Last updated: 2026-07-15
NeedleVPN is an Android mobile application built for those who value their personal space online. We help our users protect their privacy and security when going online. Understanding that anonymity is what matters most to you, we deliberately collect only the strict minimum amount of data necessary to provide the service, and nothing beyond that.
This document explains exactly what data we process, why we process it, where it is stored, and for how long. The text is written as directly as possible, without legal tricks: we want you to understand exactly what you agree to when installing the application.
By using the NeedleVPN application, you confirm that you have read this Privacy Policy and agree to its terms. If you do not agree with any provision, do not install the application or delete it.
We collect the minimum information necessary for the service to work.
You enter it during registration and each login. The email address is used exclusively for:
We do not use your email for newsletters, advertising, or transfer to third parties for marketing purposes.
On first launch, the application calculates a SHA-256 hash of the Android system identifier (Settings.Secure.ANDROID_ID) and sends only this hash to the server. Our server does not receive the original ANDROID_ID and technically cannot store it.
This hash is used for:
It is impossible to restore your real ANDROID_ID, IMEI, device serial number, or other identifiers from a SHA-256 hash.
This is a string consisting of the phone manufacturer and model (for example, "Xiaomi Redmi Note 12"). It is used only so that you can distinguish your active sessions from each other in your account. It is not transferred to advertising systems or analytics.
Plan type (free trial, monthly subscription, etc.), start and end dates, and status (active / expired / cancelled). This data does not contain banking information.
Payments are processed through third-party payment gateways. We receive from them only depersonalized service information: amount, currency, date, and transaction identifier. Full bank card details are not transferred to our server, are not processed by us, and are not stored by us.
If you enter a friend's referral code during registration, we store the "inviter - invited user" relation for later awarding of bonus subscription days. Apart from this relation and the fact that the invited user paid for a subscription, we do not collect additional information for the referral program.
During an active connection to our VPN server, we may temporarily store technical data necessary for service quality diagnostics: operating system version, device model, IP address of the server you are connected to, and the fact of a connection error. These logs are strictly depersonalized and are automatically deleted after the active session ends. Depending on the type of log, this may take from several minutes to several hours.
After the VPN session ends, the information listed above becomes unavailable to us and to anyone else.
To understand where users run into trouble (registration, trial, first connection, payment), we collect a minimal set of first-party product events. Each event is tied only to your internal account identifier and contains: the event name, time, app version, platform, experiment variant (if any), and a small set of technical fields from a pre-approved allowlist.
Example events: registration completed, trial started, referral code applied, first-connection attempt and success, the fact of being active on a given day, payment screen shown, transition to the payment bot, invoice created and payment succeeded, subscription expired.
These events do not contain: your email, exact IP address, websites visited, destination domains, traffic contents, advertising identifiers, carrier identifiers, or bank card data. We do not use them for advertising and do not share them with ad networks. Raw events are retained for 180 days and then deleted; when you delete your account, they are deleted together with it (cascade). Anonymous aggregated counters may be kept longer for product reporting.
Analytics is implemented on our own server, without any third-party advertising or tracking SDKs (see section 2).
We intentionally configured our infrastructure so that we physically do not have the following data:
We do not use third-party analytics or tracking SDKs in the application: Firebase, Google Analytics, AppMetrica, Yandex Metrica, Facebook SDK, AppsFlyer, Adjust, or similar marketing-attribution or user-behavior tracking tools. Our own product analytics, described in section 1.8, does not track your browser activity and is not shared with ad networks.
The backend and PostgreSQL database are hosted on a VPS from a European hosting provider subject to GDPR. All connections between the application and the server are protected by HTTPS (TLS 1.3). JWT session tokens are stored in the database only as cryptographic hashes and cannot be reused after logout.
JWT tokens, email, cached subscription state, and VPN configuration are stored locally in Android EncryptedSharedPreferences with AES-256 encryption through the system Android Keystore. These data are protected from reading by other applications on your device.
A daily database backup is encrypted on our server using GPG (asymmetric key) and only then uploaded to cloud storage. The third-party cloud provider receives only the encrypted file and cannot decrypt its contents without our private key.
We transfer the minimum amount of data only to services without which we cannot provide the service:
We do not sell, rent, or otherwise transfer your data to commercial third parties, advertising networks, or data brokers.
The NeedleVPN application does not show advertisements. No third-party advertising SDKs, Google Advertising ID, or similar systems operate inside the application. Our own product analytics (section 1.8) is used only to improve the product and is not advertising tracking.
Upon your written request from the email address registered to the account, we will provide all data stored by us in connection with your account in a machine-readable format (JSON) within 14 business days.
Upon your written request from the email address registered to the account, we will permanently delete all data related to the account within 7 business days.
If any data we store about you is inaccurate, for example if you want to change your email address, contact us and we will make the changes.
Any other rights granted by the applicable laws of your jurisdiction (GDPR, CCPA, etc.) are exercised in the same manner: by written request from the registered email address.
Contact for all such requests: support.needlevpn@gmail.com
We consider lawful requests for disclosure of information only if they come from authorized authorities, are properly issued, and comply with applicable law. We respond to them solely to the extent of the data we actually have (see Sections 1 and 2).
When receiving such a request:
DMCA requests or other copyright protection claims received from private persons or their representatives are redirected directly to the authors of the alleged violation, because we do not log user traffic and cannot associate a specific online action with a specific account. We do not provide such information to third parties.
Nevertheless, absolute security on the Internet does not exist. If you discover a vulnerability in our service, please contact us and we will promptly fix it.
We may periodically make changes to this Privacy Policy. Material changes will be announced:
Between publication of an updated version and the moment it takes effect, we provide at least 14 calendar days during which you may stop using the service if you do not agree with the changes.
Continued use of the application after the changes take effect means your acceptance of the updated Policy.
The date of the last update is shown at the beginning of the document.
For all questions related to this Privacy Policy, requests for access to data, rectification, deletion, portability, or restriction of processing, write to:
support.needlevpn@gmail.com
We respond to emails within 5 business days.