Colour mode
This guide walks you through the whole app in everyday language. Download the Suite for free, unlock residual Connect with a KEYGEN when you are ready, then use the three tabs — VPN, %, and EVOLVE — and the Settings that sit behind the gear on the VPN tab.
Nothing here is an operator console. Installers are free; residual Connect needs an active KEYGEN (monthly licence from £3). The unlock screen is only your licence key — enter it when you are ready to Connect.
Default: Download free; Connect needs KEYGEN
What it is
You install Restore Privacy Suite without paying for the package. Residual Connect (the VPN path that changes your public IP) waits until you enter a KEYGEN from your fulfilment email.
How to use it
Download your platform build from the homepage free installer grid (or /suite/download). Open the app, accept the end-user licence, then enter the KEYGEN (RPT-KEY-…) on the unlock screen or under Settings → Payment entitlement. A monthly licence starts at £3; yearly residual plans remain on /pay if you prefer that option.
Default: Manual Connect; entry Germany (DE)
What it is
The VPN tab is where you start and stop residual protection. It shows connection status, a short local log, entry country, and the honesty note about Suite self-update.
How to use it
Choose an entry country if you like (Germany is the product default), then press Connect and approve any system VPN prompt. Wait until status is honestly connected before you rely on residual IP. Press Disconnect when you are done — minimize does not stop the tunnel.
Default: Available after unlock; not residual Connect
What it is
The % tab is Perccent wallet inside the Suite shell. It is a separate surface for wallet work — not a second residual tunnel.
How to use it
Open the % tab from the bottom navigation. Use the wallet UI there for local wallet actions. Residual Connect still lives only on the VPN tab; your KEYGEN story is shared across the Suite.
Default: Available after unlock; analysis only
What it is
EVOLVE is the analysis surface in the same Suite app. It sits beside VPN and % so you do not juggle three installers.
How to use it
Select EVOLVE from the bottom navigation and use the tools shown there. It does not replace Connect; for residual public IP, return to VPN and Connect while your KEYGEN is active.
Default: Lean off until you opt in
What it is
Settings under the VPN gear cover power-up, residual privacy scale, KEYGEN fallback, local log, leak test, legal links, and Suite self-update.
How to use it
Tap the gear on the VPN tab. Defaults are lean: startup and autoconnect off, traffic shaping / outer obfuscation / multi-hop off, self-update off. Turn on only what you understand. Each control is listed below.
Default: Off
When ON, the app can open at sign-in (platform startup hooks). Default OFF — it only runs when you launch it. This does not Connect the VPN by itself.
Default: Off
When ON, opening the app starts Connect automatically after licence and KEYGEN unlock. Default OFF — Connect is manual. Unlock is never skipped.
Default: Off
When ON, this device may receive a pushed Suite package (operator “Push update to clients” or breadcrumbs) and store it as pending. You still must click “Unpack update and relaunch” under this Allow Suite self-update section in Settings. That path is the one privacy breach in the Suite — leave OFF if you prefer no self-update. Silent unpack never runs.
Default: Always on
Always on: licence + keygen entitlement, cryptographic HELLO/session, and system residual tunnel (capture your public IP through the VPN node). Those cannot be turned off here — without them this is not a working VPN.
Default: IPv4 always on; IPv6 on by default
IPv4 residual capture is always on (full-tunnel dual /1 routes) and cannot be turned off in Settings. IPv6 residual ISP-leak protection defaults ON and remains optional — turning IPv6 residual OFF means IPv6 may use the ISP and Connected status will not claim IPv6 is protected. Using IPv4 only may cause data leaks on dual-stack networks. Changing IPv6 Settings while residual is connected disconnects first, then saves for the next Connect.
Default: Off
Traffic shaping pads packet sizes, adds small send jitter, and sends periodic cover (dummy) frames so traffic is harder to fingerprint. OFF (product default) = leaner packets and less cover → snappier browsing; weaker against size/timing analysis. ON = stronger privacy against coarse traffic analysis; slightly more bandwidth and latency. Residual VPN crypto and tunnel still work either way.
Default: Off
Outer obfuscation wraps residual UDP in a QUIC-like shell so clear RPT framing is not obvious on the wire. OFF (product default) = bare RPT frames (node still accepts both) → slightly less overhead; easier for simple classifiers to spot product traffic. ON = better blend with generic encrypted UDP; small CPU/header cost. Not a claim of full DPI-undetectability either way.
Default: Off
Multi-hop residual routes via an exit hop (entry → Germany exit) so egress IP is the exit, not only the selected entry (default Germany). OFF (product default) = single hop to the entry node — lower lag/ping. ON = extra hop path when configured — more privacy of path, higher latency. Requires residual multi-hop routing; does not replace licence/keygen unlock.
Default: Measure on demand
Settings can show best-effort RTT from your device toward product entry (and exit when multi-hop is ON). Tap Measure ping when you want a rough sense of path health — not a speedbench SLA. Values may show n/a if the host is unreachable from your network.
Default: Must accept before Connect
Connect stays blocked until you accept the end-user licence on this device. Acceptance is stored only locally (not uploaded to the node). After accept, enter the fulfilment KEYGEN to unlock residual VPN.
Default: Required for Connect
Installers are free. Residual Connect needs a KEYGEN after you take a monthly licence (from £3) on restoreprivacy.online — email delivers RPT-KEY-…. Enter it on the unlock screen or Settings → Payment entitlement. Download alone does not unlock residual HELLO. Connect only works while the subscription is active; refunds or failed charges stop Connect until you renew.
Default: On-device only
Settings can show and export a local connection log. Events stay on your device — they are not uploaded to the node. Export only if you choose to email support yourself.
Default: Optional diagnostic
Optional residual honesty checks from Settings (capture / DNS). Local diagnostic only — not a third-party leak site.
Default: Open in browser
Opens the public security audit, privacy policy, and licence on the status host so you can read them without a public source tree.
/suite/download). You do not pay for the package itself./pay). Email delivers KEYGEN (RPT-KEY-…) after checkout.If Connect fails after KEYGEN: re-enter the key, confirm the subscription is still active, check firewall / UDP path, and open the security audit. Privacy policy and licence are linked from the homepage and Settings.