Privacy policy
This describes what our system actually stores, taken from the implementation rather than written aspirationally. Where a third party unavoidably sees something, we say so.
What we never store
- The websites or pages you visit
- Your DNS lookups
- The addresses or ports you connect to
- Your browsing or search history
- Your source IP address after your request has been handled
- Your device's private key — it is generated on your device and never sent to us
Our gateways run their own DNS resolver with query logging switched off, and their system logs are held in memory only and are lost when the machine restarts.
What we do store
Subscription records
- A random subscription identifier that is not derived from anything about you
- The plan, its status, and when the current period ends
- A reference supplied by the payment provider, which is the minimum needed to service and cancel your subscription
- A one-way hash of your private access code
- An email address, only if you chose to give one for receipts
Device records
- Your device's public key, the private half never leaves your device
- An address inside the tunnel, such as 10.77.0.2, which is not a public address and does not identify you
- The platform, an optional nickname you chose, and the date the device was last seen
Operational metrics
Aggregate figures per gateway: processor and memory use, total bytes in and out, how many devices are connected, and how many have a recent handshake. These carry no user, source address, destination address or domain labels.
Third parties that see something
We cannot honestly claim that no third party ever processes your IP address.
- Cloudflare serves this website and our API. Cloudflare's edge necessarily sees the IP address you connect from and processes it for routing and abuse protection. Our own application code removes IP-bearing headers before anything is written to a log.
- Stripe, PayPal and NOWPayments process payments when their method is enabled. They receive the information required for their payment rails. We never see your full card number. Card, PayPal and blockchain transactions are not completely anonymous, and we do not describe them that way.
- Our hosting providers operate the physical machines the gateways run on.
Retention
- Signed return tokens: short-lived and used only to complete the requested return journey
- Aggregate gateway metrics: seven days
- Subscription records: for as long as the subscription exists, and afterwards only where we are required to keep them
- Gateway system logs: held in memory, lost on restart
Legal requests
If we are compelled by a valid legal order, we can only hand over what we hold. That is subscription and payment-reference information. We cannot produce browsing history, DNS queries or connection destinations, because we do not have them.
Your rights
Under UK data protection law you may ask for a copy of your data, ask us to correct or delete it, or object to processing. Write to privacy@uvpn.ai. Because the service is deliberately built without identity, we may be unable to locate your records without your private access code.
What we have not done
We have not had this service independently audited. When we do, we will publish the report and link it here.