Per-App VPN

Per-App VPN lets you control which apps on your Android device route their traffic through the Nettica VPN tunnel and which connect directly to the internet. This is sometimes called split tunneling at the app level. It is particularly useful when you want most traffic to go through a tunnel service but need a specific app — for example a banking app that rejects VPN connections — to bypass the tunnel.

Access Per-App VPN by tapping the apps icon that appears on a VPN row on the main screen (Android only).

Per-App VPN is an Android-only feature. It is not available on iOS, macOS, Windows, or Linux. This screen works well in landscape mode as it presents the settings and apps in two columns instead of a single column in portrait mode.


Modes

Choose one of three modes from the selector at the top of the screen:

When to use Include mode: you want a small number of apps to go through the VPN (for example, a work app that requires a corporate network), and you want everything else to use your normal connection.

When to use Exclude mode: you want most traffic through the VPN but have a few apps that must not use it (for example, streaming services that block VPNs, or banking apps).


Selecting Apps

When Include or Exclude mode is active, a scrollable grid of installed apps appears. Each tile shows the app's icon and name.


Select All

Tap Select All to add every currently visible app to the selection in one tap. This is handy when you want most apps selected and only need to deselect a few — select all, then tap the ones you want to remove.


System Apps

System apps — built-in Android apps, pre-installed manufacturer apps, and background services — are hidden by default to keep the list to a manageable size. Enable Show system apps to include them in the grid.

Including or excluding core system apps can affect system functionality, network connectivity diagnostics, and app updates. Exercise caution when toggling system apps.


Saving Changes

Tap Save to apply your selections. The app writes the new per-app configuration to the VPN connection on the Nettica server and then automatically restarts the WireGuard tunnel so the new routing rules take effect immediately. You do not need to manually toggle the VPN off and on.

Tap Cancel to discard all changes and return to the previous screen without modifying the VPN configuration.


Viewing Current Per-App Settings

After saving, the VPN Settings screen for this connection shows a read-only summary of the current per-app configuration:

To change the selection, return to the main screen and tap the apps icon on the VPN row again.