Privacy Policy for PlanckVPN
Version 2.0 · Effective date: July 28, 2026 · Supersedes the policy dated 14 May 2026
PLAIN ENGLISH SUMMARY
What this means for you
- We do not log what you do on the VPN. No browsing history, no DNS queries, no destination addresses, no traffic content, no per-site bandwidth, no timestamps tied to destinations. The tunnel is encrypted and we do not record what passes through it. This is Section 2 and it is the core of this policy.
- We do hold an account and a device record. If you buy a subscription you give us an email address; the app generates a device identifier; we store a WireGuard public key and, for the duration below, which server your device last connected to and when.
- We use a small set of specialist providers — hosting, payments, notifications — described in Section 5. None of them receives your VPN activity.
- We have no advertising, no free tier, no analytics or tracking SDK, and we have never sold data. The subscription is the only revenue. There is no second business model that data could serve.
- When you delete your account we scrub it, but we keep a minimal billing record — your email address and a subscription summary — because tax, accounting and chargeback law requires us to. Section 6 explains exactly what survives and for how long.
- You have rights — access, correction, deletion, portability, objection — and Section 7 tells you how to use them.
- The summary is not the policy. Where the two differ, the numbered sections govern.
- Questions: support@planckvpn.com
Who we are and how to reach us
PlanckVPN (“PlanckVPN”, “we”, “us”) operates the PlanckVPN applications for iOS, Android and Windows, the account portal at account.planckvpn.com, and the VPN server network described in Section 3.
| Data controller | Everly Hill LLC, McLean, VA, United States |
| Privacy contact | support@planckvpn.com |
| Security / vulnerability reports | support@planckvpn.com (subject line SECURITY) |
We answer privacy requests from the address above within 30 days.
Scope
This policy covers the PlanckVPN apps, the account portal, the public website, our support channels, and the VPN gateway network. It does not cover the websites and services you reach through the VPN — once your traffic leaves our exit gateway it is subject to the privacy practices of whoever you connected to.
The zero-log commitment
This is the section that matters, so it is written precisely rather than in marketing language.
2.1 What we do not record — ever
While your device is connected to a PlanckVPN gateway, we do not create, retain, inspect or transmit any record of:
- —destination addresses — the IP addresses, domains or hostnames you connect to;
- —DNS queries — we do not run query logging on our resolvers and we do not store resolutions;
- —traffic content — the data inside the tunnel, which is encrypted end-to-end between your device and the exit gateway;
- —browsing or application history of any kind;
- —per-destination bandwidth, volume, or session timing that could reconstruct what you did;
- —deep packet inspection results — we do not perform DPI, protocol fingerprinting, or content classification on user traffic;
- —any association between your identity and the traffic leaving our exit IPs.
We do not maintain these records in temporary form either. There is no rotating buffer, no “kept for 24 hours for troubleshooting” carve-out, and no debug mode that starts logging traffic. The gateways are not configured to produce this data, so there is nothing to delete, nothing to leak, and nothing to disclose.
2.2 Why we are able to say this
Our gateways run WireGuard, OpenVPN and IKEv2 with logging of connection contents disabled. Our servers publish only aggregate, non-personal counters — total bytes transferred and interface throughput per server — which we use for capacity planning. These counters are per-server totals; they are not per-user, they are not per-destination, and they cannot be resolved back to an individual.
2.3 What this means when someone asks us for data
If a law enforcement agency, court, or private party demands records of a user’s VPN activity, we cannot produce them, because they do not exist. We will respond to a valid, properly served legal order with the categories of data described in Section 3 that we actually hold — which for the VPN service itself is limited to subscription status and, within its retention window, the fact that a device was allocated a peer slot on a given server. Where the law permits us to notify you of a demand for your data, we will.
2.4 The limit of any VPN’s promise
We are not going to overstate this. A VPN moves the point at which your traffic becomes visible; it does not make you anonymous. The website you visit still sees your session, your login, and your cookies. Your operating system, browser and the apps you run can identify you independently of us. If your threat model requires anonymity rather than privacy, a VPN alone — ours included — is the wrong tool.
What we do process
Everything we hold is listed below, together with the legal basis under GDPR Article 6 on which we process it.
3.1 VPN application and gateway data
| Data | Legal basis |
|---|---|
| Device identifier — generated by the app on first launch; not an advertising ID, not the hardware serial | Contract (Art. 6(1)(b)) |
| WireGuard public key | Contract |
| Assigned tunnel IP and peer allocation (which gateway, which internal 10.x address) | Contract |
| Last-connection timestamp per gateway | Legitimate interest (Art. 6(1)(f)) — capacity management |
| Originating IP address at the moment of connection setup | Legitimate interest — service delivery and abuse prevention |
| Platform and OS version | Contract |
| App Attest / Play Integrity attestation — a public key and counter (iOS) or a verification timestamp (Android) | Legitimate interest — fraud and abuse prevention |
| Attestation challenges | Legitimate interest — security |
| Temporary OpenVPN credentials | Contract |
| Push notification token (if you enable notifications) | Consent (Art. 6(1)(a)) — you may withdraw it in OS settings at any time |
| Connection-failure telemetry — which gateway failed, which fallback was tried, error class, app version | Legitimate interest — service quality |
Note on the last row: this telemetry describes our infrastructure failing, not your activity. It records that a connection to a named gateway timed out. It does not record where you were going.
3.2 Account and billing data (account portal)
You only have an account record if you created one. The apps can be used with a store subscription without a portal account.
| Data | Legal basis |
|---|---|
| Email address | Contract |
| Full name | Contract |
| Password — stored only as an Argon2id hash (64 MiB memory cost, 4 iterations, per-password salt). We never store, log or transmit the password itself, and we cannot recover it | Contract |
| Account status, email-verification timestamp, password-change timestamp | Contract |
| Last login timestamp and IP address | Legitimate interest — account security |
| Failed-login counters and temporary lockout state | Legitimate interest — security |
| Login attempt records — IP, email, success flag, user agent | Legitimate interest — security |
| Security events — password changes, device revocations, consent grants, with IP and user agent | Legal obligation (Art. 6(1)(c)) / legitimate interest |
| Session cookie (psv_sess) and CSRF token | Strictly necessary — no consent required |
| Mobile refresh tokens — stored only as a SHA-256 hash, with device identifier and a device name you choose | Contract |
| Email verification and password-reset codes — stored only as a SHA-256 hash | Contract |
| Mobile sign-in handoff codes | Contract |
| Marketing consent flag and timestamp | Consent |
| Referral code | Contract |
3.3 Subscription and payment data
We never see your card number. Card data is entered directly with the payment provider and never reaches our servers.
| Data | Why | Legal basis | Retention |
|---|---|---|---|
| Subscription state — plan, status, current period, renewal or cancellation dates, store of origin | Grants access to paid gateways | Contract | Life of account, then per Section 6 |
| Payment provider customer and subscription identifiers, store transaction identifiers (Apple App Store / Google Play) | Links your entitlement to the purchase; handles refunds and chargebacks | Contract / legal obligation | Statutory retention (see Section 6) |
| Invoice and receipt records — amount, currency, date, invoice URL | Accounting and tax | Legal obligation | Statutory retention (see Section 6) |
3.4 Support, breach-scan and partner data
| Data | Why | Legal basis | Retention |
|---|---|---|---|
| Support tickets and messages — the email address, name and message text you send, plus app version and device identifier so we can reproduce the problem | Answering you | Contract / legitimate interest | 24 months from ticket closure |
| Breach-scan results (optional feature) — we send the SHA-256 hash of your lower-cased email to our data-breach monitoring partner, never the address itself. Returned records are stored encrypted at rest; any exposed password string is sealed with XSalsa20-Poly1305 | Warns you that a credential of yours appeared in a public breach | Consent | Until you disable the feature or delete your account; 12 months maximum |
| Affiliate / partner applications — name, email, platform, audience size, profile URL, niche, promotion plan | Assessing the application | Pre-contractual steps (Art. 6(1)(b)) | 24 months if not accepted |
| Abuse rate-limit records — request bucket and IP | Stops automated abuse of public endpoints | Legitimate interest | 90 days |
Cookies and similar technologies
The website and account portal set exactly two things: a session cookie (psv_sess, secure, HTTP-only, SameSite=Lax, cleared when you sign out) and a CSRF token bound to that session. Both are strictly necessary to sign in safely, so no consent banner is required and there is nothing to opt out of.
We set no advertising, analytics, or cross-site tracking cookies. Our bot-protection layer (Section 5) may set a short-lived challenge token on sign-in and registration pages; it is a bot check, not a tracker, and it does not profile you across sites.
Third parties who process data for us
We use a small number of specialist providers to run the service. Each acts under a data-processing agreement, receives only what its role requires, and none of them receives your VPN activity — that data does not exist (Section 2).
- —Hosting. The API, account portal and database run on encrypted infrastructure in the EU.
- —Website and API protection. A CDN, DDoS-protection and bot-check layer covers the website and API only — it never sits in front of your VPN tunnel.
- —Payments. Card details are entered directly with our payment provider and never reach our servers. In-app purchases are processed by the Apple App Store and Google Play; we receive only an opaque transaction identifier and the resulting entitlement.
- —Notifications and email. Push notifications and service emails (verification, password reset, support replies) are delivered through specialist providers, which receive the push token or email address and the message we send you.
- —Breach monitoring (optional). Our data-breach monitoring partner receives only the SHA-256 hash of your email address — never the address itself, and never a password.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we have no data-broker relationships. Under the CCPA/CPRA this means we have not sold or shared personal information in the preceding twelve months.
Deleting your account, and what survives
You can delete your account from the app or the account portal. Deletion requires your password. When you confirm it, in a single atomic operation we:
- 1.overwrite your name with a placeholder,
- 2.replace your email address with a non-routable placeholder so the original address is released and can be registered again,
- 3.overwrite your password hash with an unusable random value,
- 4.clear your last-login IP address,
- 5.revoke every device token, signing out all devices immediately and invalidating any access token still in flight, and
- 6.cancel any active subscription billed by us.
Your VPN-side records — device record, peer allocations, WireGuard key, attestation material — are deleted along with the account.
What we retain, and why. We keep a minimal billing record consisting of your email address, the subscription and payment history associated with it (plan, amounts, dates, provider transaction identifiers) and the deletion date. We keep it because we are legally required to and because deleting it would leave us unable to handle disputes about money that has already moved:
- —Statutory bookkeeping and tax law. Invoices and the records supporting them must be retained for the period set by the accounting and tax legislation applicable to us — generally 8 to 10 years. This is a legal obligation under GDPR Article 6(1)(c) and Article 17(3)(b), and it overrides the right to erasure for those specific records.
- —Refunds, chargebacks and app-store disputes. A card chargeback or a store refund can arrive months after a purchase. Without the record we cannot verify the claim, which harms both of us.
- —Fraud and abuse prevention. It lets us recognise a repeat abuse of trial or refund mechanisms.
This retained record contains no VPN activity data, because none exists (Section 2). It is not used for marketing, it is not enriched, and it is deleted at the end of the statutory period. If you want confirmation of exactly what is held for you after deletion, ask us and we will tell you.
Your rights
Wherever you live, we apply the same set of rights.
- —Access — a copy of the personal data we hold about you.
- —Rectification — correction of inaccurate data; name and email are editable in the portal.
- —Erasure — deletion of your account and data, subject only to the statutory records in Section 6.
- —Portability — your account data in a structured, machine-readable format.
- —Restriction and objection — including an absolute right to object to processing based on legitimate interest, and to direct marketing at any time.
- —Withdraw consent — for notifications, marketing and breach scanning, without affecting processing already carried out.
How to exercise them. Email support@planckvpn.com from the address on the account. We reply within 30 days and may extend once by a further two months for complex requests, telling you why. We will ask you to confirm control of the account email; we will not demand identity documents for a routine request. There is no charge unless a request is manifestly unfounded or excessive.
California residents additionally have the rights to know, delete, correct, and to opt out of sale or sharing — the last of which is moot, since we do neither.
Children
PlanckVPN is not directed at children and we do not knowingly collect personal data from anyone under 16 (or the higher minimum age set by your local law; under 13 in the United States). You must be of the age of majority in your jurisdiction, or have the consent of a parent or guardian, to buy a subscription. If you believe a child has provided us with personal data, write to support@planckvpn.com and we will delete the account and its data.
Transparency and legal requests
We publish what we can about the demands we receive on our transparency page. We respond only to legally valid, properly served process, we narrow overbroad requests, and we produce only the categories of data described in Section 3 that we actually hold. As Section 2.3 explains, records of VPN activity are not among them, because we do not create them.
Changes to this policy
We will update this policy when the service or the law changes. Material changes are announced in the app and by email to account holders before they take effect, and the version number and effective date at the top of this document always reflect the current text. Previous versions are available on request.
What will not change is the commitment in Section 2. We can add processors, adjust retention, or restructure this document — but we will not begin logging the contents, destinations or DNS queries of user traffic. If that ever ceased to be true, it would be announced as a change of service, not buried in a policy revision.
Contact
Questions, requests and complaints: support@planckvpn.com
Everly Hill LLC
McLean, VA, United States
This document describes the processing carried out by the PlanckVPN service as at the effective date above. It has been prepared to reflect the actual technical implementation, not an aspirational one.