Not connected to Privasee VPN sites see your real address 216.73.216.204 · create an account

Privacy Policy

Last updated September 10, 2026

In short. We do not record what you do online. We keep no record of the websites you visit, the contents of your traffic, or your DNS queries — not because we delete them, but because the servers are not configured to produce them. We do keep a small amount of connection metadata, described precisely below, because it is how plan limits are enforced. This policy states what we hold, for how long, and what we can be compelled to disclose.

1. Who is responsible for your data

Privasee VPN LLC is the controller of the personal data described in this policy. Contact: privacy@privasee.org.

2. What we do not collect

We do not record, and are therefore unable to produce:

3. What we do collect

3.1 Account data

Your email address; a cryptographic hash of your password (never the password itself); your account status and plan; if you enable it, a two-factor authentication secret, held encrypted; and the date, time and IP address of your most recent sign-in to the website. We retain the sign-in address for the life of the account, to detect account compromise.

We ask for an email address because it is how we deliver account recovery, expiry notices and security notifications. We do not require your legal name, postal address or telephone number, and you should not send them to us.

3.2 Device data

For each device you register: a name you choose, a certificate issued to that device, and an identifier derived from the device, used to enforce the device limit of your plan.

3.3 Connection records

When a device connects, we record: which of our servers it connected to; the certificate name used; the internal address assigned inside the tunnel; the time the session started and ended and its duration; and the number of bytes sent and received. This exists to enforce plan limits, to show you your own active sessions, and to operate the network. It does not describe what you did.

Source address. A connection record also contains the public IP address your device connected from, together with the source port. We hold a salted cryptographic hash of that address; the address also appears in the session identifier used to match a disconnection to its connection. Both are removed when the record is deleted under the retention schedule in clause 5. We do not store the source address anywhere else, and we do not associate it with any destination.

3.4 Payment data

We record which payment method was used, the amount, the currency, the status, and a reference issued by the payment processor. We never receive or store your card number.

Card payments are processed by Stripe, who act as an independent controller of the data you provide to them. Cryptocurrency payments are processed through BTCPay, which does not require you to provide personal data to us; if you wish to minimise the personal data attached to your account, this is the method to choose.

3.5 Diagnostic reports

The client applications include a “send to developers” function. It transmits nothing unless you press it. When you do, it sends the application log, your account email, the device name, the platform and the application and operating system version, together with any note you write. The log and the note are stored encrypted. Application logs describe the state of the VPN connection; they are not a record of your browsing.

3.6 Administrative and server logs

We keep an audit record of administrative actions taken on an account, including the IP address from which the action was taken. Our VPN servers keep operational logs of the VPN daemon, which record connection and disconnection events, including the source address of the connecting device. These are rotated and overwritten on the servers and are not aggregated into any profile.

4. Why we are permitted to process it (UK/EU GDPR)

5. How long we keep it

DataRetention
Connection records (including the source address and its hash) A short, operator-configured period, 7 days by default, after the session ends. Then deleted automatically.
Server performance metrics14 days by default
Administrative audit records365 days
VPN server operational logsRotated on the server; a small number of rotations are kept
Account data, including last sign-in address For the life of the account
Payment recordsAs long as tax and accounting law requires, typically several years
Diagnostic reportsUntil resolved and no longer needed

Deletion is performed by an automated task; we do not maintain archival copies of deleted connection records beyond routine backup rotation.

6. Who we share it with

We do not sell your personal data. We share it only with:

7. Law enforcement requests

We disclose data only where we are presented with legal process that is valid and binding on us in our jurisdiction. We assess each request, and refuse those that are defective, overbroad, or not binding on us.

What we can disclose is bounded by clause 2: we hold no record of your traffic, destinations or DNS queries, so no order can compel us to produce them. Where we are legally permitted to do so, we will make reasonable efforts to notify an affected Subscriber before disclosure.

8. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you; to have it corrected; to have it erased; to restrict or object to its processing; to receive it in a portable format; and to withdraw consent where processing is based on consent. If you are in California, you additionally have the right to know what is collected and to whom it is disclosed, the right to delete, and the right not to be discriminated against for exercising those rights — noting that we do not sell or share personal information as those terms are defined under the CCPA.

To exercise any right, write to privacy@privasee.org. We will respond within the period required by applicable law. You may also close your account at any time from your dashboard, which revokes every device certificate immediately. If you believe we have handled your data unlawfully, you may complain to your local supervisory authority.

9. Security

Passwords are stored using a modern one-way hashing algorithm. Two-factor secrets and diagnostic reports are stored encrypted. Each device holds its own certificate, so a single device can be revoked without affecting the others. Traffic between your device and our servers is encrypted by OpenVPN or WireGuard. No system is perfectly secure, and we do not claim otherwise.

10. International transfers

Our servers are located in a number of countries, which you select when you connect. Your account data is held in the jurisdiction in which we operate. Where data is transferred internationally we rely on an appropriate safeguard recognised under applicable data protection law.

11. Children

The Service is not directed to children, and we do not knowingly collect personal data from a child. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Cookies

The website sets a session cookie so that you can remain signed in, and a token that protects forms against cross-site request forgery. These are strictly necessary for the site to function. We do not use advertising or third-party tracking cookies.

13. Changes to this policy

We may update this policy. Where a change materially affects your rights we will give notice by email or by prominent notice on the website before it takes effect. The date at the top of this page always reflects the current version.

14. Contact

Privacy enquiries and rights requests: privacy@privasee.org.

Terms of Service · Privacy Policy · Refund Policy