Effective 3 August 2026 · v2026-08-03

Privacy Policy

What follows is the complete list of what we keep, why, and for how long. Every item on this page corresponds to a real column in our database, and every retention period to an automatic deletion that runs every day.

01

Who is responsible for your data

The data controller is vALORA CLOUD LLC, a Florida limited liability company (United States), document no. L26000295448, located in Clearwater, Florida 33764, United States.

You can exercise any right or ask anything about this policy by writing to [email protected]. We have no designated data protection officer: write to that address and a person answers.

02

What we keep about you

About your account: your email address, whether and when you verified it, your password turned into an argon2id hash (never in the clear), your name if you give one, your language, which version of these terms you accepted and when, and the two-step verification secret if you enable it. If you sign in with Apple or Google we store the identifier that provider gives us instead of a password. For security we also store the failed sign-in counter and how long the account is locked.

About each device: the alias you choose, the platform, the OS and app version, the WireGuard public key, the internal address we assign it inside the VPN, an install identifier that lets us recognise a reinstall on the same device, and when it was last seen, to the hour. We identify devices by that alias and identifier, not by serial numbers or advertising identifiers.

About your settings: kill switch, auto-connect, local network access, protocol, DNS mode and the DNS server you set if you choose your own, the list of apps you decide to exclude from the tunnel (only the package identifier you tick), theme, language, and which notices you want. Plus the push notification token if you enable them.

About your connections: for each tunnel session we store which of our servers it went to, when it started and ended, why it ended, how many bytes went up and down, and the measured latency. Yes: that is a dated list of your sessions, and we keep it for 30 days in order to bill, support you and detect abuse. What is not in that list is where you connected to.

About your billing: the plan, subscription status and period, invoices with amount, currency and tax, and the identifying details of the payment method the gateway returns to us (brand, last four digits and expiry). The full card number never passes through our servers.

About support: the messages and tickets you write to us, and the diagnostics you choose to send (protocol, MTU, operating system, connection type and the tunnel’s latest incidents).

About telemetry: nothing, unless you turn it on yourself. Analytics, crash reports and performance metrics ship switched off and there is a toggle in Settings. If you enable them, the data is processed by Google Firebase. We do not use an advertising identifier.

03

What we do not keep, by design

We do not store the IP address you connect to us from, nor destination IP addresses, nor the domains you visit, nor your DNS queries, nor ports, nor anything of your traffic content. This is not a statement of intent: our database has no columns for that data, and the project’s internal rule is that any change adding them is rejected. That is why, when we say we cannot hand over your activity, it is because we do not have it.

We also do not perform or commission external audits, and we do not publish a warrant canary. Other VPNs advertise these; we prefer not to claim anything we cannot show today. If there is ever a real audit, this page will say so with the report linked.

04

Why we are allowed to process it

If the GDPR applies to you, these are our legal bases. Performance of the contract: the account, devices, tunnel and billing, because without that data there is no service. Legitimate interests: account security, fraud and abuse prevention, and running the network. Consent: telemetry and marketing notices, which you can withdraw at any time without losing the service. Legal obligation: keeping invoices.

05

How long we keep it

Tunnel sessions and tunnel incidents: 30 days, deleted automatically. Diagnostics you send: 7 days. Payment gateway events: 90 days. Verification and pairing codes: minutes or hours, until they expire. Your account and device data, for as long as the account exists. Invoices, for as long as applicable accounting and tax rules require, even if you delete the account.

06

Who else sees them

We do not sell or share your data with anyone for advertising. The following share it with us, only for what is necessary: Stripe, to take card payments; RevenueCat together with Apple and Google, for purchases made inside the app; our own self-hosted cryptocurrency gateway, for USDT payments (the transaction goes straight to our wallet and no external processor sees it); Cloudflare, which sits in front of the site and the API as a delivery network and firewall; the mail provider that delivers verification codes and notices; the providers of the servers that make up the network, whose current list we give you on request; and Google Firebase, only if you have enabled telemetry.

One specific, limited exception: the website’s "My IP" page queries the ipwho.is service to geolocate the address it is checking, so that address is sent to that service. This happens only on that page and only while you have it open. No other part of the site or the apps uses it.

If we receive a valid legal request, we can only hand over what we have: the account data, the billing status, and, if within 30 days, the tunnel sessions with their server and volume. We cannot hand over which sites you connected to because that data does not exist in any system of ours.

07

Deleting your account

You can request deletion from Account → Delete account on the website and in the app, or by writing to [email protected] from the account address. The account is marked and, after 30 days, anonymised: the email is replaced by a value with no identifying value, the password and name are removed, the two-step secret is deleted and all your devices are revoked. Those 30 days exist so you can change your mind and so we can answer a payment dispute. Invoices already issued are kept as an accounting obligation.

08

Where your data is

The company is in the United States and our servers are in the United States and the European Union. If you are in the European Economic Area, the United Kingdom or Switzerland, your data may be processed in the United States; where required, those transfers rely on the European Commission’s standard contractual clauses or the equivalent applicable mechanism.

09

Your rights

You can ask us for access to your data, its correction, its deletion, the restriction of its processing, object to it, take it elsewhere in a readable format, and withdraw any consent you have given. Write to [email protected] from your account address and we answer within the deadline set by the law that applies to you, which under the GDPR is one month.

If you are in the European Economic Area or the United Kingdom and believe we have mishandled your data, you can complain to your country’s supervisory authority (in Spain, the Agencia Española de Protección de Datos; in the United Kingdom, the ICO). We would rather you told us first, but it is your right and you do not have to come through us.

If you reside in California, you also have the right to know which categories of data we collect and with whom we share them — they are above, in sections 02 and 06 — to have them corrected or deleted, and not to be treated worse for exercising those rights. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of.

10

Children

The service is not directed at children under 13, nor under 16 where that is the minimum age to consent to processing without a parent or guardian’s authorisation. If we learn that an account belongs to a child below that age, we close it and delete their data.

11

Changes to this policy

If this policy changes materially, we notify you 90 days in advance by email and inside the app, and the version and date above change. If anything we do with your data changes, this page changes first.