1. Scope and our privacy approach
This Privacy Policy applies to xVPN products, applications, websites, subscriptions, and services that link to it (together, the “Services”). In this policy, “xVPN,” “we,” “us,” and “our” refer to the provider of the Services.
We design the Services to use the minimum information reasonably needed to operate a reliable VPN. We do not use your VPN browsing activity to advertise to you or build a profile of the sites and apps you use.
2. Information we may collect
The information available to us depends on the Services and features you choose to use. It may include:
- Account and subscription information, such as your email address, plan, subscription status, and transaction or receipt identifiers. Payment card details are processed by the relevant app store or payment provider and are not stored by xVPN unless clearly stated at checkout.
- Communications and submissions you send to us, including support emails, feedback, survey answers, and information you choose to include in a request.
- Device and application information, such as device category, operating system and app version, language, general network type, crash reports, and diagnostic events.
- Approximate location inferred from an IP address when needed to provide a nearby server, localize the Service, prevent fraud, or comply with regional requirements. We do not collect precise GPS location unless a feature clearly requests it and you grant permission.
- Website information collected through essential cookies and limited analytics, such as pages viewed, referring pages, browser type, and interaction events.
3. VPN connection data and no-logs design
xVPN does not collect, inspect, log, or retain the websites you visit, DNS queries generated by your browsing, traffic contents, destination domains or IP addresses, messages, files, or browsing history while you are connected to the VPN. We do not associate VPN browsing activity with a name, email address, Apple account, or other real-world identity.
To establish and operate a connection requested by the user, the Service necessarily processes limited technical data: an anonymous installation token, iOS as the platform, the source IP address required for network communication, the selected country, city, server and protocol, and connection success, failure, duration, or quality measurements. These values do not contain traffic contents or browsing destinations. They are used only to authenticate an anonymous installation, issue VPN credentials, route the encrypted connection, prevent abuse, troubleshoot failures, and measure service reliability.
Raw public-IP, approximate-location, and speed-test results requested by the user are displayed in the app. xVPN does not receive or retain those raw results as a browsing or VPN activity history. If the user separately authorizes tracking through Apple’s App Tracking Transparency prompt, only content-free app-interaction and broad performance buckets may be processed for attribution and app-performance measurement. Refusing that authorization does not affect VPN or subscription access.
We do not sell, rent, use for advertising, profile users from, or disclose to third parties any VPN traffic or browsing data. Limited operational data is not combined with browsing history or destination data and is not used to identify an individual user.
4. How and why we use information
We use information only for legitimate operational, contractual, security, and legal purposes, including to:
- Provide, maintain, authenticate, and troubleshoot the Services and your subscription.
- Choose responsive infrastructure, balance network capacity, and improve connection reliability.
- Respond to requests and send service, security, billing, or policy notices.
- Understand feature performance and develop new or improved Services.
- Prevent fraud, abuse, security incidents, and violations of our Terms of Service.
- Measure and improve marketing without using your VPN browsing activity.
- Comply with applicable law, valid legal process, and enforceable requests.
Where the GDPR or UK GDPR applies, our legal bases may include performance of a contract, consent, compliance with legal obligations, protection of vital interests, and our legitimate interests in operating and securing the Services.
7. Security
We use administrative, technical, and organizational safeguards intended to protect information against unauthorized access, alteration, loss, and disclosure. These measures may include encryption in transit, access controls, monitoring, and vendor reviews.
No online service can guarantee absolute security. You are responsible for protecting your account credentials and keeping your devices and xVPN software up to date.
8. International data transfers
xVPN and its service providers may process information in countries other than your own. Where required, we use recognized safeguards for international transfers, such as adequacy decisions, Standard Contractual Clauses, or equivalent mechanisms.
When you choose a VPN server in another country, your internet traffic is routed there at your direction as part of providing the Service.
9. Data retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide a subscription, resolve disputes, meet tax or accounting requirements, enforce agreements, and prevent fraud.
Retention periods vary by data type and legal requirement. We delete or de-identify information when it is no longer needed. VPN browsing activity described in Section 3 is not retained.
10. Your choices and privacy rights
Depending on where you live, you may have the right to:
- Request access to or a copy of your personal information.
- Correct inaccurate or incomplete information.
- Request deletion or restriction of processing.
- Object to certain processing or withdraw consent.
- Receive portable information in an appropriate format.
- Opt out of marketing communications.
- Appeal a privacy decision or complain to your local data protection authority.
We may need to verify your request and may retain limited information where permitted or required by law. Authorized agents may submit requests where local law allows.
11. Regional disclosures
Residents of certain U.S. states, including California, may have additional rights to know, access, correct, or delete personal information; opt out of its sale or sharing; and limit certain uses of sensitive personal information. xVPN does not sell personal information for money. If our use of advertising technologies is considered “sharing” or “targeted advertising” under applicable law, we will provide the legally required choice and honor supported opt-out preference signals, such as Global Privacy Control, where required.
We do not knowingly discriminate against anyone for exercising a privacy right. These rights apply only where the relevant law covers xVPN and may be subject to statutory exceptions.
12. Children’s privacy
The Services are not directed to children under 13, or a higher minimum age where local law requires it. We do not knowingly collect personal information from children below the applicable age. If you believe a child has provided information to us, contact us so we can review and delete it where required.
13. Changes to this policy
We may update this policy to reflect changes in the Services, law, technology, or our practices. We will publish the revised version here and change the “Last updated” date. If a change materially affects your rights, we will provide additional notice when required.
14. Contact us
For privacy questions, rights requests, or complaints, contact xVPN by email:
legal@xvpn.co