Vaultsecure

Privacy Policy

Last updated: March 1, 2026

1. General Provisions

This Privacy Policy describes how Vault Secure (hereinafter — "Service", "we") collects, uses, and protects personal data of users (hereinafter — "you", "user"). By using the Service, you agree to the terms of this Policy.

Vault Secure is a VPN service that protects your internet traffic. We adhere to a strict No-Log policy: we do not track, record, or store any data about your online activity.

By using the Service, you express full and unconditional consent to the terms of this Policy. If you do not agree with its provisions, please discontinue using the Service.

2. Data Controller

The data controller is the company operating the Vault Secure service. Contact details of the controller are provided in the "Contacts" section of this Policy.

3. Sources of Information

Information processed within the Service may be personified (directly relating to a specific person) or non-personified (data about the Service User obtained without reference to a specific person).

The Administration has access to information obtained through the following channels:
  • information received during correspondence between the Administration and Service Users via email;
  • data provided by Users during registration in the Service, in surveys, requests, and feedback forms;
  • technical information — data about the Internet provider, IP address, characteristics of the PC and software used;
  • statistical data on individual User preferences (topics of pages viewed).
According to this Policy, only information stored in the Service's database in encrypted form and accessible exclusively to the Administration is considered confidential.

Information voluntarily posted by a User in publicly accessible sections of the Service when filling out registration forms and accessible to any other user, or information that can be freely obtained from other public sources, is not considered confidential.

4. No-Log Policy

Vault Secure adheres to a strict No-Log policy, which means:
  • We do not record your internet traffic or connection contents
  • We do not store DNS queries, destination IP addresses, or connection timestamps
  • Our servers operate exclusively in RAM-only mode — no data is written to disk
  • Upon server reboot, all session data is automatically erased
  • We cannot provide data about your VPN activity because it physically does not exist

5. Data We Collect

We collect the minimum amount of data necessary to operate the Service:
  • Email address — for registration, sign-in, and account recovery
  • Payment data — processed through a third-party payment provider (we do not store card data)
  • Account metadata — registration date, subscription type
We do not collect:
  • Internet traffic or connection contents
  • DNS queries
  • Destination IP addresses
  • Connection timestamps
  • Browsing history

6. Purposes of Data Processing

We process your data for the following purposes:
  • Providing and maintaining the VPN connection
  • User authentication and authorization
  • Optimizing server network and load balancing
  • Ensuring account security and fraud prevention
  • Sending important security notifications
  • Improving Service quality based on aggregated analytics

7. Legal Basis for Processing

We process personal data on the following grounds:
  • Contract performance — processing is necessary to provide the Service
  • Consent — for sending marketing communications (if applicable)
  • Legitimate interest — for security and fraud prevention
  • Legal obligation — for compliance with applicable law, including Russian Federal Law No. 152-FZ "On Personal Data"

8. Third-Party Disclosure

We do not sell your personal data. We may share data with:
  • Infrastructure providers — for hosting VPN servers
  • Payment processors — for payment processing (we do not store card data)
  • Law enforcement — only upon lawful request, however we cannot provide data about users' VPN activity as we do not keep logs

9. Data Storage and Security

We employ comprehensive measures to protect your data:
  • VPN connection via WireGuard, OpenVPN, and IKEv2 protocols
  • Servers operate exclusively in RAM-only mode
  • Perfect Forward Secrecy (PFS) support — key compromise does not reveal past sessions
  • Encryption in transit (TLS 1.3)
  • Regular security audits and penetration testing
Access to the User's personal information is provided through an authentication system with login and password. The User is obligated to independently ensure the security of their credentials and not disclose them to third parties. Any changes made using the User's credentials shall be deemed to have been made by the User personally.

Account personal data is retained for the duration of your use of the Service. Upon account deletion, all data is permanently deleted within 30 days.

10. Your Rights

Under applicable law (including GDPR and CCPA), you have the right to:
  • Access — request information about your personal data
  • Rectification — update or correct your data
  • Erasure — request deletion of your account and data
  • Portability — export your data in a machine-readable format
  • Restriction — restrict the processing of your data
  • Objection — object to certain types of processing
  • Withdraw consent — withdraw previously given consent
To exercise your rights, contact us using the details provided below.

11. Cookies

We use only essential cookies:
  • Session cookies — to maintain your authentication
  • Preference cookies — to save your language and theme settings
We do not use advertising or third-party tracking cookies.

12. Cross-Border Data Transfer

Your data may be processed on servers located outside your country of residence. In such cases, we ensure an adequate level of data protection in accordance with applicable law and use standard contractual clauses.

13. Children

The Service is not intended for persons under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us for its removal.

14. Policy Changes

We may update this Policy as needed. We will notify you of material changes by email or through a notification in the Service at least 30 days before the changes take effect.

15. Contacts

For questions related to personal data processing, you can contact us:
  • Email: privacy@vaultsecure.app
  • Through the feedback form in the Service