VyneVPN Legal

Privacy Policy

How VyneVPN handles app, subscription, security, advertising, notification, and limited VPN operational data.

Effective July 24, 2026Revision 1

1. Who controls your data

VyneVPN is provided by KEYLAB OÜ, registration number 14676735, registered in Estonia. Our postal address is Männimäe, Pudisoo Küla 74626, Harju maakond/Estonia. You can contact us about privacy at bilgi@keylab.eu.

This policy is effective from 2026-07-24.

2. Data we process

VyneVPN is accountless. We do not require your name, phone number, social account, or email address to use the app.

We process a randomly generated app installation identifier, app and iOS version, first and last activity times, launch count, and current feature or service state. This lets us operate the service, diagnose availability, enforce rate limits, and protect the service from abuse.

When you use a subscription, we process Apple transaction and entitlement metadata needed to validate access, such as product identifier, transaction references, subscription status, renewal state, and relevant expiration or refund events. Apple processes your payment details; VyneVPN does not receive your full payment card information.

For VPN access, we issue per-install IKEv2 credentials. Protected credential secrets are stored encrypted where applicable and are revoked after expiration, refund, cancellation, revocation, or abuse.

If you enable notifications, we process your notification permission state, Apple Push Notification service environment, and an encrypted device token so that requested service messages can be delivered.

Security controls may process pseudonymous App Attest keys, short-lived challenges, request counters, and abuse-prevention records. These controls are used to distinguish genuine app requests from automated or tampered requests.

3. Limited VPN operational records

VyneVPN may retain a connection timestamp and total bandwidth amount for service operation, capacity management, abuse prevention, and troubleshooting. These operational records are retained for no more than 72 hours.

We do not store or log VPN traffic content, DNS queries, visited URLs or domains, payload or content packets, or mappings between a source IP address and a user's browsing activity.

VPN traffic data is not sold, used for advertising, or disclosed to third parties for advertising purposes.

4. Advertising and consent

Free users may see Google AdMob advertising when advertising is enabled. VyneVPN requests non-personalized ads and does not request App Tracking Transparency permission for personalized tracking.

Where required, Google's User Messaging Platform presents consent or privacy choices before an eligible advertising request. Google and its advertising partners may process device, consent, diagnostic, and ad-delivery data under their own privacy terms. You can reopen available privacy choices from the app settings.

Premium users do not receive advertising from VyneVPN while their premium entitlement is active.

5. Why we process data

  • To provide and secure the VPN service and requested app functions.
  • To validate purchases, restore subscriptions, and enforce premium access.
  • To deliver notifications you have enabled.
  • To detect abuse, protect infrastructure, and enforce service limits.
  • To meet legal obligations and resolve support or privacy requests.
  • With consent where applicable to advertising privacy choices.

Depending on your location, our legal bases may include performing the service you requested, our legitimate interests in operating and securing VyneVPN, compliance with law, and your consent where consent is required.

6. Service providers and international processing

We use service providers only as needed to operate VyneVPN. These may include Apple for App Store purchases and push notifications, Google for AdMob and consent management, Vercel for backend hosting, and Supabase for managed PostgreSQL infrastructure.

These providers may process data in countries outside your own. Where required, transfers are protected by applicable contractual or legal safeguards.

7. Retention and deletion

VPN operational connection records are retained for no more than 72 hours. Short-lived security challenges and rate-limit records are removed after their operational purpose expires. Subscription, credential, notification, and app installation state is retained only while needed to provide the service, protect it, meet legal obligations, or resolve disputes.

You may request deletion of your app installation record. Deletion may require active VPN credentials to be revoked first. Some transaction or security records may be retained where law, fraud prevention, accounting, or dispute handling requires it.

8. Your rights and choices

Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability of personal data. You may withdraw consent where processing relies on consent. You may also complain to your local data protection authority.

Because VyneVPN is accountless, include the anonymous installation identifier shown in the app settings when making a request. Do not send VPN passwords, private keys, payment card details, or traffic data.

Notification permission can be changed in iOS Settings. Subscription renewal can be managed through your Apple Account subscription settings. Advertising privacy choices can be reopened from VyneVPN settings where available.

9. Children

VyneVPN is not directed to children below the minimum age required to consent to digital services in their country. We do not knowingly request a child's name, email address, or other account identity.

10. Changes

We may update this policy when the service, law, or our providers change. The published effective date identifies the current version.

11. Contact

Privacy: bilgi@keylab.eu

Support: bilgi@keylab.eu

Postal address: Männimäe, Pudisoo Küla 74626, Harju maakond/Estonia