Privacy Policy
Updated: July 17, 2026
We built VPN Ninja to know as little about you as possible: no accounts, no activity logs, and a single anonymous device identifier. This policy describes in detail what data we process, why, who we share it with, and what rights you have.
Data controller
The controller of your data is ONLYAPPS d.o.o. — the developer of the VPN Ninja app and the operator of the vpn-ninja.app website. You can contact us about privacy matters via the support form on this site.
What data we process
We have deliberately reduced processing to a minimum:
- an anonymous device identifier (UUID) generated on first launch — needed to link your subscription and support requests;
- subscription status (active/inactive, plan type) received from Apple and RevenueCat — without your payment details;
- the contents of support requests: email, message text, and the device identifier if you attach it yourself;
- short-lived technical logs of our API servers (response codes, request timing) — for stability and abuse protection.
No registration or account is required; we never ask for your name, phone number, or address.
What we do not collect
We do not store or record:
- browsing history or DNS queries;
- the contents of your traffic;
- your real IP address after a session ends;
- behavioral profiles or advertising identifiers.
The app contains no ad SDKs and no third-party analytics. We do not sell user data and never have.
How a VPN session works
During an active session, the VPN server technically sees your IP address and the traffic passing through — routing is impossible without that. This data is processed transiently in the server’s memory, is not written to disk, and is not linked to your identifier. Once the session ends, we retain no record of who connected or where.
Purposes and legal bases
We process data on the following bases (for EEA users, in GDPR terms):
- performance of a contract: operating the service, verifying subscription status, responding to requests;
- legitimate interest: infrastructure stability, protection against abuse and attacks;
- consent: when you contact us and provide contact details yourself.
Who we share data with
We use a limited set of processors:
- Apple — payment and subscription processing under its own policy;
- RevenueCat — subscription status validation: receives the anonymous identifier and App Store receipt data;
- hosting providers — running our VPN and API servers.
We do not sell data and do not share it with ad networks. Government requests are honored only when legally binding — and there is no activity history in our possession that could be handed over.
International transfers
Our servers are located in different countries — that is the essence of a VPN service. Where transferring personal data outside your jurisdiction requires legal safeguards, we rely on recognized mechanisms, including Standard Contractual Clauses (SCC).
Retention
The device identifier and subscription status are kept while the app profile is installed or the subscription is active. Support correspondence is kept for up to 24 months after a request is closed. Short-lived technical logs are automatically deleted within a short period.
Data deletion
The “Remove data” button on the app’s settings screen permanently erases the local profile and device identifier — after that, no data can be linked to you. You can also request deletion via the support form.
Your rights
Regarding your data, you have the right to:
- request access to it and obtain a copy;
- correct inaccurate data;
- delete data (the “right to be forgotten”);
- restrict or object to processing;
- receive data in a portable format;
- withdraw consent at any time;
- lodge a complaint with your country’s data protection authority.
To exercise these rights, write to us via the support form — we respond within 30 days.
Security
Traffic is encrypted with modern protocols (VLESS, Trojan over TLS). We practice data minimization, restrict access to our infrastructure, and keep server software up to date. No service can guarantee absolute security, but a leak of data we do not store is impossible by design.
Children
The service is not intended for anyone below the app’s age rating in the App Store. We do not knowingly collect children’s data; if you believe a child has provided us with data, contact us and we will delete it.
Cookies and the website
The vpn-ninja.app website uses no cookies, third-party trackers, or analytics scripts. The only data the site can process is what you submit yourself through the support form.
Changes to this policy
For significant changes, we will notify you in the app before they take effect. The current version is always available on this page; the date of the latest update is shown at the top.