Two different things, kept apart on purpose. Your traffic — the sites you reach, your DNS lookups, the contents of your connection — is not recorded. The app does report a small amount of technical information about itself, listed in full in section 5. Blurring those two together is how “no logs” claims stop being true, so this policy does not.
1. Who we are
VaultVPN (the “App”) is published by YourApps Ltd., Rm 1603 16/F THE L PLZ, 367-375 Queen's Rd C, Sheung Wan, Hong Kong (“we”, “us”, “our”). We are the controller for the personal data described here.
Contact: [email protected]
2. The short version
| Data | Recorded by us? |
|---|---|
| Websites, apps and services you connect to | No. |
| DNS queries made while connected | No. |
| Contents of your traffic | No. Encrypted and not inspected. |
| Sessions tied to an identity | No. There is no identity to tie them to. |
| Email address, password, profile | No. The App has no accounts. |
| Device model, iOS version, app version | Yes. |
| Crash and error reports | Yes. |
| Pseudonymous installation identifier | Yes. |
| Subscription status and App Store receipt | Yes. |
| IP address | Processed in transit; see section 6. |
| Advertising identifier (IDFA) | No. Not requested, not used. |
3. What we do not log
We do not create, store or retain records of:
- the websites, domains, applications or services your traffic reaches;
- DNS queries or resolutions made while the VPN is connected;
- the contents of any traffic passing through the tunnel;
- bandwidth or session records associated with an individual user;
- your originating IP address paired with any record of activity.
This is a statement about what we record, not a claim about what is technically possible on a network. Because activity logs are not produced, there is nothing of that kind for us to disclose, sell, lose in a breach, or hand over when asked.
4. No account
The App has no registration, no login and no user profile. Access to paid features is verified against the App Store purchase on your device, through Apple. We never receive an email address, a password or a name, because the App never asks for one.
5. What the app reports
Claiming to collect nothing at all would be inaccurate. The App includes a crash-reporting and analytics component, and a component that manages subscriptions. Between them, the following is processed:
Technical and diagnostic data
- Device model, iOS version, App version
- Language, region and coarse country derived from the connection
- Crash logs, error reports and performance diagnostics
- A pseudonymous installation identifier that distinguishes one install from another, and is reset if the App is deleted and reinstalled
- Basic events about the App itself — for example that a connection was started, or that a screen was opened
None of this describes where your traffic went. It describes the App: which version, on which device, and whether it worked.
Subscription data
- App Store receipts and purchase validation
- Subscription status, renewal, cancellation and trial state
- The country of your App Store account, for pricing and tax
Payments are handled entirely by Apple. We never see your card number or full payment details.
Support correspondence
If you write to us, or use the contact form on our website, we process your email address and whatever you choose to tell us, for as long as it takes to resolve the matter and to keep a record of it. The form on our website does not send anything by itself — it opens your own email application with a message prepared, and nothing reaches us until you send it.
6. IP addresses
Every network connection involves an IP address; that is how packets find their way back. Two consequences follow:
- On the VPN connection. Your IP address is used to carry the connection itself. It is not written to a log next to a record of your activity.
- On the App's own requests. When the App contacts our analytics or subscription providers, those providers observe the IP address of that request. It is used to derive an approximate country for statistics and is not retained in raw form in the reporting we receive.
7. No advertising or tracking
The App shows no advertising. It does not request Apple's advertising identifier (IDFA), does not present the App Tracking Transparency prompt, and does not track you across other companies' apps or websites.
8. Third parties
We do not sell, rent or trade personal data, and we do not disclose it to third parties for their own purposes. We do not share data with advertising networks or data brokers.
We use a small number of providers who process data strictly on our behalf, under written data processing agreements and only for the purposes described in this policy:
| Provider | Purpose |
|---|---|
| Apple Inc. | Distribution of the App, payments, subscription management |
| Our crash reporting and analytics provider | Crash logs, error diagnostics and aggregate app analytics |
| Our subscription management provider | Validating App Store receipts and tracking subscription state |
| Third-party datacentre providers | Operating the servers that carry VPN traffic |
None of these providers receives records of your browsing, because no such records exist.
9. Legal bases (GDPR)
For users in the European Economic Area and the United Kingdom:
- Performance of a contract (Art. 6(1)(b)) — operating the VPN service and managing your subscription.
- Legitimate interests (Art. 6(1)(f)) — keeping the App stable and secure, diagnosing crashes, preventing abuse of the service.
- Consent (Art. 6(1)(a)) — where consent is required for optional analytics. It may be withdrawn at any time.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records relating to purchases.
10. Where data is processed
We are established in Hong Kong. Our providers and the servers carrying VPN traffic are located in a number of countries, so the data described in section 5 may be processed outside your country of residence.
Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, as applicable. A copy of the safeguards in place is available on request.
11. Retention
- Activity and DNS logs — none exist, so nothing is retained.
- Crash and diagnostic data — up to 14 months, then deleted or aggregated.
- Subscription and billing records — for as long as tax and accounting law requires.
- Support correspondence — 24 months after the matter is closed.
12. Legal requests
If we receive a lawful request from an authority, we respond as the law requires. What we can produce is limited by what exists: there are no activity logs, no browsing history, no DNS records and no account details, so those cannot be produced regardless of who asks. We will not introduce new logging in order to satisfy a request without a valid legal obligation to do so.
13. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent.
Write to [email protected]. Please note a practical consequence of having no accounts: with no identifier linking you to a record on our side, we frequently cannot locate data “about you” at all. For subscription records, your App Store order ID is usually the only workable reference.
European Economic Area and United Kingdom
You may lodge a complaint with your national supervisory authority, or with the Information Commissioner's Office in the UK.
Hong Kong
You may contact the Office of the Privacy Commissioner for Personal Data, which supervises the Personal Data (Privacy) Ordinance.
United States
If you are a resident of California or another state with comparable legislation, you have the right to know what personal information is collected, to request deletion, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and you will not be treated differently for exercising these rights.
14. Children
The App is not directed at children and we do not knowingly collect personal data from anyone under 16, or under the minimum age required in your country. If you believe a child has provided us with data, write to us and we will delete it.
15. Security
VPN traffic is encrypted between your device and the server you connect to. Data exchanged between the App and our providers travels over TLS. Access to our systems is limited to the people who need it.
No system is perfectly secure. Keeping your device passcode-protected and your iOS version current does more for your safety than any single feature of this App.
16. Changes
Any updated version is posted on this page. Where a change is material, we will signal it in the App. If we ever begin collecting something not listed in section 5, this page will say so before that change takes effect.
17. Contact
YourApps Ltd.
Rm 1603 16/F THE L PLZ
367-375 Queen's Rd C
Sheung Wan
Hong Kong
Privacy: [email protected]
Support: [email protected]