Privacy Policy

Updated: July 17, 2026

We built VPN Ninja to know as little about you as possible: no accounts, no activity logs, and a single anonymous device identifier. This policy describes in detail what data we process, why, who we share it with, and what rights you have.

Data controller

The controller of your data is ONLYAPPS d.o.o. — the developer of the VPN Ninja app and the operator of the vpn-ninja.app website. You can contact us about privacy matters via the support form on this site.

What data we process

We have deliberately reduced processing to a minimum:

  • an anonymous device identifier (UUID) generated on first launch — needed to link your subscription and support requests;
  • subscription status (active/inactive, plan type) received from Apple and RevenueCat — without your payment details;
  • the contents of support requests: email, message text, and the device identifier if you attach it yourself;
  • short-lived technical logs of our API servers (response codes, request timing) — for stability and abuse protection.

No registration or account is required; we never ask for your name, phone number, or address.

What we do not collect

We do not store or record:

  • browsing history or DNS queries;
  • the contents of your traffic;
  • your real IP address after a session ends;
  • behavioral profiles or advertising identifiers.

The app contains no ad SDKs and no third-party analytics. We do not sell user data and never have.

How a VPN session works

During an active session, the VPN server technically sees your IP address and the traffic passing through — routing is impossible without that. This data is processed transiently in the server’s memory, is not written to disk, and is not linked to your identifier. Once the session ends, we retain no record of who connected or where.

Purposes and legal bases

We process data on the following bases (for EEA users, in GDPR terms):

  • performance of a contract: operating the service, verifying subscription status, responding to requests;
  • legitimate interest: infrastructure stability, protection against abuse and attacks;
  • consent: when you contact us and provide contact details yourself.

Who we share data with

We use a limited set of processors:

  • Apple — payment and subscription processing under its own policy;
  • RevenueCat — subscription status validation: receives the anonymous identifier and App Store receipt data;
  • hosting providers — running our VPN and API servers.

We do not sell data and do not share it with ad networks. Government requests are honored only when legally binding — and there is no activity history in our possession that could be handed over.

International transfers

Our servers are located in different countries — that is the essence of a VPN service. Where transferring personal data outside your jurisdiction requires legal safeguards, we rely on recognized mechanisms, including Standard Contractual Clauses (SCC).

Retention

The device identifier and subscription status are kept while the app profile is installed or the subscription is active. Support correspondence is kept for up to 24 months after a request is closed. Short-lived technical logs are automatically deleted within a short period.

Data deletion

The “Remove data” button on the app’s settings screen permanently erases the local profile and device identifier — after that, no data can be linked to you. You can also request deletion via the support form.

Your rights

Regarding your data, you have the right to:

  • request access to it and obtain a copy;
  • correct inaccurate data;
  • delete data (the “right to be forgotten”);
  • restrict or object to processing;
  • receive data in a portable format;
  • withdraw consent at any time;
  • lodge a complaint with your country’s data protection authority.

To exercise these rights, write to us via the support form — we respond within 30 days.

Security

Traffic is encrypted with modern protocols (VLESS, Trojan over TLS). We practice data minimization, restrict access to our infrastructure, and keep server software up to date. No service can guarantee absolute security, but a leak of data we do not store is impossible by design.

Children

The service is not intended for anyone below the app’s age rating in the App Store. We do not knowingly collect children’s data; if you believe a child has provided us with data, contact us and we will delete it.

Cookies and the website

The vpn-ninja.app website uses no cookies, third-party trackers, or analytics scripts. The only data the site can process is what you submit yourself through the support form.

Changes to this policy

For significant changes, we will notify you in the app before they take effect. The current version is always available on this page; the date of the latest update is shown at the top.