traffic can reach the network you are on. Nothing holds it at the device. WireGuard's single round trip is what keeps that window to about a second instead of several, but short is not the same as closed. The practical consequence is an ordering: connect before you join something you would rather not be seen on, not after.
Where this stops
A tunnel changes who can watch you. It does not make you anonymous, it does not help if your device is already compromised, and it cannot get you onto a network that has not let you on yet — nothing can be tunnelled before a captive portal has been accepted. The full list of what this does not do is on the features page, stated plainly for the same reason this page exists.
See what it doesn't do