eSIM Without an App: Why We Refuse to Ship One (and How Install Works)
Every eSIM provider has an app, and every store listing says the same things: manage your plans, top up, stay connected. What the listing does not say is what the app does on your device between those balance checks. Cypher eSIM has no app. Not because we ran out of time, but because we looked at what a provider app actually is, vendor code with network access and an analytics budget, and decided the honest move is to keep our code off your phone entirely. This article is the reasoning in full, and then the practical half: how installing an eSIM without an app works, step by step, on both platforms.
What actually ships inside a typical eSIM app
An eSIM app is never just a storefront. Consumer apps are assembled from third party SDKs, and travel eSIM apps follow the pattern. The standard load looks like this:
- An analytics SDK in the Firebase or Amplitude class, recording which screens you open, what you tap, and how long you stay.
- An attribution tracker in the AppsFlyer or Adjust class, whose whole job is to link your install to the ad you clicked, which means ad networks learn you are now an eSIM user.
- Push infrastructure. The app registers a device push token, a durable handle that ties this install to this phone for as long as the app lives there.
- Permissions. Location requests justified as picking the right plan for your region, plus camera, network state, and whatever else the release manager approved that quarter.
This is not a hypothetical. Exodus Privacy, the French nonprofit that scans Android apps for known tracker signatures, has a public report trail for mainstream eSIM apps. An archived Exodus report for Airalo's Android app, version 1.25.5, scanned in 2023, lists 6 trackers and 18 permissions, and earlier builds of the same app carried up to 8 trackers. To be clear, we are not accusing Airalo of anything unusual. It is a competently built, normal mainstream app. That is exactly the point: several trackers and a long permission list is what normal looks like in this market.
The store account is the identity anchor nobody mentions
Now suppose a provider genuinely collects nothing in the app. No analytics, no attribution, a clean binary. The app still betrays you at the moment of installation, because apps do not arrive out of thin air. They arrive through a store, and the store knows you.
- The download is on your record. Your Apple ID or Google account logs the install, and that account is tied to your name, your payment card, and your devices.
- In-app purchases run through platform billing. Pay inside the app and the receipt lands in an account that already holds your legal identity.
- The history persists. Download history survives deletion, syncs across devices, and sits in backups you do not control.
So when a provider says "we never ask your name", that can be true and still beside the point. The provider does not need to ask. If distribution runs through an app store, the platform has already written the sentence that matters: this person uses this eSIM service. For a travel gadget, that is background noise. For a product sold on privacy, it is a structural defect you cannot patch.
Our answer: nothing to install, nothing to log into
Cypher eSIM works in two ways, and neither involves our code running on your device. The first is the website: you pick a plan on cypheresim.com, pay in crypto, and get your eSIM. No account, no email, no password. Your order lives behind an opaque token, a random link that proves nothing about who you are. The second is our Telegram bot, for people who live in Telegram anyway.
Every order comes with an eSIM passport: a persistent page holding your QR code, live data usage, and reinstall, readable in any browser with no login. Nothing gets installed, no push token gets minted, no store writes an entry about you. The surface we occupy on your device is a browser tab, and you close it whenever you like.
What an app honestly does better
We would be lying if we said apps have no advantages, so here are the real ones. An app can trigger the platform's native install flow directly, so activation feels like one tap with no QR ceremony. An app can render a polished dashboard with notifications when your data runs low. Those are genuine conveniences, and anyone who tells you otherwise is selling something.
Our answers are the universal link on iOS 17.4 and later, which gets you the same one-tap install with zero installed code, and the passport page, which is the dashboard without the app around it. What we accept losing is native push notifications on low balance. If you want a nudge, the Telegram bot can do it in chat. We think that trade, convenience kept, tracking surface removed, is the right one for this product.
- The path — Provider app — Our web + passport — Telegram bot
- Installed on device — The app plus its SDKs — Nothing — Telegram, which you already have
- Store account involved — Yes, Apple ID or Google — No — No new one
- Push token created — Yes, device level — No — Only Telegram's existing one
- Analytics SDKs added — Often several — None from us — None from us
- Data created by buying — Account, device IDs, event log — Opaque token, order, payment — Chat history with the bot
- QR and reinstall access — Inside the app — Passport page, no login — In the chat
- Convenience — Highest, native install — High, one saved link — High, always in your pocket
→ Choosing between the two no-app paths? Read Web checkout or Telegram bot: which fits you
How eSIM install works with no app at all
Underneath every install, app or no app, sits the same GSMA machinery. The eSIM profile lives on a chip in your phone called the eUICC. Downloading a profile is a conversation between your phone's built in profile manager, the LPA (local profile assistant), and the provider's SM-DP+ server, secured end to end by the GSMA's remote provisioning protocol. The only thing your phone needs from the provider is one string:
LPA:1$smdp.example.com$ACTIVATION-CODE
That is the whole secret. A QR code is just this string drawn as squares. A provider app is just software that types it for you. Which means everything an app does during install, your settings screen already does on its own.
Install by QR code, step by step
The default path. You need the QR code visible on a second screen, or printed. With Cypher eSIM it sits on your passport page.
- iOS: Settings, then Cellular, then Add eSIM, then Use QR Code. Point the camera at the code, tap Continue, wait for activation to finish.
- Android: Settings, then Network and internet, then SIMs, then Add eSIM or Download a SIM instead. Scan the code when prompted. Exact wording shifts by manufacturer, but the flow is the same.
- After install: label the new line, set it as your data line for the trip, and keep your home SIM active for calls if you need them. Turn on data roaming for the travel eSIM; that is normal and expected.
Install by manual LPA entry
No second screen, no printer, no problem. Every phone that scans QR codes also accepts the same data typed in. Take the LPA string and split it at the dollar signs: the middle part is the SM-DP+ address, the last part is the activation code.
- iOS: Settings, Cellular, Add eSIM, Use QR Code, then Enter Details Manually at the bottom. Paste the SM-DP+ address and the activation code into their fields.
- Android: in the QR scanner screen, look for Need help or Enter it manually, then paste the activation code. Some manufacturers ask for the full LPA string in one field, which is even easier.
Manual entry is also your fallback if a camera is broken or a QR image will not render. The string is the source of truth; the QR was only ever a picture of it.
One tap on iOS 17.4 and later
Since iOS 17.4, Apple supports eSIM installation through a universal link. The link wraps the same LPA string into a URL on esimsetup.apple.com, and tapping it on the phone that will host the eSIM opens the install screen directly. No camera, no typing, no third party code. This is the app-style one-tap experience, shipped inside the operating system itself, which is exactly where it belongs. Android has equivalents through its own activation links on many devices, though behavior varies more across manufacturers, so QR remains the universal answer there.
Is a Telegram bot just an app with better PR?
Fair challenge, so here is the honest answer. Telegram is absolutely an app, with its own analytics, its own push tokens, and its own metadata trail. We will not pretend otherwise. The difference is marginal cost. If Telegram is already on your phone, our bot adds zero new code to your device: no new SDK, no new push token, no new store record, just one more chat inside an app you already accepted. If Telegram is not something you accepted, do not install it for us. The web checkout needs nothing but a browser, and for most threat models it is the cleaner of the two paths.
- A QR code is just a string drawn as squares. An app is just software that types the string for you. We would rather hand you the string.
Where Cypher eSIM stands
We sell no-KYC travel eSIMs for 180 plus countries at cypheresim.com. You pay in crypto: USDT on TRC-20, BEP-20, Arbitrum or Solana, plus BTC, ETH, SOL, USDC, DAI, XMR, and TON. No account, no email; your order is an opaque token, and your eSIM lives on a passport page with QR, usage, and reinstall. The service is data-only today, with voice and SMS numbers launching in August 2026.
And the honesty clause we attach to everything: no-KYC is not anonymity, and an eSIM is not a VPN. Buying without identity checks removes your name from the purchase record; it does not encrypt your traffic or hide your device from the network. What we control is what exists about you on our side, which is close to nothing, and what runs on your device, which is nothing at all.
FAQ
Can I install an eSIM without any app at all?
Yes. QR scanning and manual entry are built into iOS and Android settings, and on iOS 17.4 and later a universal link opens the install screen with one tap. The provider app is a wrapper around this built in flow, not a requirement for it.
Will my eSIM keep working if I never install a provider app?
Yes. The profile is stored on the eUICC chip in your phone, not inside any app. Connectivity, roaming, and data all run at the operating system level. Apps only add management screens on top.
What is the LPA string and where do I find it?
It is the activation payload, formatted as LPA:1$, then the SM-DP+ server address, then the activation code, separated by dollar signs. It is what your QR code encodes. Cypher eSIM shows both the QR and the raw string on your eSIM passport page.
Is buying through a website really more private than an app?
On the device side, clearly: no SDKs, no push token, no store record of the install. You still create an order and a payment trail wherever you buy, so the honest claim is a smaller footprint, not an invisible one.
Do I need Telegram to use Cypher eSIM?
No. The website works on its own with no account and no email. The Telegram bot is an alternative for people who already live in Telegram, not a requirement.
So, can you run an eSIM without an app? You can, and mechanically you always could: the installer has been sitting in your settings screen the whole time. The app was never the price of admission. It was a choice a provider made about your device, and we chose differently.