Skip to content
Draft for review by licensed counsel. Not for publication.This page contains 263 open points (highlighted) that must be resolved in the source documents before publication. Remove nothing by hand: resolve each point in the source draft and rebuild.

Privacy Policy

How HidzoVPN handles personal information, including cookies, account deletion, service providers and requests from authorities.

  • Delete your account
  • Your rights
  • How long we keep information
  • Cookies
  • Who we share information with
  • Contact
Contents
  1. Privacy Policy
  2. Summary
  3. 1. Who is responsible for your information
  4. 2. Our commitment for the VPN service
  5. 3. Information we process
  6. 4. Features that use information on your device
  7. 5. Why we use information
  8. 6. Legal bases (European Economic Area, United Kingdom, Switzerland)
  9. 7. Sale, sharing and targeted advertising
  10. 8. Cookies and similar technologies
  11. 9. Who we share information with
  12. 10. International transfers
  13. 11. How long we keep information
  14. 12. Deleting your account
  15. 13. Your choices
  16. 14. Your rights
  17. 15. Additional information for the European Economic Area, the United Kingdom and Switzerland
  18. 16. Additional information for U.S. residents
  19. 17. Security
  20. 18. Automated decisions
  21. 19. Children
  22. 20. Changes to this Policy
  23. 21. Contact
  24. Cookie Notice
  25. 1. What cookies are
  26. 2. The cookies we use
  27. 3. Your choices
  28. 4. Changes
  29. 5. Contact
  30. Account and Data Deletion
  31. 1. Your subscription
  32. 2. How to delete your account
  33. 3. Deleting data without deleting your account
  34. 4. If you use HidzoVPN without an account
  35. 5. What we delete and what we keep
  36. 6. After deletion
  37. 7. Questions
  38. Our Service Providers
  39. Law Enforcement Guidelines
  40. 1. How to send a request
  41. 2. Legal process we require
  42. 3. Records we keep in the ordinary course of business
  43. 4. Preservation requests
  44. 5. Emergencies
  45. 6. Notice to users
  46. 7. Transparency
  47. 8. Costs

Privacy Policy

Version: 2.2 [OPEN: renumber on publication] · Effective: [OPEN: date] · Last updated: [OPEN: date]

[COUNSEL: publish together with the change notice that corrects earlier references to "NebulaVPN Inc." and an address in Panama — DEC-2026-001 §7.1; RSK-047]

Summary#

  • Who we are: HidzoVPN, Inc., a Florida corporation, is responsible for your personal information when you use HidzoVPN.
  • Your VPN traffic: while the VPN is on, your internet traffic passes through our servers so that it can reach its destination. We do not record the websites you visit, the content of your traffic or your DNS queries [ENGINEERING: logging attestation, EV-201–EV-205; claims register entry required].
  • What we do keep: limited account, subscription, device and connection information needed to run the service, apply plan limits, prevent abuse and meet legal duties, for the periods in Section 11 [ENGINEERING].
  • Advertising: [OPEN — BRF-2026-001 D4: describe the advertising model chosen; see Section 2]
  • Your choices and rights: Sections 13 to 16.

This Privacy Policy explains how HidzoVPN, Inc. ("HidzoVPN", "we", "us" or "our") collects, uses, shares and protects personal information when you use our apps, websites, VPN service, accounts, billing and support (the "Services").

1. Who is responsible for your information#

HidzoVPN, Inc., a Florida profit corporation (Florida Department of State document number P25000060442), is the controller of the personal information described in this Policy. Mailing address: 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States. Contact details for each purpose are on our Legal Information page [OPEN: link]. Privacy requests: [OPEN: [email protected]].

Apple and Google (for app-store purchases and distribution) [COUNSEL: and our payment processor, for its own fraud-prevention and legal purposes; and, if applicable under Section 2, advertising providers] process some information under their own privacy notices, as independent businesses.

2. Our commitment for the VPN service#

[OPEN — BRF-2026-001 D4; COUNSEL — Apple Guideline 5.4 requires that apps offering VPN services "may not sell, use, or disclose to third parties any data for any purpose, and must commit to this in their privacy policy" (EV-106, Verified). Choose one alternative. If Alternative A is chosen, Sections 1, 3.5, 5, 7, 9, 13 and 16 must be conformed with an explicit platform split, and the Apple privacy label rebuilt.]

Alternative A — no third-party data disclosure in the iOS app: In our iOS app, we do not sell data to third parties, and we do not disclose data to third parties or allow third parties to use it for their own purposes. We disclose data only to service providers that process it on our instructions to provide the Services, and where the law requires us to do so. [COUNSEL: whether Apple, Google, the payment processor, Sign in with Apple/Google, resellers and a successor fit these exceptions; whether voluntary emergency disclosure and "with your permission" (Section 9) must be excluded for iOS]

Alternative B — iOS as in Alternative A; advertising in the Free Service on Android and the website: [COUNSEL and ENGINEERING: iOS text as in Alternative A. For Android and the website: name the advertising networks, the data they receive, the consent obtained, and the Google Play VpnService prominent-disclosure screen (G-5). Not drafted until D4 is decided.]

3. Information we process#

3.1 Account information#

If you create an account: your email address, an internal account identifier, your plan and subscription status, the devices linked to your account and your sign-in method [ENGINEERING: fields]. If you sign in with Apple or Google, we receive an identifier and the email address the provider shares (Apple may share a private relay address) [ENGINEERING: sign-in methods offered]. We do not receive your Apple or Google password. One-time sign-in codes expire after [ENGINEERING: 10 minutes] and are stored only in protected form [ENGINEERING].

3.2 Device and app information#

When you use the app, with or without an account: an installation or device identifier, device model, operating system and app version, language, time zone and the IP address used to contact our servers [ENGINEERING: fields]. In the Free Service, the installation identifier is used to apply session limits and waiting periods and to prevent abuse [ENGINEERING: EV-205].

3.3 VPN connection information#

To connect you, our systems process: your IP address at the time of connection, a session identifier, your account or installation identifier, the server and protocol selected, the internal tunnel address, connection status and errors, the number of simultaneous connections, connection start and end times and the amount of data transferred [ENGINEERING: confirm each field, where it is stored and for how long — EV-201, EV-205]. We use this information to establish and end connections, enforce device and plan limits, keep the network reliable and prevent abuse. Section 11 states how long it is kept.

We do not record the content of your VPN traffic, the websites or destinations you visit, or your DNS queries, and we do not keep a history that links those destinations to you. We do not use VPN traffic for advertising, analytics or profiling. [ENGINEERING: attestation required for both sentences; claims register entry required]

The IP address from which you connect is visible to our systems while the connection is set up. The providers that host our servers and the networks that carry traffic may process network information under their own legal obligations.

3.4 Purchase information#

For trials and subscriptions: plan, purchase channel, transaction identifiers, dates, price, currency, billing country, subscription and refund status and fraud signals. Apple and Google process payments for store purchases and send us confirmation of your entitlement. For website purchases, our payment processor [OPEN: Stripe entity] collects your payment details; we receive [ENGINEERING: e.g. a payment token, card type and last four digits, billing country and payment status]. [OPEN — BRF-2026-001 D7: cryptocurrency purchases — wallet address, transaction hash, asset and amount]

3.5 Advertising and measurement information#

[OPEN — depends on Section 2 and the SDK inventory (EV-206)] Where advertising is shown, the advertising provider may receive [ENGINEERING: list]. Measurement and analytics tools may receive app events such as installation, account creation, trial start and purchase [ENGINEERING: named tools and events]. We do not send VPN traffic, DNS queries, destinations, sign-in codes or payment details to these providers [ENGINEERING: EV-206].

3.6 Diagnostics and security information#

Crash reports, app performance data, API request records, sign-in attempts, rate-limit events and abuse reports, used to keep the Services working and secure [ENGINEERING: whether these records contain IP addresses — CLM-024].

3.7 Support and communications#

Messages and attachments you send us, and records of our replies. If you agree to receive marketing emails, your email address and your preference.

3.8 Website information#

IP address, browser and device type, pages viewed and cookie identifiers. See our Cookie Notice [OPEN: link — POL-COOK-001].

3.9 Information from other sources#

We receive information from: Apple and Google (sign-in, purchases and entitlements); our payment processor (payment status and fraud signals); [OPEN — D4: advertising and measurement providers]; [OPEN — POL-RTOS-001 §0: resellers, only the contact details needed to resolve a specific support or fraud case (POL-RPRIV-001 §2), if a reseller program is launched]; and people who report abuse, security vulnerabilities or legal issues to us.

3.10 What you must provide#

You must give us an email address or sign-in identifier to create an account, and payment information to buy on our website. Without them we cannot provide those parts of the Services. Using the Free Service without an account does not require them, but the app cannot connect without the device and connection information in Sections 3.2 and 3.3 [ENGINEERING: confirm].

4. Features that use information on your device#

FeatureWhat it usesWhere it stays
Split tunnelingThe list of apps installed on your device, to let you choose which apps use the VPN [ENGINEERING: platforms]On your device [ENGINEERING: confirm]
Trusted networks / auto-connectWi-Fi network namesOn your device [ENGINEERING: confirm]
Location / local network permission[ENGINEERING: whether requested, and why][ENGINEERING]
QR code scanningCamera, only when you choose to scan [ENGINEERING]The image is not stored or uploaded [ENGINEERING: confirm]
Paste / importClipboard, only when you tap Paste or Import [ENGINEERING]On your device [ENGINEERING: confirm]
Custom configurations (BYOC)Configuration files, keys and credentials you importOn your device, encrypted [ENGINEERING: confirm]
NotificationsA push tokenSent to Apple or Google to deliver notifications; [ENGINEERING: whether stored on our servers]
Weekly statisticsYour usage statistics[ENGINEERING: on device or on our servers — if on servers, reconcile with Section 11]

5. Why we use information#

To provide and secure the Services; to manage accounts, subscriptions and billing; to apply Free Service limits and device limits; to prevent fraud and abuse and enforce our Terms; to monitor the reliability and performance of our systems; to measure how the apps are used and how users find us, without using VPN traffic; [OPEN — D4: to show advertising as described in Sections 2 and 3.5]; to respond to requests; to send service messages and, with your agreement where required, marketing; and to meet legal obligations and defend legal claims.

6. Legal bases (European Economic Area, United Kingdom, Switzerland)#

Legal basisProcessing
Performance of a contractAccounts, VPN connections, Free Service limits, subscriptions, billing, support
Legitimate interestsSecurity, fraud and abuse prevention, reliability, limited diagnostics, product improvement, legal claims; complying with U.S. tax, sanctions and legal-process requirements that apply to us
ConsentNon-essential cookies; storage of or access to information on your device that is not strictly necessary; personalized advertising; marketing emails; optional diagnostic uploads [COUNSEL: legal basis for contextual advertising, if any — D4]
Legal obligationObligations under the law of the European Union, the United Kingdom or Switzerland that apply to us [COUNSEL]

You may withdraw consent at any time; this does not affect processing that took place before.

7. Sale, sharing and targeted advertising#

We do not sell personal information for money. We do not sell your VPN traffic, browsing destinations or DNS queries, and we do not keep records of them that could be disclosed [ENGINEERING: attestation]. [OPEN — depends on Section 2:] Under some U.S. state laws, giving advertising providers identifiers or app activity for targeted advertising may count as "selling", "sharing" or "targeted advertising" even if no money is paid. Where those laws apply to us, you can opt out as described in Section 16. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of the sale or sharing of your personal information and of targeted advertising for that browser or device and, if we know who you are, for your account [ENGINEERING: confirm] [COUNSEL: which state laws apply — EV-233].

8. Cookies and similar technologies#

See our Cookie Notice [OPEN: link] for our website. In our apps, [ENGINEERING: describe the storage of or access to information on your device that is not strictly necessary, the consent tool used (for example Google UMP or App Tracking Transparency), and how to change your choice].

9. Who we share information with#

  • Service providers that host our servers and systems, deliver email and notifications, provide customer support, process payments, measure app performance and help prevent fraud. We require them to protect the information to the same standard as this Policy and to use it only to provide their services to us [VERIFY: contract terms — POL-SUB-001]. The current list is in our List of Service Providers [OPEN: link — POL-SUB-001].
  • Apple and Google, for app-store purchases and distribution, and our payment processor for website purchases [COUNSEL: role].
  • Advertising and measurement providers [OPEN — Section 2].
  • Authorities, courts and parties to legal proceedings, when we are legally required to do so, or in an emergency involving danger of death or serious physical injury, as described in our Law Enforcement Guidelines [OPEN: link — POL-LE-001] [COUNSEL: whether to include voluntary emergency disclosure — Section 2]. We can only provide information we actually hold.
  • Resellers [OPEN — POL-RTOS-001 §0]: the contact details of a person who bought an Activation Code from that reseller, only where needed to resolve a specific support or fraud case; we do not tell resellers whether or by which account a code was activated [POL-RPRIV-001 §§2, 9; COUNSEL — Section 2].
  • A buyer or successor of our business, subject to this Policy.
  • Anyone else, with your permission [COUNSEL — Section 2].

10. International transfers#

We are based in the United States. Your information is processed in the United States and in the countries where our service providers and VPN servers are located [OPEN: list countries or refer to POL-SUB-001]. The European Commission has adopted an adequacy decision for the United States only for organizations certified under the EU-U.S. Data Privacy Framework; HidzoVPN [OPEN: is not] certified [VERIFY]. For transfers from the European Economic Area, the United Kingdom or Switzerland to countries without an adequacy decision, we use the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or other lawful safeguards [COUNSEL: confirm the mechanism for each provider, given that HidzoVPN, Inc. is itself subject to the GDPR under Art. 3(2)]. You can ask us for a copy of the relevant safeguards.

11. How long we keep information#

[ENGINEERING and FINANCE: each period must be implemented before publication — POL-RET-000]

InformationHow long
Account informationWhile your account exists; deleted within 30 days after we receive a deletion request, or after you confirm it if we ask you to [ENGINEERING]
Sign-in codesUntil they expire ([ENGINEERING: 10 minutes])
Sign-in sessions and tokensUntil you sign out or they expire, and no longer than [ENGINEERING: 30 days]
Free Service limit state (installation identifier and timing)[ENGINEERING]
Linked devicesWhile your account exists [ENGINEERING]
Live VPN session informationWhile the connection is active and up to [ENGINEERING: 15 minutes] after it ends
Usage statistics linked to an account or device[ENGINEERING: 24 hours], then deleted or de-identified
API, security and abuse recordsUp to [ENGINEERING: 30 days]; up to 24 months where needed for a specific incident, dispute or legal obligation
Blocked device and payment identifiers (fraud and abuse)Up to [ENGINEERING and COUNSEL: 24 months], or longer only for a documented incident or legal claim
Crash and diagnostic reportsUp to [ENGINEERING: 90 days]
Analytics and advertising measurementUp to [ENGINEERING: 13 months]
Push tokensUntil they become invalid, you disable notifications or you delete your account, then up to 30 days
Support messagesUp to 12 months after the request is closed, or until you delete your account, unless needed for an open matter
Marketing preferencesUntil you unsubscribe; we keep a minimal record so that we respect your choice
Purchase, tax and accounting recordsFor the period tax and accounting law requires [VERIFY and tax counsel: U.S. periods; EU VAT records may require up to 10 years]
Records of privacy requestsUp to 5 years [COUNSEL]
Information covered by a legal hold or open disputeUntil the hold or dispute ends
BackupsDeleted information is removed from backups within [ENGINEERING: 90 days]

"De-identified" means information that can no longer reasonably be linked to you; we do not try to re-identify it.

12. Deleting your account#

You can delete your account in the app or as described in our Account and Data Deletion Policy [OPEN: link — POL-DEL-001] [ENGINEERING: in-app and web deletion]. Deleting your account cancels the renewal of a subscription bought on our website, but not of a subscription billed by Apple or Google [ENGINEERING: automatic cancellation of the Stripe subscription]. After deletion, we keep some information for the periods in Section 11, for example tax records, fraud and security records, and information covered by a legal hold.

13. Your choices#

You can: update your account information; unsubscribe from marketing emails; change advertising and tracking choices in the app and in your device settings, including Apple's App Tracking Transparency [OPEN — D4]; change cookie choices on our website [ENGINEERING: consent management — BRF-2026-001 P2-2]; change device permissions in your device settings; and delete your account.

14. Your rights#

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, to opt out of the sale or sharing of personal information or targeted advertising, and not to be treated differently for exercising these rights.

To make a request, email [OPEN: [email protected]] from your account email and tell us which right you want to use. If you use the app without an account, include the installation identifier shown in [ENGINEERING: Settings → About]. We will verify your request in a way that is proportionate and will reply within the time the law requires. If we refuse your request, we will explain why. To appeal, email the same address with the subject "Privacy Appeal" within [OPEN: 60] days of our decision. Please do not send identity documents, passwords, sign-in codes or payment card numbers.

You can also complain to the data-protection authority where you live or work.

15. Additional information for the European Economic Area, the United Kingdom and Switzerland#

Right to object. You can object at any time to our use of your information based on legitimate interests, and to direct marketing. If you object to direct marketing, we will stop.

[COUNSEL — RSK-049; EV-231]

  • EU representative (GDPR Article 27): [OPEN: name and address. Assessment: the Art. 27(2)(a) exemption is unlikely to apply to continuous processing]
  • UK representative (UK GDPR Article 27): [OPEN]
  • Swiss representative: [COUNSEL: whether required]
  • Data Protection Officer: [COUNSEL: whether required]

16. Additional information for U.S. residents#

[COUNSEL: state which state laws apply to HidzoVPN — EV-233; do not state that a law applies if its thresholds are not met. If the CCPA applies, complete the table below under 11 CCR §7011(e).]

Category of personal informationExamplesSourcesPurposesCategories of recipientsSold or shared in the last 12 months?
IdentifiersEmail, account ID, installation ID, IP address [ENGINEERING]You; your device; Apple and GoogleSections 5, 9Service providers; app stores; [OPEN][OPEN — D4]
Customer and commercial recordsPlan, purchases, refundsYou; payment processor; app storesBilling, support, fraudService providers; payment processorNo [VERIFY]
Internet or network activityApp and website use, security records (not browsing destinations)Your deviceOperation, security, measurementService providers[OPEN — D4]
Approximate locationDerived from IP addressYour deviceLocalization, security, taxService providers[OPEN — D4]
Inferences[OPEN: only if used]————

We do not use or disclose sensitive personal information for purposes other than those the law permits [COUNSEL]. We do not knowingly sell or share the personal information of consumers under 16. To opt out of the sale or sharing of personal information or targeted advertising, use [OPEN: "Your Privacy Choices" link] or send a Global Privacy Control signal (Section 7). You may use an authorized agent to make a request; we may ask the agent for proof of authority and ask you to confirm the request. We will not discriminate against you for exercising your rights.

17. Security#

We use administrative, technical and physical measures to protect personal information [ENGINEERING: list only measures in place, e.g. encryption in transit, access controls, monitoring of our systems]. No method of transmitting or storing information is free of risk. If a security breach affects your personal information, we will notify you and the authorities where the law requires.

18. Automated decisions#

We use automated rules to authenticate sessions, apply plan and device limits, and detect suspicious sign-ins, payments and abuse [ENGINEERING: confirm]. These rules may temporarily block a request or account. You can ask for a person to review a decision by contacting us.

19. Children#

The Services are for people aged 18 and over [OPEN: align store age ratings — BRF-2026-001 P2-4]. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.

20. Changes to this Policy#

We will publish any update with its effective date. If a change is material, we will tell you in advance by email or in the app and, where the law requires, ask for your consent. Earlier versions are available on request [OPEN: or archive].

21. Contact#

HidzoVPN, Inc., 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States · Privacy: [OPEN: [email protected]] · Legal Information page: [OPEN: link]. This Policy is written in English; if a translation differs, the English version prevails unless the law of your place of residence requires otherwise.

Supplements the Privacy Policy

Cookie Notice

Last updated: [OPEN: date]

This notice explains how HidzoVPN, Inc. uses cookies and similar technologies on hidzovpn.com and its subdomains [OPEN: list other domains, e.g. help center]. Our apps are covered by our Privacy Policy.

1. What cookies are#

Cookies are small files that a website stores in your browser. Similar technologies, such as local storage and pixels, work in a similar way. We call them all "cookies" in this notice.

2. The cookies we use#

[ENGINEERING and MARKETING: complete from the GTM export and a production cookie scan (EV-212). One row per cookie. Remove any category that is not used. Cookie lifetimes must not exceed the periods in Privacy Policy §11.]

CategoryPurposeCookie nameProvider (and link to its privacy notice)DurationEuropean Economic AreaUnited Kingdom
Strictly necessarySecurity, checkout, remembering your cookie choices [ENGINEERING: and sign-in, if the website has sign-in][ ]HidzoVPN / [ ][ ]No consent neededNo consent needed
PreferencesRemembering your language[ ][ ][ ][COUNSEL][COUNSEL: PECR Sch. A1 para. 6]
AnalyticsUnderstanding how the website is used[ ][ ][ ]Consent[COUNSEL: opt-out under PECR Sch. A1 para. 5, or consent as a policy choice]
Advertising and measurementMeasuring our advertising campaigns[ ][ ][ ]ConsentConsent

Some cookies are set by other companies, which may use the information under their own privacy notices. For more about who receives information and international transfers, see Sections 9 and 10 of our Privacy Policy.

3. Your choices#

  • Cookie settings: you can accept or reject non-essential cookies, and change your choice at any time, using [ENGINEERING: "Cookie settings" link in the website footer]. [ENGINEERING: the first layer offers Accept and Reject with equal prominence]
  • Your Privacy Choices: [OPEN: link] — applies where U.S. state law gives you a right to opt out of the sale or sharing of personal information or of targeted advertising [COUNSEL: which state laws apply].
  • Global Privacy Control: if your browser sends a Global Privacy Control signal, we treat it as a request to opt out of the sale or sharing of your personal information and of targeted advertising for that browser or device and, if we know who you are, for your account, and we show on the website that your signal has been honored [ENGINEERING: confirm; status display] [COUNSEL: which state laws apply — EV-233].
  • Browser settings: you can also block or delete cookies in your browser. If you block strictly necessary cookies, parts of the website, such as checkout, may not work.

4. Changes#

We update this notice when we add or change a category of cookies. The "Last updated" date at the top shows the latest change. If we add cookies that need consent, we will ask for your consent again.

5. Contact#

[OPEN: [email protected]] · See also our Privacy Policy. This notice is written in English; if a translation differs, the English version prevails unless the law of your place of residence requires otherwise.

Supplements the Privacy Policy

Account and Data Deletion

Version: 1.0 [OPEN] · Effective: [OPEN: date]

This notice explains how to delete your account in the HidzoVPN app and your personal information. It is issued by HidzoVPN, Inc., a Florida corporation, and supplements our Privacy Policy. [OPEN: the app and developer name shown here must match the Google Play listing — Google Play Help 13327111]

1. Your subscription#

  • If you bought Premium on our website, deleting your account also cancels its renewal, and you will not be charged again [ENGINEERING: automatic cancellation of the Stripe subscription when the account is deleted]. Deletion does not by itself give a refund for the current period; see our Refund and Cancellation Policy.
  • If you pay through Apple or Google, deleting your account does not cancel your subscription. Cancel it first in your Apple or Google account, as explained in our Refund and Cancellation Policy; otherwise Apple or Google will continue to charge you. [ENGINEERING: the in-app deletion flow shows this warning and a link to the store's subscription page]

2. How to delete your account#

WhereHow
In the app[ENGINEERING: Settings → Account → Delete account]
On the web (you do not need the app)[ENGINEERING: https://hidzovpn.com/delete-account] — sign in with a one-time code sent to your account email and confirm
By emailEmail [OPEN: [email protected]] from your account email with the subject "Delete Account"

We may ask you to confirm the request from your account email, or while signed in to the app, before we delete anything. We will email you when the deletion is complete. [ENGINEERING: revoke Sign in with Apple tokens and disconnect Google sign-in on deletion]

3. Deleting data without deleting your account#

You can ask us to delete particular information, such as support conversations or diagnostic reports, without closing your account. Email [OPEN: [email protected]] and tell us what you want deleted. [ENGINEERING: confirm which categories can be deleted separately]

4. If you use HidzoVPN without an account#

Information linked to your installation is removed from our active systems [ENGINEERING: when — e.g. after X days of inactivity or when you delete the app and the installation identifier expires]. You can also ask us to delete it by emailing [OPEN: [email protected]] with the installation identifier shown in [ENGINEERING: Settings → About]. We may ask you to confirm the request from the app on that device [ENGINEERING].

5. What we delete and what we keep#

InformationWhat happens
Account information (email, account identifier, linked devices, settings)Deleted from our active systems within 30 days after we receive your request, or after you confirm it if we ask you to [ENGINEERING]
Connection informationDeleted on the schedule in Section 11 of our Privacy Policy; any that still exists when you delete your account is deleted within [ENGINEERING]
Support messagesDeleted when you delete your account, unless needed for an open refund, dispute or legal matter
Analytics and advertising measurement linked to your account or deviceDeleted or de-identified in our systems; we send deletion requests to our service providers [ENGINEERING: list]
Purchase, refund, tax and accounting recordsKept for the period tax and accounting law requires [VERIFY and tax counsel: U.S. and Florida periods; EU VAT records for digital services may require up to 10 years]
Records needed to prevent fraud or abuse, including device and payment identifiers blocked under our Acceptable Use PolicyKept for up to 24 months, or longer only for a documented incident or legal claim [ENGINEERING and COUNSEL]
Information covered by a legal hold, a preservation request or an open disputeKept until the hold or dispute ends, then deleted
A record of your deletion requestKept up to 5 years to show that we handled it [COUNSEL]
BackupsDeleted information is removed when backups expire, within [ENGINEERING: 90 days]

Information held by Apple and Google [COUNSEL: and our payment processor, for its own purposes — POL-SUB-001 A.1] [OPEN — BRF-2026-001 D4: and advertising providers in the Free Service], acting as independent businesses, is not deleted by us. You can contact them directly.

6. After deletion#

Deletion cannot be undone. You will lose your linked devices and settings. If you still have an Apple or Google subscription, it continues until you cancel it with them [ENGINEERING: whether it can be restored to a new account]. You can create a new account later, unless we closed your account under our Acceptable Use Policy.

7. Questions#

Email [OPEN: [email protected]]. See our Privacy Policy for your other rights.

Supplements the Privacy Policy

Our Service Providers

Last updated: [OPEN: date]

The service providers below process personal data on behalf of HidzoVPN, Inc. to provide the Services [VERIFY: a signed data processing agreement, or accepted online terms, in the name of HidzoVPN, Inc. for each row — RSK-036]. Some of them, such as hosting providers, also process limited information for their own legal and security obligations. For how we protect international transfers, see Section 10 of our Privacy Policy.

[PROCUREMENT and CTO: complete one row per confirmed provider. Do not list a provider until the confirmation in Part C.2 is complete. A provider in use may not be omitted.]

Provider (legal entity)What they do for usPersonal data involvedWhere data is processedTransfer safeguard
[e.g. DigitalOcean — VERIFY entity]Hosting of servers and systems [VERIFY]Network traffic passing through servers they host, including IP addresses [ENGINEERING: whether any connection records are stored on provider systems][COUNSEL: country only, or city — law-enforcement exposure (RSK-030)][EU (no transfer) / Data Privacy Framework / Standard Contractual Clauses / UK Addendum / Swiss FADP]
[e.g. Hetzner Online GmbH — VERIFY]Hosting [VERIFY][ ][ ][ ]
[OneProvider — VERIFY entity]Dedicated servers [VERIFY][ ][ ][ ]
[Clouvider — VERIFY entity]Hosting / network [VERIFY][ ][ ][ ]
[DNS resolution — ENGINEERING: own resolver or third party (EV-202)]Resolving domain names[ENGINEERING: DNS queries — must be consistent with Privacy Policy §3.3][ ][ ]
[Stripe entity — COUNSEL: role]Website payment processingPayment details, email, billing country[ ][ ]
[Email / one-time code provider]Sending sign-in codes and service emailsEmail address[ ][ ]
[Crash reporting / analytics provider]App stability and usage measurementDevice and app data[ ][ ]
[Consent management provider]Recording cookie choicesConsent records, device identifiers[ ][ ]
[Customer support tool]Handling support requestsMessages, email address[ ][ ]
[OPEN — D7: cryptocurrency payment processor][ ][ ][ ][ ]

Changes to this list. We update this list when we add or replace a service provider [OPEN: advance notice period, if any].

For courts, authorities and parties to legal proceedings

Law Enforcement Guidelines

Version: 1.0 [OPEN] · Effective: [OPEN: date]

These guidelines are for courts, government agencies, law-enforcement authorities and parties to legal proceedings who want to request information from HidzoVPN, Inc., a Florida corporation. They are not legal advice and do not create rights for any person. Users can read our Privacy Policy for how we handle their information.

1. How to send a request#

Send requests by email to [OPEN: [email protected]]. Formal service of legal process on HidzoVPN, Inc. in Florida may be made on our registered agent, Northwest Registered Agent LLC, 7901 4th Street North, Suite 300, Saint Petersburg, FL 33702, United States [COUNSEL: after Northwest confirms its appointment — RSK-050]. Requests must be addressed to HidzoVPN, Inc.; we do not process requests sent to individual employees, officers or contractors. Requests sent to customer support or through social media are not handled as legal requests and will be delayed.

Each request must state: the requesting authority or party and the person making the request, with official contact details; the legal basis for the request; the account email, installation identifier or other identifier concerned; the information sought; the relevant time period; and any deadline.

We verify every request, including by contacting the requesting agency through its publicly listed contact details, and may refuse a request we cannot verify.

2. Legal process we require#

2.1 United States authorities. Except in the emergencies described in Section 5, or where the law requires us to report, we disclose user information to U.S. authorities only in response to valid legal process [COUNSEL: HidzoVPN's status as a provider of electronic communication service to the public]:

InformationProcess generally required
Basic subscriber records listed in 18 U.S.C. §2703(c)(2) (e.g. name, address, session times and durations, temporarily assigned network address, means of payment)Subpoena
Other non-content recordsCourt order under 18 U.S.C. §2703(d), or a search warrant
Content of communicationsSearch warrant (our policy; the statute also allows other process in some cases — 18 U.S.C. §2703(b)) [COUNSEL]

As a Florida business, we produce records in response to a subpoena, court order or warrant issued by another U.S. state as if a Florida court had issued it, as Florida law requires (Fla. Stat. §92.605(3)) [COUNSEL: whether HidzoVPN provides electronic communication service to the public].

2.2 Authorities outside the United States. As a matter of company policy, we respond to authorities outside the United States only through a mutual legal assistance request or another procedure that U.S. law recognizes [COUNSEL: CLOUD Act executive agreements; EU European Production Orders under Regulation (EU) 2023/1543 — whether HidzoVPN is a covered provider (EV-237, Level D)].

2.3 Civil and private requests. We do not disclose the content of communications to private parties. We disclose other user information to private parties only in response to a subpoena or court order that is valid under applicable law, after notifying the user where we can and allowing [OPEN] days to object [COUNSEL: including subpoenas under 17 U.S.C. §512(h)].

2.4 We review every request for its legal validity and scope. We may reject, narrow or challenge a request that is invalid, overbroad or lacks jurisdiction.

3. Records we keep in the ordinary course of business#

We can only provide records that exist when we receive a valid request. The table below describes the records we keep in the ordinary course of business as of [OPEN: date], and how long we keep them (see Section 11 of our Privacy Policy). [ENGINEERING and COUNSEL: every row must match the logging attestation (EV-201–205) and the Privacy Policy exactly] [COUNSEL: wording on orders that require future collection]

CategoryDo we keep it in the ordinary course of business?How long
Content of a user's internet traffic[ENGINEERING: No — attestation EV-201; claims register approval]—
Websites or destinations visited, and DNS queries, through the VPN[ENGINEERING: No — EV-201, EV-202]—
IP address from which a user connects to a VPN server; server, tunnel address, start and end times, data volume (live session information)[ENGINEERING]Up to [ENGINEERING: 15 minutes] after the connection ends
Usage statistics linked to an account or device[ENGINEERING][ENGINEERING: 24 hours]
Sign-in sessions and tokens[ENGINEERING]No longer than [ENGINEERING: 30 days]
Free Service limit state (installation identifier and timing)[ENGINEERING][ENGINEERING]
Marketing preferences[ENGINEERING]Until the user unsubscribes; a minimal suppression record is kept
IP address used to reach our apps, website and account systems (API, security and abuse records)[ENGINEERING]Up to [ENGINEERING: 30 days]; up to 24 months where needed for a specific incident, dispute or legal obligation
Account email, sign-in method, Apple or Google identifier, linked devicesYes, for users with an account [ENGINEERING]While the account exists
Installation or device identifier, device model and operating system[ENGINEERING][ENGINEERING]
Blocked device and payment identifiers (fraud and abuse)[ENGINEERING]Up to [ENGINEERING and COUNSEL: 24 months], or longer only for a documented incident or legal claim
Subscription and payment records (plan, dates, amounts, payment token and last four digits of a card)[ENGINEERING: Yes, for website purchases; limited records for Apple and Google purchases — PP §3.4]For the period tax and accounting law requires [VERIFY and tax counsel]
Cryptocurrency wallet address and transaction hash[OPEN — BRF-2026-001 D7][OPEN]
Crash and diagnostic reports[ENGINEERING]Up to [ENGINEERING: 90 days]
Analytics and measurement data[ENGINEERING]Up to [ENGINEERING: 13 months]
Support messages[ENGINEERING: Yes]Up to 12 months after the request is closed, or until the account is deleted, unless needed for an open matter
Push token[ENGINEERING]Until it becomes invalid, notifications are disabled or the account is deleted, then up to 30 days
Records of privacy requests[ENGINEERING: Yes]Up to 5 years [COUNSEL]
Backups[ENGINEERING]Up to [ENGINEERING: 90 days]

4. Preservation requests#

On a valid preservation request from a U.S. authority, we preserve records that exist when we receive the request for 90 days, extended by a further 90 days on a renewed request, pending receipt of legal process (18 U.S.C. §2703(f)). A preservation request does not by itself lead to disclosure. We do not start recording activity that we do not normally record because of a preservation request.

5. Emergencies#

If you believe in good faith that an emergency involving danger of death or serious physical injury to any person requires disclosure without delay, send an emergency request to [OPEN: [email protected]] with the subject "EMERGENCY". Describe the specific danger and explain why the information is needed without delay. We review emergency requests promptly and may disclose information voluntarily where the law permits (18 U.S.C. §2702(b)(8), (c)(4)) [COUNSEL].

6. Notice to users#

Where we have contact details for the user and the law allows it, we will notify the user before disclosing their information. We may delay notice in an emergency, where a court order prohibits it (for example under 18 U.S.C. §2705(b)), or where notice would create a risk of harm, and we will then notify the user once that reason no longer applies [COUNSEL].

7. Transparency#

[OPEN: include only when the first transparency report is approved; no warrant canary without counsel's advice]

8. Costs#

We may seek reimbursement of reasonable costs where the law permits (18 U.S.C. §2706) [VERIFY: §2706 not re-read first-hand — EV-237].

HidzoVPN, Inc. · Other legal pages: Terms of Service · Legal information · Delete your HidzoVPN account · Reseller Terms of Service · Reseller Privacy Policy
Built from: POL-PRIV-002 v2.3, POL-COOK-001 v0.3, POL-DEL-001 v0.3, POL-SUB-001 v0.3, POL-LE-001 v0.3