Revision of 12 August 2026
Privanta privacy policy
This describes what data Privanta needs to run your account and the VPN, what it is used for, and how to manage it.
1. Scope
The policy covers the Privanta apps for Android TV, Android, iOS, Windows and macOS, the privanta.ai site, the account area and the service's server infrastructure. Questions about data can be sent to privacy@privanta.ai.
2. What data is processed
- Account
- Email address, an internal account identifier, subscription state, purchases, refunds and the right to use the service.
- Device
- A random registration identifier, the platform type, the app version, a neutral device name and cryptographic public keys. Private keys never leave the device.
- Connection reliability
- Bounded connection states, the chosen transport and gateway, the result of controlled DNS and HTTPS checks, the IP family, the time range of a connection and a closed error code.
- App stability
- On Android only the fact of a launch, a crash or an ANR is sent, by system code. Exception text, stack traces and memory contents are not sent.
- Abuse protection
- The network address is processed when a sign-in code is requested and is immediately turned into a keyed irreversible hash used for rate limiting. It is not used for advertising or to determine location.
- Support
- A diagnostic report, including any optional comment, is sent only after you explicitly choose to send it. Before sending, the app explains what diagnostic data is included.
3. VPN traffic
To provide the VPN, network nodes technically forward packets and process connection addresses. Privanta does not build a history of visited sites, searches, arbitrary DNS queries, messages, media or packet contents. That data is not used for advertising, profiling or sale.
Synthetic checks reach only Privanta's own controlled service addresses and record a result from a closed set of values, never a user's activity.
4. Purposes and sharing
Data is used for signing in, registering and revoking devices, managing the subscription, issuing a signed configuration, restoring a connection, preventing abuse, support, and measuring service reliability.
Privanta does not sell personal data and does not share it for advertising. Limited data may be processed by hosting, email and payment providers solely to deliver that service, under contract and with applicable safeguards.
5. Retention and protection
- Connection reliability events are kept for no more than 30 days.
- Account, devices and entitlement are kept for the life of the account and for the period the law requires afterwards.
- Payment records are kept as long as settlement, refunds, fraud prevention and the law require.
- Traffic between the apps and the Control Plane is protected with TLS; personal configurations are signed and encrypted for the device.
Periods may be shortened after legal review. Extending a period, or widening what is collected, requires updating this policy and the app-store declarations.
6. Access, deletion and choice
In your account area you can view your subscription and devices, revoke a device or a session, request a data export and request account deletion. For questions, write to privacy@privanta.ai.
A diagnostic file is never sent without separate consent. The system events needed for the security and reliability of the VPN are part of running the service and are limited to the fields listed above.
7. Changes to this policy
If what is processed or why changes materially, Privanta will update the date and the text of this policy before releasing the corresponding app version. An earlier revision does not automatically cover new processing.