Two different things, kept apart on purpose. Your traffic — the sites you reach, your DNS lookups, the contents of your connection — is not recorded. The app reports a small amount of technical information about itself, listed in full in section 5. And one optional feature, the email leak check, involves an address you type in yourself; that is dealt with separately in section 6. Blurring these together is how “no logs” claims stop being true, so this policy does not.
1. Who we are
VPN Protectify (the “App”) is published by NIKU SH.P.K., Bulevardi Zogu I, Pallati i Ri, Tirana 1000, Albania (“we”, “us”, “our”). We are the controller for the personal data described here.
Contact: [email protected]
2. The short version
| Data | Recorded by us? |
|---|---|
| Websites, apps and services you connect to | No. |
| DNS queries made while connected | No. |
| Contents of your traffic | No. Encrypted and not inspected. |
| Sessions tied to an identity | No. Connecting requires no identity. |
| An account, password or profile | No. The App has none. |
| Device model, iOS version, app version | Yes. |
| Crash and error reports | Yes. |
| Pseudonymous installation identifier | Yes. |
| Subscription status and App Store receipt | Yes. |
| Email address | Only if you use the leak check — see section 6. |
| IP address | Processed in transit; see section 7. |
| Advertising identifier (IDFA) | No. Not requested, not used. |
3. What we do not log
We do not create, store or retain records of:
- the websites, domains, applications or services your traffic reaches;
- DNS queries or resolutions made while the VPN is connected;
- the contents of any traffic passing through the tunnel;
- bandwidth or session records associated with an individual user;
- your originating IP address paired with any record of activity.
This is a statement about what we record, not a claim about what is technically possible on a network. Because activity logs are not produced, there is nothing of that kind for us to disclose, sell, lose in a breach, or hand over when asked.
4. No account to connect
Connecting to the VPN requires no registration, no login and no user profile. Access to paid features is verified against the App Store purchase on your device, through Apple. We never receive a password or a name, because the App never asks for one.
The only circumstance in which we handle an email address is if you choose to use the leak check, described next. That feature is optional and separate from the VPN.
5. What the app reports
Claiming to collect nothing at all would be inaccurate. The App includes a crash-reporting and analytics component, and a component that manages subscriptions. Between them, the following is processed:
Technical and diagnostic data
- Device model, iOS version, App version
- Language, region and coarse country derived from the connection
- Crash logs, error reports and performance diagnostics
- A pseudonymous installation identifier that distinguishes one install from another, and is reset if the App is deleted and reinstalled
- Basic events about the App itself — for example that a connection was started, or that a screen was opened
None of this describes where your traffic went. It describes the App: which version, on which device, and whether it worked.
Subscription data
- App Store receipts and purchase validation
- Subscription status, renewal, cancellation and trial state
- The country of your App Store account, for pricing and tax
Payments are handled entirely by Apple. We never see your card number or full payment details.
Support correspondence
If you write to us, we process your address and whatever you choose to tell us, for as long as it takes to resolve the matter and to keep a record of it.
6. The email leak check
The App includes an optional tool that checks whether an email address appears in known data-breach records. It is worth being precise about this, because it is the one place in the App where you hand over a piece of personal data.
- It is entirely optional. The VPN connects and works without it. Nothing prompts you to provide an address in order to use the App.
- You supply the address. It is typed in by you for the purpose of that single check.
- It is used for the check only. The address is compared against breach records and the result is shown to you. It is not used for marketing, not sold, and not added to any mailing list.
- It is not linked to your VPN use. Since connecting requires no account, there is nothing to attach an address to. An address entered into the leak check is not associated with any connection, session or location.
- Recently checked addresses may appear in the App so you can run the check again without retyping. That list is held on your device and disappears when the App is deleted.
Who performs the check. The lookup is carried out by Have I Been Pwned, an independent breach-notification service. Performing the check requires comparing your address against its records, which means the address you enter is transmitted to that service for that single purpose. Their own handling of it is governed by their privacy policy, available on their website.
We do not retain the address after the check, and we do not use it for anything else. If you would rather not have an address handled at all, do not use this feature — everything else in the App works without it.
7. IP addresses
Every network connection involves an IP address; that is how packets find their way back. Two consequences follow:
- On the VPN connection. Your IP address is used to carry the connection itself. It is not written to a log next to a record of your activity.
- On the App's own requests. When the App contacts our analytics or subscription providers, those providers observe the IP address of that request. Our analytics provider derives an approximate country from it for statistics and does not retain it in raw form in the reporting we receive.
8. No advertising or tracking
The App shows no advertising. It does not request Apple's advertising identifier (IDFA), does not present the App Tracking Transparency prompt, and does not track you across other companies' apps or websites. We do not sell personal data and we do not share it with advertising networks or data brokers.
9. Legal bases (GDPR)
For users in the European Economic Area and the United Kingdom:
- Performance of a contract (Art. 6(1)(b)) — operating the VPN service and managing your subscription.
- Consent (Art. 6(1)(a)) — the email leak check, which runs only when you choose to use it, and optional analytics where consent is required. Consent may be withdrawn at any time.
- Legitimate interests (Art. 6(1)(f)) — keeping the App stable and secure, diagnosing crashes, preventing abuse of the service.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records relating to purchases.
10. Service providers
We use a small number of providers, under written data processing agreements and only for the purposes above:
| Provider | Purpose |
|---|---|
| Apple Inc. | Distribution of the App, payments, subscription management |
| Our crash reporting and analytics provider | Crash logs, error diagnostics and aggregate app analytics |
| Our subscription management provider | Validating App Store receipts and tracking subscription state |
| Have I Been Pwned | Performing the optional email leak check described in section 6. Receives only the address you enter, and only when you run a check. |
| Third-party datacentre providers | Operating the servers that carry VPN traffic |
None of these providers receives records of your browsing, because no such records exist.
11. Where servers are
VPN servers are available in Australia, Brazil, Canada, Chile, France, Germany, Spain and the United States, and the list may change as capacity is added or servers are taken out of service. Your traffic passes through the location you select, or the one Optimal Location picks. As set out in section 3, no record of that traffic is kept at any of them.
We are established in Albania, and several of our providers are established outside the European Economic Area, including in the United States. Where personal data described in sections 5 and 6 is transferred out of the European Economic Area or the United Kingdom we rely on the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, as applicable. A copy of the safeguards in place is available on request.
12. Retention
- Activity and DNS logs — none exist, so nothing is retained.
- Email addresses entered into the leak check — not retained by us after the check. The convenience list of recent checks stays on your device.
- Crash and diagnostic data — up to 14 months, then deleted or aggregated.
- Subscription and billing records — for as long as tax and accounting law requires.
- Support correspondence — 24 months after the matter is closed.
13. Legal requests
If we receive a lawful request from an authority, we respond as the law requires. What we can produce is limited by what exists: there are no activity logs, no browsing history, no DNS records and no account details, so those cannot be produced regardless of who asks. We will not introduce new logging in order to satisfy a request without a valid legal obligation to do so.
14. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent.
Write to [email protected]. Please note a practical consequence of requiring no account: with no identifier linking you to a record on our side, we frequently cannot locate data “about you” at all. For subscription records, your App Store order ID is usually the only workable reference.
Albania
You may contact the Information and Data Protection Commissioner, which supervises personal data protection in Albania.
European Economic Area and United Kingdom
You may lodge a complaint with your national supervisory authority, or with the Information Commissioner's Office in the UK.
United States
If you are a resident of California or another state with comparable legislation, you have the right to know what personal information is collected, to request deletion, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and you will not be treated differently for exercising these rights.
15. Children
The App is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, write to us and we will delete it.
16. Security
VPN traffic is encrypted between your device and the server you connect to. Data exchanged between the App and our providers travels over TLS. Access to our systems is limited to the people who need it.
No system is perfectly secure. Keeping your device passcode-protected and your iOS version current does more for your safety than any single feature of this App.
17. Changes
Any updated version is posted on this page. Where a change is material, we will signal it in the App. If we ever begin collecting something not listed in sections 5 and 6, this page will say so before that change takes effect.
18. Contact
NIKU SH.P.K.
Bulevardi Zogu I, Pallati i Ri
Tirana 1000
Albania
Privacy: [email protected]
Support: [email protected]