WHAT THE APP DOES
Split tunneling, the kill switch, and the rest of what the app does
A short, accurate list of what the StreamShield app actually has, how to switch each one on, and — because it matters more than a feature table — what it does not have.
Split tunneling: choose which apps skip the VPN
Split tunneling runs in exclude mode: everything uses the VPN except the apps you pick. Open Settings in the app, choose Split tunneling, and switch off any app that should go around the tunnel.
The three reasons people usually want it:
- An app that refuses to work over a VPN. Some services block known VPN addresses outright. Excluding that one app is better than turning the whole tunnel off.
- A banking or payment app. Signing in from an address in another country tends to trigger fraud checks and extra verification.
- Anything that talks to your own network. Casting to a speaker or reaching a device at home has no reason to leave through a server in another country.
Changes apply on the next connect
Android fixes per-app rules at the moment the tunnel is established, so they cannot be altered on a live connection. We could reconnect for you automatically — but on a television that means dropping whatever you are watching to action a settings change, so instead the screen tells you a reconnect is needed and leaves the timing to you.
If the rules cannot be applied for any reason, the app connects with everything inside the tunnel rather than failing to connect. Erring toward more protection rather than less is the right default for a setting most people will configure once and forget.
Kill switch: how to turn on Android’s
A kill switch blocks your device from reaching the internet at all when the VPN is not connected, so nothing slips out unprotected during a dropout. It is the feature most worth having and the one most often described loosely, so here is the precise position.
StreamShield does not implement its own kill switch. Android does, and StreamShield works with it. The app registers as a system VPN service, which is what makes it selectable in Android’s own always-on settings. We would rather point you at the one built into the operating system than ship a second, weaker one inside the app and call it a feature.
Turning it on
- Connect once first, so Android has a profile to attach the setting to.
- Open Settings, then Network and internet, then VPN. The app’s Settings screen has a System VPN settings row that opens this for you.
- Tap the gear next to StreamShield VPN.
- Turn on Always-on VPN, then also turn on Block connections without VPN. The second one is the part that actually blocks traffic — the first only reconnects.
The caveat, before you rely on it
Not every device exposes that screen. Fire OS and several Android TV builds hide the always-on VPN settings entirely, and where the screen does not exist the option cannot be enabled by us or by you. The app’s own wording says “when this device provides one” for exactly this reason. If a kill switch is essential to you on a TV device, check it on the device before you depend on it.
Reconnect after a reboot — and why it is not a kill switch
Switch on reconnect after reboot and the connection comes back by itself when the device restarts. On a Fire Stick or an Android TV box, which get unplugged, power-cycled and knocked off shelves, this is the difference between a VPN that is on and one that is on when someone remembered.
It is worth being clear that this is a different thing from a kill switch, because a lot of writing on this subject blurs them. Reconnect after reboot covers the gap after a restart. A kill switch covers a dropout in the middle of a session by blocking traffic instead of letting it out unprotected. One is convenience, the other is containment, and having the first does not give you the second.
Servers, regions and profiles
Every plan reaches every server — no region is held back for a higher tier. You can see the whole fleet, and which nodes are up right now, on the server status page, which needs no account to read.
For anything the Android app does not run on — a router, a desktop OpenVPN client, a NAS — each server publishes a downloadable profile from that same page. It is the same connection, configured by hand.
No activity logs
We do not record what you browse or watch. That is the short version; the complete list of what is kept, what is not, and how long any of it survives is on the no-logs page, which is the honest treatment rather than a bullet point.
What StreamShield does not have
More useful than a longer feature list, and it saves you finding out after paying:
- No in-app kill switch — Android’s system one, as above, and not on devices that hide it.
- No obfuscation or stealth protocol. If you are on a network that blocks VPNs outright, this will not get through it.
- No multi-hop or double VPN.
- No dedicated or static IP, and no port forwarding.
- No ad or tracker blocking. A VPN is not an ad blocker and we would rather not imply otherwise.
- No native iOS app. iOS devices can use an OpenVPN client with a downloaded profile.
If you want the app, the download page has the current version and the Downloader code for Fire TV, and the Fire Stick guide walks through installing it on a TV device.
ANSWERS
Feature questions
- What is a VPN kill switch?
- It blocks your device from reaching the internet at all when the VPN is not connected, so nothing slips out unprotected during a dropout or a reconnect. Without one, a brief disconnection means your traffic goes out over your ordinary connection for a few seconds without any visible sign that it happened.
- Does StreamShield have a kill switch?
- Not inside the app — Android provides one at system level and StreamShield works with it. Turn it on under Settings, Network, VPN, then the gear next to StreamShield, and enable both "Always-on VPN" and "Block connections without VPN". The app has a System VPN settings row that opens that screen for you. One caveat worth knowing before you rely on it: Fire OS and some Android TV builds do not expose that screen at all, so on those devices it is not available.
- What is split tunneling for?
- It lets specific apps bypass the VPN while everything else keeps using it. The usual reasons are an app that refuses to work over a VPN, a banking app that treats a foreign IP address as suspicious, or something that talks to a device on your own network and has no reason to go out through the tunnel at all.
- Why do split tunneling changes not apply straight away?
- Android fixes per-app rules when the tunnel is established, so they cannot be changed on a live connection. We could reconnect automatically to apply them, but on a TV that would drop whatever you were watching to action a settings change. Instead the screen tells you a reconnect is needed and leaves the timing to you.
- Will the app reconnect after I unplug my Fire Stick?
- If you turn on reconnect after reboot, yes — the connection is restored when the device starts up again. That is a convenience feature, not a kill switch: it covers the gap after a restart, not a dropout in the middle of a session.
- Can I use split tunneling and the kill switch together?
- Yes, and it is worth understanding what happens. Android blocks traffic from apps that are inside the tunnel when it is down. Apps you excluded through split tunneling are outside it, so they keep working — which is usually what you wanted, but means an excluded app is not protected by the block either.
Start streaming with a private connection
Pick a plan, install the app, and connect. No activity logs, ever.
See plans and pricing