Data Collection Policy
Last Updated: 2025-10-27
Our NO-LOG Promise
Codex VPN is a privacy-first service. We collect the MINIMUM data necessary to operate.
🔒 NO IP address logging
🔒 NO browsing history
🔒 NO connection timestamps
🔒 NO traffic monitoring
If you value your privacy, you're in the right place.
Data We Collect (Very Little!)
To provide our service, we collect:
✅ Device Identifier:
• Anonymous ID (not linked to your identity)
• Used only for multi-device management
• Deleted after 5 minutes of inactivity
✅ Subscription Information:
• Subscription status (active/inactive)
• Expiry date
• Payment method type (e.g., "Google Play")
• We do NOT see your credit card or personal details
✅ Technical Data:
• App version (to ensure compatibility)
• OS version (Android)
• Crash reports (anonymous, can be disabled)
✅ Aggregate Metrics:
• Total number of active connections
• Server load statistics
• NO individual user tracking
Data We DON'T Collect (Most Important!)
Codex VPN will NEVER collect:
❌ Your real IP address
❌ Websites you visit
❌ DNS queries (what domains you look up)
❌ Connection timestamps (when you connect/disconnect)
❌ Bandwidth usage per session
❌ Traffic content (what you send/receive)
❌ Downloaded files
❌ Location information
❌ Individual user activity
We can't hand over data we don't have!
How We Use Your Data
The minimal data we collect is used ONLY for:
• Service Operation: Keeping the VPN running smoothly
• Device Management: Enforcing device limits (1 for free, 5 for premium)
• Subscription Management: Tracking your premium status
• Bug Fixes: Anonymous crash reports help us improve the app
• Abuse Prevention: Detecting and blocking malicious activity
Your data is NEVER:
❌ Sold to advertisers
❌ Shared with data brokers
❌ Used for profiling
❌ Given to governments (except minimal account data if legally required)
Data Retention (How Long We Keep It)
We keep data for the SHORTEST time possible:
• Connection Sessions:
→ Stored in RAM only
→ Deleted immediately on disconnect
→ NEVER written to disk
• Device IDs:
→ Kept for 5 minutes after disconnect (grace period)
→ Automatically deleted after inactivity
• Server Logs:
→ Kept for 7 days for debugging
→ NO IP addresses or user activities logged
→ Only error messages and system events
• Account Data:
→ Kept while your subscription is active
→ Deleted within 24 hours after account deletion
• Payment Records:
→ Kept for 7 years (tax law requirement)
→ Stored by Google Play, not by us
Data Sharing (With Whom?)
We share data with these parties ONLY:
📱 Google Play Services:
• Purpose: App distribution and in-app purchases
• Data shared: Subscription status, payment transactions
• Your credit card details: NEVER seen by us
• Privacy policy: https://policies.google.com/privacy
📊 Google AdMob (Free users only):
• Purpose: Showing ads to support free service
• Data shared: Ad preferences (managed by Google)
• You can opt-out: Android Settings → Ads → Disable personalization
• Privacy policy: https://support.google.com/admob/answer/6128543
🏢 Infrastructure Providers:
• Server hosting companies
• They have NO access to user data (encrypted)
• Strict confidentiality agreements in place
⚖️ Legal Requests:
• ONLY if legally required by court order
• We can ONLY provide: subscription status, account email
• We CANNOT provide: browsing history, IP logs (we don't have them!)
Your Data Rights
You have complete control over your data:
🔍 Right to Access:
• Request a copy of your data (there's not much!)
• Email us: [email protected]
🗑️ Right to Deletion:
• Delete your account anytime
• App → Settings → Account → Delete Account
• All data removed within 24 hours
📤 Right to Data Portability:
• Download your data in a readable format
• We'll provide: subscription history, account info
🚫 Right to Object:
• Opt-out of crash reports
• App → Settings → Privacy → Disable Crash Reports
✏️ Right to Rectification:
• Correct inaccurate account information
• Contact: [email protected]
Security Measures
We protect your data with:
🔐 Encryption:
• TLS 1.3 for all API connections
• AES-256-GCM for VPN tunnel
• QUIC protocol for enhanced security
💾 Storage:
• Session data stored in RAM only (not on disk)
• Automatic deletion on disconnect
• No persistent logs with user data
🔒 Access Control:
• Limited personnel access
• Two-factor authentication required
• Regular security audits
🛡️ Infrastructure:
• Secure data centers
• DDoS protection
• Regular vulnerability scanning
Transparency & Accountability
We believe in transparency:
📊 Transparency Report:
• We will publish an annual report
• Shows: number of legal requests, data breaches (if any)
• Available at: https://Codexvpn.com/transparency
🔔 Breach Notification:
• If a data breach occurs, we'll notify you within 72 hours
• Details: what data was affected, what we're doing about it
📧 Contact Us:
• Questions about data collection?
• Email: [email protected]
• We respond within 48 hours
Updates to This Policy
"This policy may be updated occasionally:
• You'll see a notification in the app
• "Last Updated" date will change
• Major changes require your consent
Last updated: 2025-10-27
By using Codex VPN, you agree to this data collection policy."