RU | EN

Privacy Policy — NeedleVPN

Last updated: 2026-07-15

Introduction

NeedleVPN is an Android mobile application built for those who value their personal space online. We help our users protect their privacy and security when going online. Understanding that anonymity is what matters most to you, we deliberately collect only the strict minimum amount of data necessary to provide the service, and nothing beyond that.

This document explains exactly what data we process, why we process it, where it is stored, and for how long. The text is written as directly as possible, without legal tricks: we want you to understand exactly what you agree to when installing the application.

By using the NeedleVPN application, you confirm that you have read this Privacy Policy and agree to its terms. If you do not agree with any provision, do not install the application or delete it.

1. WHAT DATA WE COLLECT

We collect the minimum information necessary for the service to work.

1.1. Email address.

You enter it during registration and each login. The email address is used exclusively for:

We do not use your email for newsletters, advertising, or transfer to third parties for marketing purposes.

1.2. Device identifier (device hash).

On first launch, the application calculates a SHA-256 hash of the Android system identifier (Settings.Secure.ANDROID_ID) and sends only this hash to the server. Our server does not receive the original ANDROID_ID and technically cannot store it.

This hash is used for:

It is impossible to restore your real ANDROID_ID, IMEI, device serial number, or other identifiers from a SHA-256 hash.

1.3. Device name.

This is a string consisting of the phone manufacturer and model (for example, "Xiaomi Redmi Note 12"). It is used only so that you can distinguish your active sessions from each other in your account. It is not transferred to advertising systems or analytics.

1.4. Subscription data.

Plan type (free trial, monthly subscription, etc.), start and end dates, and status (active / expired / cancelled). This data does not contain banking information.

1.5. Payment data.

Payments are processed through third-party payment gateways. We receive from them only depersonalized service information: amount, currency, date, and transaction identifier. Full bank card details are not transferred to our server, are not processed by us, and are not stored by us.

1.6. Referral relations.

If you enter a friend's referral code during registration, we store the "inviter - invited user" relation for later awarding of bonus subscription days. Apart from this relation and the fact that the invited user paid for a subscription, we do not collect additional information for the referral program.

1.7. Minimal technical logs during a VPN session.

During an active connection to our VPN server, we may temporarily store technical data necessary for service quality diagnostics: operating system version, device model, IP address of the server you are connected to, and the fact of a connection error. These logs are strictly depersonalized and are automatically deleted after the active session ends. Depending on the type of log, this may take from several minutes to several hours.

After the VPN session ends, the information listed above becomes unavailable to us and to anyone else.

1.8. Our own product analytics.

To understand where users run into trouble (registration, trial, first connection, payment), we collect a minimal set of first-party product events. Each event is tied only to your internal account identifier and contains: the event name, time, app version, platform, experiment variant (if any), and a small set of technical fields from a pre-approved allowlist.

Example events: registration completed, trial started, referral code applied, first-connection attempt and success, the fact of being active on a given day, payment screen shown, transition to the payment bot, invoice created and payment succeeded, subscription expired.

These events do not contain: your email, exact IP address, websites visited, destination domains, traffic contents, advertising identifiers, carrier identifiers, or bank card data. We do not use them for advertising and do not share them with ad networks. Raw events are retained for 180 days and then deleted; when you delete your account, they are deleted together with it (cascade). Anonymous aggregated counters may be kept longer for product reporting.

Analytics is implemented on our own server, without any third-party advertising or tracking SDKs (see section 2).

2. WHAT WE DO NOT COLLECT

We intentionally configured our infrastructure so that we physically do not have the following data:

We do not use third-party analytics or tracking SDKs in the application: Firebase, Google Analytics, AppMetrica, Yandex Metrica, Facebook SDK, AppsFlyer, Adjust, or similar marketing-attribution or user-behavior tracking tools. Our own product analytics, described in section 1.8, does not track your browser activity and is not shared with ad networks.

3. ANDROID APPLICATION PERMISSIONS

4. HOW AND WHERE DATA IS STORED

4.1. Server.

The backend and PostgreSQL database are hosted on a VPS from a European hosting provider subject to GDPR. All connections between the application and the server are protected by HTTPS (TLS 1.3). JWT session tokens are stored in the database only as cryptographic hashes and cannot be reused after logout.

4.2. Device.

JWT tokens, email, cached subscription state, and VPN configuration are stored locally in Android EncryptedSharedPreferences with AES-256 encryption through the system Android Keystore. These data are protected from reading by other applications on your device.

4.3. Backups.

A daily database backup is encrypted on our server using GPG (asymmetric key) and only then uploaded to cloud storage. The third-party cloud provider receives only the encrypted file and cannot decrypt its contents without our private key.

5. RETENTION PERIODS

6. TO WHOM AND WHY WE TRANSFER DATA

We transfer the minimum amount of data only to services without which we cannot provide the service:

We do not sell, rent, or otherwise transfer your data to commercial third parties, advertising networks, or data brokers.

7. NO ADVERTISING OR TRACKERS

The NeedleVPN application does not show advertisements. No third-party advertising SDKs, Google Advertising ID, or similar systems operate inside the application. Our own product analytics (section 1.8) is used only to improve the product and is not advertising tracking.

8. USER RIGHTS

8.1. Right of access.

Upon your written request from the email address registered to the account, we will provide all data stored by us in connection with your account in a machine-readable format (JSON) within 14 business days.

8.2. Right to deletion.

Upon your written request from the email address registered to the account, we will permanently delete all data related to the account within 7 business days.

8.3. Right to rectification.

If any data we store about you is inaccurate, for example if you want to change your email address, contact us and we will make the changes.

8.4. Right to restriction of processing and data portability.

Any other rights granted by the applicable laws of your jurisdiction (GDPR, CCPA, etc.) are exercised in the same manner: by written request from the registered email address.

Contact for all such requests: support.needlevpn@gmail.com

9. REQUESTS FROM GOVERNMENT AUTHORITIES AND THIRD PARTIES

We consider lawful requests for disclosure of information only if they come from authorized authorities, are properly issued, and comply with applicable law. We respond to them solely to the extent of the data we actually have (see Sections 1 and 2).

When receiving such a request:

DMCA requests or other copyright protection claims received from private persons or their representatives are redirected directly to the authors of the alleged violation, because we do not log user traffic and cannot associate a specific online action with a specific account. We do not provide such information to third parties.

10. SECURITY

Nevertheless, absolute security on the Internet does not exist. If you discover a vulnerability in our service, please contact us and we will promptly fix it.

11. CHANGES TO THIS POLICY

We may periodically make changes to this Privacy Policy. Material changes will be announced:

Between publication of an updated version and the moment it takes effect, we provide at least 14 calendar days during which you may stop using the service if you do not agree with the changes.

Continued use of the application after the changes take effect means your acceptance of the updated Policy.

The date of the last update is shown at the beginning of the document.

12. CONTACTS

For all questions related to this Privacy Policy, requests for access to data, rectification, deletion, portability, or restriction of processing, write to:

support.needlevpn@gmail.com

We respond to emails within 5 business days.