Data Collection Policy

Last Updated: 2025-10-27

Our NO-LOG Promise

Codex VPN is a privacy-first service. We collect the MINIMUM data necessary to operate.

🔒 NO IP address logging

🔒 NO browsing history

🔒 NO connection timestamps

🔒 NO traffic monitoring

If you value your privacy, you're in the right place.

Data We Collect (Very Little!)

To provide our service, we collect:

✅ Device Identifier:

• Anonymous ID (not linked to your identity)

• Used only for multi-device management

• Deleted after 5 minutes of inactivity

✅ Subscription Information:

• Subscription status (active/inactive)

• Expiry date

• Payment method type (e.g., "Google Play")

• We do NOT see your credit card or personal details

✅ Technical Data:

• App version (to ensure compatibility)

• OS version (Android)

• Crash reports (anonymous, can be disabled)

✅ Aggregate Metrics:

• Total number of active connections

• Server load statistics

• NO individual user tracking

Data We DON'T Collect (Most Important!)

Codex VPN will NEVER collect:

❌ Your real IP address

❌ Websites you visit

❌ DNS queries (what domains you look up)

❌ Connection timestamps (when you connect/disconnect)

❌ Bandwidth usage per session

❌ Traffic content (what you send/receive)

❌ Downloaded files

❌ Location information

❌ Individual user activity

We can't hand over data we don't have!

How We Use Your Data

The minimal data we collect is used ONLY for:

• Service Operation: Keeping the VPN running smoothly

• Device Management: Enforcing device limits (1 for free, 5 for premium)

• Subscription Management: Tracking your premium status

• Bug Fixes: Anonymous crash reports help us improve the app

• Abuse Prevention: Detecting and blocking malicious activity

Your data is NEVER:

❌ Sold to advertisers

❌ Shared with data brokers

❌ Used for profiling

❌ Given to governments (except minimal account data if legally required)

Data Retention (How Long We Keep It)

We keep data for the SHORTEST time possible:

• Connection Sessions:

→ Stored in RAM only

→ Deleted immediately on disconnect

→ NEVER written to disk

• Device IDs:

→ Kept for 5 minutes after disconnect (grace period)

→ Automatically deleted after inactivity

• Server Logs:

→ Kept for 7 days for debugging

→ NO IP addresses or user activities logged

→ Only error messages and system events

• Account Data:

→ Kept while your subscription is active

→ Deleted within 24 hours after account deletion

• Payment Records:

→ Kept for 7 years (tax law requirement)

→ Stored by Google Play, not by us

Data Sharing (With Whom?)

We share data with these parties ONLY:

📱 Google Play Services:

• Purpose: App distribution and in-app purchases

• Data shared: Subscription status, payment transactions

• Your credit card details: NEVER seen by us

• Privacy policy: https://policies.google.com/privacy

📊 Google AdMob (Free users only):

• Purpose: Showing ads to support free service

• Data shared: Ad preferences (managed by Google)

• You can opt-out: Android Settings → Ads → Disable personalization

• Privacy policy: https://support.google.com/admob/answer/6128543

🏢 Infrastructure Providers:

• Server hosting companies

• They have NO access to user data (encrypted)

• Strict confidentiality agreements in place

⚖️ Legal Requests:

• ONLY if legally required by court order

• We can ONLY provide: subscription status, account email

• We CANNOT provide: browsing history, IP logs (we don't have them!)

Your Data Rights

You have complete control over your data:

🔍 Right to Access:

• Request a copy of your data (there's not much!)

• Email us: [email protected]

🗑️ Right to Deletion:

• Delete your account anytime

• App → Settings → Account → Delete Account

• All data removed within 24 hours

📤 Right to Data Portability:

• Download your data in a readable format

• We'll provide: subscription history, account info

🚫 Right to Object:

• Opt-out of crash reports

• App → Settings → Privacy → Disable Crash Reports

✏️ Right to Rectification:

• Correct inaccurate account information

• Contact: [email protected]

Security Measures

We protect your data with:

🔐 Encryption:

• TLS 1.3 for all API connections

• AES-256-GCM for VPN tunnel

• QUIC protocol for enhanced security

💾 Storage:

• Session data stored in RAM only (not on disk)

• Automatic deletion on disconnect

• No persistent logs with user data

🔒 Access Control:

• Limited personnel access

• Two-factor authentication required

• Regular security audits

🛡️ Infrastructure:

• Secure data centers

• DDoS protection

• Regular vulnerability scanning

Transparency & Accountability

We believe in transparency:

📊 Transparency Report:

• We will publish an annual report

• Shows: number of legal requests, data breaches (if any)

• Available at: https://Codexvpn.com/transparency

🔔 Breach Notification:

• If a data breach occurs, we'll notify you within 72 hours

• Details: what data was affected, what we're doing about it

📧 Contact Us:

• Questions about data collection?

• Email: [email protected]

• We respond within 48 hours

Updates to This Policy

"This policy may be updated occasionally:

• You'll see a notification in the app

• "Last Updated" date will change

• Major changes require your consent

Last updated: 2025-10-27

By using Codex VPN, you agree to this data collection policy."