Privacy-first

Privacy Policy

This policy explains what mVPN collects, why, and what choices you have.

Last updated: Jul 26, 2026 Applies to: mVPN iOS app and related services

1) Summary

  • We collect the minimum data required to operate a VPN account and keep the service secure.
  • We do not build profiles based on the websites you visit.
  • We process technical connection data (e.g., last handshake time and traffic counters) to provide the VPN service.
  • We use Firebase Authentication, Firebase Core services, Firebase Cloud Messaging, and Firebase backend infrastructure to operate the iOS app and service.
  • mVPN iOS build 14 does not include or use the Firebase Analytics SDK. The public website separately uses Firebase-powered analytics to measure visits, clicks, and language selection.
  • mVPN iOS build 14 has no App Store purchases or subscriptions and includes its own complimentary daily data allowance. Optional web data packs are separate and are for manual WireGuard profiles on supported non-iOS platforms.

2) Data We Collect

Account data

  • Email address (if you sign up with email/password).
  • Firebase user identifier (uid) used internally to link your account and VPN access.
  • Approximate country code inferred from the IP observed at registration; the raw IP is not stored for this purpose.

Device and VPN service data

  • Device identifier you provide to the service (used to enforce the active manual-profile limit).
  • WireGuard peer identifiers/keys and an assigned internal VPN IP address.
  • Connection state and telemetry needed to operate the service, such as last handshake timestamp and traffic counters (RX/TX bytes).
  • A Firebase Cloud Messaging push token and basic delivery metadata if you enable notifications.

Support and security logs

  • Audit events related to security-sensitive actions (e.g., config issuance, key rotation, access revoke).
  • Basic request logs for debugging and abuse prevention.

Optional web-purchase data

  • For optional website purchases, we process Stripe customer and transaction identifiers, pack, amount, currency, payment status, and related account entitlement records.
  • Stripe processes payment-card details. mVPN does not receive or store your full card number.

What we do not intentionally collect

  • Browsing history (which websites you visit).
  • Content of your traffic.

3) How We Use Your Data

  • Provide VPN connectivity and generate WireGuard configuration for your account/device.
  • Enforce account rules, including the active manual-profile limit.
  • Operate, secure, and improve the service (e.g., detect abuse, debug failures).
  • Communicate with you about support requests and important service changes.

4) Sharing and Third-Party Services

We use third-party infrastructure providers to run the service. These providers may process data on our behalf:

  • Google Firebase (Authentication, Core services, Cloud Messaging, Cloud Functions, Firestore, and Hosting).
  • Google Analytics for Firebase on the public website only (website visit and event measurement); the iOS app does not include or use Firebase Analytics.
  • Stripe (payment processing for optional web data packs used by manual WireGuard profiles on supported non-iOS platforms).
  • An IP geolocation provider may process the request IP to return an approximate country code at registration; mVPN does not store the raw IP for this purpose.
  • DNS provider configured in the VPN profile (example: 1.1.1.1).
  • Apple distributes the iOS app and provides platform services. mVPN iOS build 14 offers no App Store purchases or subscriptions.

We do not sell VPN or personal data, use VPN traffic or activity data for advertising or analytics, or disclose VPN traffic or activity data collected by mVPN to third parties for their own purposes.

VPN data commitment: mVPN uses operational VPN data only to provide and secure the service. Infrastructure providers process the minimum account and service data on our instructions. A DNS resolver configured in the tunnel handles DNS requests directly; mVPN does not receive or store DNS query contents.

5) Data Retention

When you delete your account in the iOS app under Profile → Delete Account, we remove the active account, VPN peer and configuration, device, quota, profile, and ordinary service data. We retain a non-reversible pseudonymous deletion tombstone to prevent unsafe account restoration or event replay. We may also retain the minimum transaction, accounting, fraud-prevention, or dispute records required by law or legitimate security needs. Retained records are not used to restore the account, operate its VPN access, or market to you.

6) Security

We take reasonable measures to protect data, including access controls and secure transport where applicable. No method of transmission or storage is 100% secure.

7) Your Choices

  • You can sign out and stop using the VPN at any time.
  • You can delete your active account and associated VPN service data in the iOS app under Profile → Delete Account, or contact us for help. The limited retention described in Section 5 still applies.

8) Children

mVPN is not intended for children under 13. If you believe a child has provided personal data, contact us.

9) Changes to This Policy

We may update this policy from time to time. The “Last updated” date will reflect the latest version.

10) Contact

Questions or deletion requests: support@mvpnapp.net