Early Access - WireGuard configs - No traffic or DNS query logs stored on VPN servers
Privacy Policy

NoLogVPN Privacy Policy

This page explains what personal data NoLogVPN collects, how it is used, how long it is kept, and where third-party providers are involved.

Effective: 21/08/2026Updated: 21/08/2026Version: 2026-08-21-r6

No-Log Statement

The separate No-Log Policy covers the VPN activity side of the service. In short: NoLogVPN does not store traffic logs, browsing activity logs, or DNS query logs on its own VPN servers. This Privacy Policy focuses on the personal data and operational records that are retained to run the service, including the minimal bandwidth/accounting totals needed for fair use.

Controller, Sources, and Eligibility

The data controller is the Romanian PFA provider identified in the Legal Notice. Full identity and contact details are kept in one place to avoid conflicting information: Legal Notice.
We receive data directly from you during enrollment, checkout, support, and account setup; from Stripe for payment and subscription status; and generate it when the service provisions a device, applies plan limits, or delivers a message. The public connection check uses the visible IP only when that page is requested. Form fields marked as required are needed for the contract; optional feedback or support messages are not required to purchase.
The service is intended only for people aged 18 or over. We do not knowingly request children's data; if we learn that such data was provided, we review and delete it where required.

Personal Data We Collect

Pending enrollment data

Before payment, we temporarily keep the verified email, password hash, selected plan, hashed verification credentials, checkout reference, and consent details needed to finish enrollment. This is not an active user account and cannot access the dashboard or VPN.

Account data

While the account exists: email address, password hash, account status, and account creation time. Password hashes are not copied into the post-closure compliance history.

Password reset records

Short-lived password reset token hashes, expiry times, and related delivery or completion events needed to operate self-service password reset. Used or expired reset tokens are removed automatically.

Billing and subscription data

Selected plan, subscription status, renewal or cancellation timing, provider customer and subscription references, and related billing metadata.

Device records

For active devices: device name, WireGuard public key, assigned internal VPN IP, and selected protection mode. Revoked-device records and linked device-scoped events are erased within 7 days.

Checkout consent data

Typed checkout name, policy release and document fingerprints, consent flags, language, timestamp, and related payment or subscription references.

Policy notice evidence

For contract-change notices: recipient address, policy release and document fingerprints, email-template version, Message-ID, content fingerprint, queue and SMTP-acceptance times, attempts, status, and limited error codes. This specialized evidence is not duplicated in the account timeline, and we do not add an email-open tracking pixel.

Limited account and contract history

One deletion-safe timeline records the normalized account email, original account reference, typed checkout signature where supplied, account creation or closure, consent and policy version, plan and payment-provider references, important subscription or account actions, and acceptance of essential lifecycle email by the outgoing mail server. Routine operational events are kept only briefly.

Bandwidth accounting data

Minimal current-cycle and current-day bandwidth totals, plus operational counter state needed for fair-use enforcement, network protection, and throttling.

Flex aggregate billing data

Where Flex is offered, we keep aggregate received-plus-sent byte totals per invoice cycle, the related Stripe customer/subscription references, queued and reported meter quantities, and reporting status. We do not attach destinations, DNS queries, traffic content, protocols, apps, or browsing/session history to this ledger.

Why We Use It

To operate your account

Authentication, account access, device provisioning, subscription status, and dashboard management.

To process payments

Stripe-hosted checkout, subscription management, renewal state, and billing issue handling.

To deliver service messages

Email verification, subscription activation and lifecycle notices, account-security notices, policy-change notices, and inactive-account deletion warnings. Stripe, not NoLogVPN email, sends official invoices and receipts.

To provide support and abuse control

Self-service password reset, billing support, device troubleshooting, and reasonable fraud or abuse prevention.

To meet legal obligations

Record-keeping needed for payment disputes, legal obligations, or compliance where required.

Automated Rules and Human Review

Automated rules apply subscription status, simultaneous-connection limits, fair use, the selected DNS protection, and inactive-account scheduling. These rules use account, plan, device, and aggregate-counter state, not browsing history, traffic content, or a marketing profile.
You may contest a restriction, suspension, or deletion schedule and request human review through support. Before an inactive account is automatically deleted, warning notices are sent and the presence of an active subscription is checked again.

Legal Bases

We use data needed for account creation, authentication, VPN delivery, device management, and subscription handling to perform the contract with you.
We use data needed for billing, accounting, tax, legal requests, and required record keeping to comply with legal obligations.
We use limited data for security, fraud prevention, support, troubleshooting, network protection, and the establishment, exercise, or defense of legal claims based on legitimate interests, without keeping VPN activity logs.
Where a flow asks for separate consent, such as checkout agreement consent, we use that consent for the related consent record.

Third-Party Services

Stripe: Stripe processes payments and keeps its own payment and subscription records under Stripe's policies.
Cloudflare: Cloudflare fronts the public website and API. Cloudflare may keep edge or network records under Cloudflare's policies.
Email delivery provider: Our configured email provider processes recipient addresses and message-delivery metadata for verification, subscription lifecycle, security, support, and inactive-account deletion notices.
IP lookup provider: The public connection status card may send the visitor's visible IP address from a server-side route to an IP lookup provider to display approximate location and provider/ISP. This lookup is not a VPN activity log and does not include browsing history, DNS queries, or traffic contents.
Upstream DNS resolvers: Our DNS layer forwards queries upstream for resolution. We disable EDNS client subnet on our side, but upstream resolvers operate under their own policies.

Transfers and Your Rights

Some providers, such as Stripe, Cloudflare, or email services, may process data in Romania, the EEA, or other countries. Where GDPR requires a transfer safeguard, we rely as applicable on an adequacy decision, Standard Contractual Clauses, or another mechanism permitted by GDPR Article 46. You may request information about the safeguard relevant to your data.
Depending on the situation, you may request access, rectification, erasure, restriction, portability, objection to processing, and withdrawal of consent where processing is based on consent. We normally respond within one month; GDPR permits an extension for complex requests. We may request proportionate information to verify identity. Requests are free except for the limited cases permitted for manifestly unfounded or excessive requests.
The right to erasure is not absolute. We may retain only records still needed for a legal obligation or for the establishment, exercise, or defense of legal claims; we may restrict their processing to those purposes and delete them when that basis ends.
You have the right to lodge a complaint with the competent data protection supervisory authority. In Romania, the authority is ANSPDCP: dataprotection.ro.

Retention, Deletion, and Security

Operational account, subscription, and device records are kept while needed to supply the service and are then deleted under the specific periods below.
The minimal account and contract history is retained throughout the customer relationship and, after account closure, until the later of five years from closure or the applicable Romanian accounting archive deadline. It is the single canonical record for those events and contains only the limited data described above.
The Flex aggregate billing ledger is retained for no more than 5 years after the invoice cycle ends. It may be retained longer only where a legal obligation, payment dispute, or limited Legal Hold requires it. At expiry, the ledger and its reporting events are erased automatically when no unresolved billing event remains.
Where there is an actual dispute, chargeback, legal claim, official request, or security incident, we may apply a limited Legal Hold that pauses automatic deletion only for relevant records. The hold is reviewed at least annually and released when its reason ends.
Policy-notice evidence is retained for 5 years from queueing to demonstrate the version and content sent, SMTP-server acceptance, and handling of delivery errors. This evidence does not prove inbox placement or that the message was read.
Abandoned enrollments expire within 48 hours. Temporary records for a completed enrollment are deleted within 7 days, after the temporarily stored password hash has already been removed at account activation. Password reset tokens are deleted automatically after use or expiry. Non-essential operational events are auto-purged after a short retention window.
If an account remains without an active subscription for at least 14 days, we may send a notice with its scheduled deletion date and a final reminder before that date. A subscription activated before the stated date automatically cancels the schedule. When deletion takes effect, the application removes access, authentication, devices, keys and DNS settings, the local subscription, operational bandwidth counters, and operational events. Only the minimal account and contract history and, where Flex billing occurred, the aggregate billing ledger remain until their separate retention deadlines. Payment providers may separately retain records required by their policies or the law.
Third-party providers may keep their own billing or network records under their own policies even when our VPN servers do not store user activity logs.
Live operational state, such as recent VPN handshake status used for simultaneous-connection enforcement, is used at runtime and is not presented as a long-term browsing or DNS history record.

Privacy Contact

For privacy questions, no-log clarification, or account-related help, contact [email protected].

This is also the current route for exercising GDPR rights. If a data protection officer is appointed, their contact details will be published here and in the Legal Notice.