Privacy policy
// last updated 26 July 2026
This policy explains what VPNmine collects, why, how long it is kept and what you can do about it. It covers every place VPNmine runs: the Windows and macOS apps, the Android and iOS apps, the Android TV and Apple TV apps, the browser extensions for Chrome, Edge, Opera and Firefox, the VPN service itself, and this website.
We do not log, monitor, store or sell the traffic you send through the VPN. The rest of this page is the detail behind that sentence.
Who is responsible
VPNmine is the data controller for the processing described here. Registered address: [registered company address, to be completed before launch]. Privacy questions and data rights requests go to support@vpnmine.com. General support goes to support@vpnmine.com. Representative for UK/EU data subjects where one is required: [EU/UK representative, if required, to be completed before launch].
What we collect, why, and for how long
- Account data. Your email address, and optionally a display name, when you create an account or sign in with Google or Apple. Passwords are stored only as salted hashes. Purpose: to create and secure your account. Legal basis: performance of a contract. Kept until you delete your account.
- Device data. A randomly generated device identifier, platform, operating system version and app version or build. Purpose: to deliver the right configuration, to keep sessions attached to the right device, and to prevent abuse of a free service. Legal basis: legitimate interests. Kept for up to 12 months after the device last connects.
- Connection metadata. Which server a session used, when it started and when it ended, and the volume of data transferred. Purpose: capacity planning and handling abuse reports. This is not a record of the sites you visited. Legal basis: legitimate interests. Kept for up to 30 days.
- Diagnostics. Coarse events such as app opened, connection started or connection failed, with the platform and country they came from. Purpose: to find and fix faults. Legal basis: legitimate interests. Kept in aggregate form.
- Support correspondence. Whatever you send us when you ask for help. Legal basis: legitimate interests. Kept for up to 24 months.
- Website analytics. This website, not the apps, uses Vercel Web Analytics to count page views. It sets no cookies and builds no persistent visitor identifier, so we can see that a page was viewed but not who viewed it or where they went next.
- Purchases. If a paid tier launches and you buy it, Google Play or the App Store processes the payment and tells us that a valid subscription exists. We receive a purchase token or transaction identifier and its status. We never receive your card number or billing address.
What we never collect
- The websites, apps or services you reach through the tunnel.
- DNS queries made through the tunnel.
- The contents of your traffic, in any form, at any point.
- Deep packet inspection or bandwidth content analysis of any kind.
- Your originating IP address paired with your browsing activity.
Our servers are configured so that this data is not written to disk. There is no logging pipeline for it to enter, which means there is nothing for us to hand over, sell, or lose in a breach.
The VPN tunnel
VPNmine runs OpenVPN with AES encryption on the desktop, mobile and TV clients. Traffic passes through servers VPNminerents and configures. We do not resell your bandwidth, route your traffic through other users' devices, or share the tunnel with third-party networks.
A VPN hides your traffic from your network and your internet provider. It does not make you anonymous to the services you sign in to, and it does not remove your obligations under the law where you are.
The browser extensions
The Chrome, Edge, Opera and Firefox extensions proxy browser traffic through the same network. They do not read page content, do not inject scripts into the pages you visit, and do not collect your browsing history. They request only the permissions needed to set a proxy and to show connection status.
Our use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Extension data is never sold, never used for advertising, and never transferred except as described in this policy.
Advertising
VPNmine is currently ad free and no advertising SDK runs in the apps. If ads are ever enabled, our ad partners may process an advertising identifier to select and measure ads. Before any of that happens you will be asked for consent, through the standard consent prompt in the EEA and the UK, and through App Tracking Transparency on Apple platforms. Declining leaves the app fully usable. We will update this policy before ads are switched on, not after.
Who we share data with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share only what a processor needs in order to run the service:
- Hosting and server providers that run the panel, the API and the VPN endpoints.
- Google Play and the App Store, for purchases and subscription status.
- Vercel, for this website and its page-view counts.
- Ad networks, only if and when ads are enabled and you have consented.
- Law enforcement, only where a valid and binding legal order compels us, and only from what we actually hold. We cannot produce browsing records because we do not keep any.
International transfers
The service runs in several countries, so your account and connection metadata may be processed outside the country you live in. Where data leaves the UK or the EEA we rely on the European Commission's standard contractual clauses or an equivalent safeguard.
Deleting your account
You can delete your account and its associated data at any time. Open Settings in any VPNmine app and choose Delete account, or use the account deletion page on the web. Deletion is immediate rather than queued for review. It removes your account record, your devices, your sessions and your tokens. Anonymous aggregate counts that cannot be traced back to you may remain, and we may keep the minimum required to meet a legal or tax obligation.
Your rights
Depending on where you live you may have the right to access the data we hold about you, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent you previously gave. If you are in California you also have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we will not treat you differently for exercising any of these rights.
Write to support@vpnmine.com and we will respond within the time the applicable law allows. If you are unhappy with our answer you can complain to your local data protection authority.
Security
Passwords are salted and hashed. Traffic between the apps and our API is encrypted in transit. Access to production systems is limited to the people who need it and is logged. No system is perfect, so if we ever suffer a breach that puts you at risk we will tell you and the relevant regulator within the deadlines the law sets.
Children
VPNmine is not directed to children. We do not knowingly collect data from anyone under 13, or under 16 in the EEA and the UK. If you believe a child has given us data, write to support@vpnmine.com and we will delete it.
Automated decisions
We do not make decisions about you by automated means that produce legal or similarly significant effects. Automated abuse controls may rate limit or temporarily block a device, and you can ask a person to review that.
Changes to this policy
We may update this policy. The date at the top always reflects the current version, and material changes are announced in the app before they take effect.