Privacy Policy — CipherVPN
Legal Document

Privacy Policy

How CipherVPN collects, uses, and protects your personal data

Effective Date: 1 January 2026  ·  Last Updated: 25 February 2026  ·  Version 3.1

1. Overview & Scope

This Privacy Policy ("Policy") describes how CipherVPN ("CipherVPN", "we", "us", "our") processes personal data in connection with the CipherVPN platform, including CipherVPN, CipherMail, and all associated websites, mobile applications, desktop clients, APIs, and services (collectively, the "Services").

CipherVPN is built on a foundational principle: we collect the minimum data necessary to operate our services securely and nothing more. Our technical architecture is designed to prevent us from accessing the content of your communications or your browsing activity.

This Policy applies to all users globally. Where we offer region-specific rights (e.g., GDPR for EEA residents, CCPA for California residents), those are explicitly stated in the relevant sections. If you use our Services on behalf of an organisation under an Enterprise Agreement, that agreement's data processing addendum (DPA) governs in any conflict with this Policy.

By accessing or using the Services, you confirm you have read and understood this Policy. If you disagree with any part, please discontinue use and contact us for clarification.

2. Data Controller Identity

The data controller for all personal data processed under this Policy is:

EntityDetail
Legal NameCipherVPN Ltd
Registered AddressAvailable upon formal legal request
Company TypePrivate Limited Company
Data Protection Officerdpo@ciphervpn.eu
GDPR Representative (EEA)eu-rep@ciphervpn.eu
UK Representativeuk-rep@ciphervpn.eu

For Enterprise customers, CipherVPN acts as a data processor on behalf of the customer organisation (the controller) for data processed within the customer's dedicated infrastructure. The Enterprise DPA governs this relationship.

3. Data We Collect

We categorise data collection into three tiers based on necessity:

3.1 Account Data (Required)

Data ElementPurposeRetention
Email addressAccount identification, login, transactional notificationsDuration of account + 30 days
Password (hashed, bcrypt)AuthenticationDuration of account
Account creation dateFraud prevention, compliance7 years post-closure
Subscription statusService access controlDuration + 7 years (billing law)
Payment processor tokenRecurring billing (Stripe/PayPal token only — no card numbers stored)Duration of subscription

3.2 Operational Data (Minimal — See No-Log Policy)

Data ElementPurposeWhat We DON'T Collect
VPN session timestamps (connect/disconnect)Abuse detection, network capacity planningSource IP address, destination IPs, URLs, DNS queries
Aggregate bandwidth (total bytes per day)Fair usage enforcementPer-destination traffic breakdown
Protocol used (WireGuard/OpenVPN)Load balancingPacket contents or metadata
Server region selectedQuality monitoringYour real IP address after connection

Zero-Log Commitment: We do not log, store, inspect, or correlate VPN tunnel traffic. We cannot map your VPN session to any outbound connection. Our infrastructure is designed to make such logging technically impossible in production environments — audited annually by independent third parties.

3.3 CipherMail Data

Email metadata (sender address, recipient address, timestamp, subject line if unencrypted) is handled as follows:

  • Messages encrypted end-to-end (PGP or our CipherVPN E2E protocol): CipherVPN has zero access to content or metadata beyond routing information necessary for delivery.
  • Messages in transit (SMTP relay for non-CipherVPN recipients): Standard SMTP headers are processed for delivery and immediately discarded. We do not retain SMTP relay logs.
  • Stored messages: Stored at-rest using AES-256-GCM with per-account keys derived from your passphrase. CipherVPN does not hold key material for E2E accounts.

3.4 Technical & Device Data

ElementCollectedPurpose
App versionYesCrash diagnostics, update enforcement
Operating system & versionYesCompatibility support
Device fingerprintNoN/A
Advertising ID (IDFA/GAID)NoWe do not use ad networks
Crash dumpsOptional (user-controlled)Bug fixes — stripped of personal data before processing

3.5 Communication Data

When you contact our support team, we collect: your email address, the content of your message, and any attachments you send. Support tickets are retained for 3 years for quality assurance and compliance. You may request deletion of individual support records at any time.

5. How We Use Your Data

We use collected data strictly for the following purposes, with no cross-purpose processing without fresh notice and legal basis:

  • Service delivery — routing VPN connections, delivering email, managing account sessions
  • Authentication & security — verifying identity, detecting and preventing unauthorised access
  • Billing & subscription management — processing payments, issuing invoices, handling disputes
  • Customer support — responding to tickets, diagnosing technical issues
  • Legal compliance — responding to valid, lawful orders from competent authorities
  • Service improvement — analysing aggregated, anonymised performance metrics to improve reliability
  • Communications — sending transactional emails (password reset, payment receipts, security alerts) and, with consent, product updates

We do not: sell data, share data with advertisers, use data for profiling, or engage in behavioural advertising.

6. No-Log Architecture

CipherVPN is architecturally designed to prevent logging of user activity. This is not merely a policy commitment — it is a technical implementation:

Technical Controls

  • VPN servers run in memory-only mode — no persistent storage is mounted on tunnel servers
  • Kernel-level firewall rules block all syslog writes related to tunnel interfaces
  • Access logs for the VPN infrastructure API are written to a separate, restricted system and contain only administrative actions, not user traffic
  • IP address NAT pools are shared across all active users simultaneously — making individual attribution technically infeasible
  • WireGuard keys are ephemeral — rotated every 24 hours. No session keys are retained after rotation

Independent Audits

Our no-log policy is verified by annual security audits conducted by independent third-party firms. Audit reports are published in summary form in our Transparency Report. We have never been required to produce VPN traffic logs in response to a legal order because such logs do not exist.

In the event of a court order or legal process requesting VPN traffic records, we can only provide: account creation date, email address, subscription status, and the fact that a session occurred (timestamp only). We cannot provide source IP, destination, or any browsing data because it is not collected.

7. Data Sharing & Disclosure

We do not sell, rent, trade, or commercially share your personal data. Data is shared only in the following specific circumstances:

7.1 Service Providers (Processors)

Provider TypeData SharedPurposeSafeguards
Payment processor (Stripe)Email, billing amountPayment processingDPA, PCI-DSS Level 1, SCCs
Cloud infrastructure (bare-metal, no major hyperscalers for VPN nodes)Encrypted payloads onlyNetwork transitDPA, encrypted transit
Email delivery (transactional only)Email, namePassword reset, receiptsDPA, TLS, SCCs
Customer support softwareSupport ticket contentHelpdesk managementDPA, access controls

7.2 Legal Disclosure

We disclose personal data in response to legal process only when all of the following conditions are met:

  1. The request is from a competent authority in a jurisdiction where we have legal obligations
  2. The request is legally binding and specific (not broad surveillance requests)
  3. The request has been reviewed by our legal counsel
  4. We have exhausted any available legal challenges

We publish aggregate statistics on legal requests received in our annual Transparency Report. Where legally permitted, we notify affected users.

7.3 Business Transfers

In the event of a merger, acquisition, or asset sale, we will provide 30 days' notice before any personal data is transferred to a new entity. Users will have the right to delete their account before any such transfer.

8. Retention Periods

Data CategoryRetention PeriodBasis
Account credentialsDuration of account + 30 days after deletion requestContract
Billing records7 years from transaction dateTax/accounting law
Support tickets3 years from closeLegitimate interest (QA)
VPN session timestamps7 days (rolling window, automated deletion)Abuse detection
Aggregate bandwidth stats90 daysCapacity planning
Security/access logs (admin infrastructure)90 daysSecurity operations
Legal hold dataDuration of hold + 30 daysLegal obligation
Anonymised analyticsIndefinitely (no personal data)N/A

Upon account deletion, all personal data is purged within 30 days from production systems and within 90 days from encrypted backup archives. Billing records subject to statutory retention obligations are retained in isolated, restricted storage.

9. Technical Security Measures

We implement layered technical and organisational security measures (ISO/IEC 27001 framework):

Encryption

  • Data at-rest: AES-256-GCM for all persistent storage
  • Data in-transit: TLS 1.3 minimum for all API communications; WireGuard (ChaCha20-Poly1305) or OpenVPN (AES-256-GCM) for VPN tunnels
  • Database fields: sensitive columns (email, payment tokens) encrypted at application layer before storage

Access Controls

  • Role-based access control (RBAC) with principle of least privilege
  • Multi-factor authentication mandatory for all staff with infrastructure access
  • Hardware security keys (FIDO2) required for production system access
  • All access to data systems logged and reviewed quarterly
  • Zero-trust network architecture — no implicit trust on internal networks

Operational Security

  • Annual penetration testing by independent security firms
  • Vendor security assessments for all data processors
  • Background checks for employees with data access
  • Incident response plan with 72-hour breach notification capability (GDPR Art. 33)
  • Bug bounty programme — responsible disclosure at security@ciphervpn.eu

10. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

RightDescriptionGDPRCCPA
AccessObtain a copy of all personal data we hold about youArt. 15
RectificationCorrect inaccurate or incomplete personal dataArt. 16
Erasure ("Right to be Forgotten")Request deletion of all personal data (subject to legal retention obligations)Art. 17
RestrictionPause processing while a dispute is resolvedArt. 18
PortabilityReceive your data in a machine-readable format (JSON/CSV)Art. 20
ObjectionObject to processing based on legitimate interestsArt. 21
Withdraw consentRevoke any consent-based processing at any timeArt. 7
Non-discriminationEqual service regardless of exercising privacy rights

To exercise any right, submit a request to privacy@ciphervpn.eu or via Account Settings → Privacy Controls. We respond within 30 days (GDPR: 1 month, extendable by 2 months for complex requests). We verify identity before processing rights requests via email confirmation or authentication.

If you believe we have violated your rights, you have the right to lodge a complaint with your national supervisory authority. For EEA residents: your local Data Protection Authority. For UK residents: the Information Commissioner's Office (ICO).

11. Cookies & Tracking Technologies

Our marketing websites use a minimal cookie footprint:

CookieTypePurposeDuration
sessionEssentialAuthentication sessionSession / 14 days if "remember me"
csrf_tokenEssentialCross-site request forgery protectionSession
pref_themeFunctionalUI preference (dark/light mode)1 year
_analyticsAnalytics (consent)Aggregate page view counting (self-hosted, no 3rd party)90 days

We do not use Google Analytics, Meta Pixel, or any third-party advertising trackers on any of our properties. Our analytics system is self-hosted and processes only aggregated, anonymised data.

You can manage cookies via your browser settings or our cookie preference centre at the bottom of any landing page.

12. International Data Transfers

CipherVPN operates infrastructure globally to provide low-latency service. Personal data (account records only — not tunnel traffic) is stored primarily within the EEA. Where data is transferred to third countries, we ensure adequate safeguards:

  • Standard Contractual Clauses (SCCs) — EU Commission 2021/914 for all EEA-to-third-country transfers
  • UK IDTA — International Data Transfer Agreement for UK-originated data
  • Adequacy decisions — where available (e.g., transfers to countries with EU adequacy decisions)
  • Binding Corporate Rules — in development for intra-group transfers

You may obtain a copy of applicable SCCs by contacting dpo@ciphervpn.eu.

13. Children's Privacy

The Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will delete that data within 48 hours.

If you believe a minor has registered an account, contact privacy@ciphervpn.eu immediately with the account email address.

14. Policy Changes

We may update this Policy as our practices evolve or legal requirements change. When we make material changes:

  • We will update the "Last Updated" date at the top of this document
  • We will notify registered users by email at least 30 days before the new Policy takes effect
  • For significant changes affecting your rights, we will require affirmative re-consent
  • Previous versions are archived and available upon request

Continued use of the Services after the effective date constitutes acceptance of the revised Policy.

15. Contact & Data Protection Officer

Data Protection Officer

dpo@ciphervpn.eu
Response within 5 business days
GDPR Art. 37–39 compliant

General Privacy Enquiries

privacy@ciphervpn.eu
Rights requests, data access
Response within 30 days

Security & Vulnerability Reports

security@ciphervpn.eu
PGP key available on request
72-hour acknowledgement SLA

Legal & Law Enforcement

legal@ciphervpn.eu
Valid legal requests only
Reviewed by legal counsel