Privacy policy
Anaximander Group Ltd, company number 17294798. Last updated 19 August 2026.
This policy explains what uVPN stores, what it does not store, and who else may process information about you when you use the service. Where a third party unavoidably sees something, we say so.
What we never store
- The websites or pages you visit
- Your DNS lookups
- The addresses or ports you connect to
- Your browsing or search history
- Your source IP address after your request has been handled
- Your device's private key — it is generated on your device and never sent to us
Our gateways run their own DNS resolver with query logging switched off, and their system logs are held in memory only and are lost when the machine restarts.
What we do store
Subscription records
- A random subscription identifier that is not derived from anything about you
- The plan, its status, and when the current period ends
- A reference supplied by the payment provider, which is the minimum needed to service and cancel your subscription
- A one-way hash of your private access code
- An email address, only if you chose to give one for receipts
Device records
- Your device's public key, the private half never leaves your device
- An address inside the tunnel, such as 10.77.0.2, which is not a public address and does not identify you
- The platform, an optional nickname you chose, and the date the device was last seen
Operational metrics
Aggregate figures per gateway: processor and memory use, total bytes in and out, how many devices are connected, and how many have a recent handshake. These carry no user, source address, destination address or domain labels.
Third parties that see something
We cannot honestly claim that no third party ever processes your IP address.
- Cloudflare serves this website and our API. Cloudflare's edge necessarily sees the IP address you connect from and processes it for routing and abuse protection. Our own application code removes IP-bearing headers before anything is written to a log.
- Stripe, PayPal and NOWPayments process payments when their method is enabled. They receive the information required for their payment rails. We never see your full card number. Card, PayPal and blockchain transactions are not completely anonymous, and we do not describe them that way.
- Our hosting providers operate the physical machines the gateways run on.
Retention
- Signed return tokens: short-lived and used only to complete the requested return journey
- Aggregate gateway metrics: seven days
- Subscription records: for as long as the subscription exists, and afterwards only where we are required to keep them
- Gateway system logs: held in memory, lost on restart
Legal requests
If we are compelled by a valid legal order, we can only hand over what we hold. That is subscription and payment-reference information. We cannot produce browsing history, DNS queries or connection destinations, because we do not have them.
Your rights
Under UK data protection law you may ask for a copy of your data, ask us to correct or delete it, or object to processing. Write to privacy@uvpn.ai. See Data deletion requests below for what we need in order to find the right records, and what we can and cannot remove.
Data deletion requests
uVPN.ai does not require a conventional user account. To request deletion of data associated with your subscription, purchase or app installation, email privacy@uvpn.ai with the subject “uVPN data deletion request”.
Do not send us your private access code, VPN private key, authentication token or any password. We may ask for a non-secret purchase reference, payment-provider reference, device information or approximate purchase date so that we can locate the correct records.
After verifying the request, we will delete or anonymise data that is no longer required, including associated device records, public keys and any optional device nickname you chose.
We may retain limited subscription and transaction records where required for accounting, tax, fraud prevention, refunds, chargebacks or legal compliance. We may also retain a minimal record of the deletion request where required to demonstrate compliance. These records will be kept only for as long as required for those purposes or by applicable law. Where UK tax law sets that period, it is six years from the end of the relevant accounting period.
uVPN.ai does not store browsing history, DNS queries, connection destinations or VPN activity logs, so there is no such browsing data to delete.
uVPN.ai is operated by Anaximander Group Ltd, 20 Wenlock Road, London N1 7GU, United Kingdom, which is the data controller for these requests.
Independent audit
This service has not yet been independently audited. If that changes, we will publish the report and link to it here.