How CipherVPN collects, uses, and protects your personal data
Effective Date: 1 January 2026 · Last Updated: 25 February 2026 · Version 3.1
This Privacy Policy ("Policy") describes how CipherVPN ("CipherVPN", "we", "us", "our") processes personal data in connection with the CipherVPN platform, including CipherVPN, CipherMail, and all associated websites, mobile applications, desktop clients, APIs, and services (collectively, the "Services").
CipherVPN is built on a foundational principle: we collect the minimum data necessary to operate our services securely and nothing more. Our technical architecture is designed to prevent us from accessing the content of your communications or your browsing activity.
This Policy applies to all users globally. Where we offer region-specific rights (e.g., GDPR for EEA residents, CCPA for California residents), those are explicitly stated in the relevant sections. If you use our Services on behalf of an organisation under an Enterprise Agreement, that agreement's data processing addendum (DPA) governs in any conflict with this Policy.
By accessing or using the Services, you confirm you have read and understood this Policy. If you disagree with any part, please discontinue use and contact us for clarification.
The data controller for all personal data processed under this Policy is:
| Entity | Detail |
|---|---|
| Legal Name | CipherVPN Ltd |
| Registered Address | Available upon formal legal request |
| Company Type | Private Limited Company |
| Data Protection Officer | dpo@ciphervpn.eu |
| GDPR Representative (EEA) | eu-rep@ciphervpn.eu |
| UK Representative | uk-rep@ciphervpn.eu |
For Enterprise customers, CipherVPN acts as a data processor on behalf of the customer organisation (the controller) for data processed within the customer's dedicated infrastructure. The Enterprise DPA governs this relationship.
We categorise data collection into three tiers based on necessity:
| Data Element | Purpose | Retention |
|---|---|---|
| Email address | Account identification, login, transactional notifications | Duration of account + 30 days |
| Password (hashed, bcrypt) | Authentication | Duration of account |
| Account creation date | Fraud prevention, compliance | 7 years post-closure |
| Subscription status | Service access control | Duration + 7 years (billing law) |
| Payment processor token | Recurring billing (Stripe/PayPal token only — no card numbers stored) | Duration of subscription |
| Data Element | Purpose | What We DON'T Collect |
|---|---|---|
| VPN session timestamps (connect/disconnect) | Abuse detection, network capacity planning | Source IP address, destination IPs, URLs, DNS queries |
| Aggregate bandwidth (total bytes per day) | Fair usage enforcement | Per-destination traffic breakdown |
| Protocol used (WireGuard/OpenVPN) | Load balancing | Packet contents or metadata |
| Server region selected | Quality monitoring | Your real IP address after connection |
Zero-Log Commitment: We do not log, store, inspect, or correlate VPN tunnel traffic. We cannot map your VPN session to any outbound connection. Our infrastructure is designed to make such logging technically impossible in production environments — audited annually by independent third parties.
Email metadata (sender address, recipient address, timestamp, subject line if unencrypted) is handled as follows:
| Element | Collected | Purpose |
|---|---|---|
| App version | Yes | Crash diagnostics, update enforcement |
| Operating system & version | Yes | Compatibility support |
| Device fingerprint | No | N/A |
| Advertising ID (IDFA/GAID) | No | We do not use ad networks |
| Crash dumps | Optional (user-controlled) | Bug fixes — stripped of personal data before processing |
When you contact our support team, we collect: your email address, the content of your message, and any attachments you send. Support tickets are retained for 3 years for quality assurance and compliance. You may request deletion of individual support records at any time.
For users in the European Economic Area, UK, and other jurisdictions requiring a legal basis, our processing is founded on:
| Processing Activity | Legal Basis | Article |
|---|---|---|
| Providing the VPN and Mail services | Performance of contract | Art. 6(1)(b) |
| Billing and payment processing | Performance of contract + Legal obligation | Art. 6(1)(b)(c) |
| Fraud detection and abuse prevention | Legitimate interests | Art. 6(1)(f) |
| Legal compliance (court orders, lawful disclosure) | Legal obligation | Art. 6(1)(c) |
| Service improvement analytics (aggregated, never individual) | Legitimate interests | Art. 6(1)(f) |
| Marketing communications | Consent | Art. 6(1)(a) |
| Crash diagnostics (when enabled) | Consent | Art. 6(1)(a) |
You may withdraw consent for consent-based processing at any time via Account Settings → Privacy Controls, or by contacting dpo@ciphervpn.eu.
We use collected data strictly for the following purposes, with no cross-purpose processing without fresh notice and legal basis:
We do not: sell data, share data with advertisers, use data for profiling, or engage in behavioural advertising.
CipherVPN is architecturally designed to prevent logging of user activity. This is not merely a policy commitment — it is a technical implementation:
Our no-log policy is verified by annual security audits conducted by independent third-party firms. Audit reports are published in summary form in our Transparency Report. We have never been required to produce VPN traffic logs in response to a legal order because such logs do not exist.
In the event of a court order or legal process requesting VPN traffic records, we can only provide: account creation date, email address, subscription status, and the fact that a session occurred (timestamp only). We cannot provide source IP, destination, or any browsing data because it is not collected.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account credentials | Duration of account + 30 days after deletion request | Contract |
| Billing records | 7 years from transaction date | Tax/accounting law |
| Support tickets | 3 years from close | Legitimate interest (QA) |
| VPN session timestamps | 7 days (rolling window, automated deletion) | Abuse detection |
| Aggregate bandwidth stats | 90 days | Capacity planning |
| Security/access logs (admin infrastructure) | 90 days | Security operations |
| Legal hold data | Duration of hold + 30 days | Legal obligation |
| Anonymised analytics | Indefinitely (no personal data) | N/A |
Upon account deletion, all personal data is purged within 30 days from production systems and within 90 days from encrypted backup archives. Billing records subject to statutory retention obligations are retained in isolated, restricted storage.
We implement layered technical and organisational security measures (ISO/IEC 27001 framework):
Depending on your jurisdiction, you have the following rights regarding your personal data:
| Right | Description | GDPR | CCPA |
|---|---|---|---|
| Access | Obtain a copy of all personal data we hold about you | Art. 15 | ✓ |
| Rectification | Correct inaccurate or incomplete personal data | Art. 16 | ✓ |
| Erasure ("Right to be Forgotten") | Request deletion of all personal data (subject to legal retention obligations) | Art. 17 | ✓ |
| Restriction | Pause processing while a dispute is resolved | Art. 18 | — |
| Portability | Receive your data in a machine-readable format (JSON/CSV) | Art. 20 | ✓ |
| Objection | Object to processing based on legitimate interests | Art. 21 | — |
| Withdraw consent | Revoke any consent-based processing at any time | Art. 7 | ✓ |
| Non-discrimination | Equal service regardless of exercising privacy rights | — | ✓ |
To exercise any right, submit a request to privacy@ciphervpn.eu or via Account Settings → Privacy Controls. We respond within 30 days (GDPR: 1 month, extendable by 2 months for complex requests). We verify identity before processing rights requests via email confirmation or authentication.
If you believe we have violated your rights, you have the right to lodge a complaint with your national supervisory authority. For EEA residents: your local Data Protection Authority. For UK residents: the Information Commissioner's Office (ICO).
CipherVPN operates infrastructure globally to provide low-latency service. Personal data (account records only — not tunnel traffic) is stored primarily within the EEA. Where data is transferred to third countries, we ensure adequate safeguards:
You may obtain a copy of applicable SCCs by contacting dpo@ciphervpn.eu.
The Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will delete that data within 48 hours.
If you believe a minor has registered an account, contact privacy@ciphervpn.eu immediately with the account email address.
We may update this Policy as our practices evolve or legal requirements change. When we make material changes:
Continued use of the Services after the effective date constitutes acceptance of the revised Policy.
dpo@ciphervpn.eu
Response within 5 business days
GDPR Art. 37–39 compliant
privacy@ciphervpn.eu
Rights requests, data access
Response within 30 days
security@ciphervpn.eu
PGP key available on request
72-hour acknowledgement SLA
legal@ciphervpn.eu
Valid legal requests only
Reviewed by legal counsel