Privacy Policy
A VPN is a trust product. This policy says exactly what we collect, what we never collect, and what happens to your data. It is written to be read, not skimmed past.
The short version
- We do not log what you do online. Not your browsing, not your DNS queries, not your traffic.
- We keep the minimum needed to run your account: your email and your subscription state.
- Your WireGuard private key is generated on your device and never leaves it. We only ever see the public key.
- We do not sell, rent, share, or disclose your data to third parties for any purpose. The only companies that ever touch it are the processors listed below, acting on our instructions to deliver the service.
Who we are
SecuremeVPN is operated by Dharam Digital Private Limited ("we", "us"), the data controller for the personal data described here.
Dharam Digital Private Limited
710-711, Tower B, Emaar Digital Greens, Sector 61, Gurgaon, Haryana 122001, India
+91 124 4009257
support@securemevpn.com
What we collect
Account data
- Email address. Used to sign you in with one-time codes, deliver any redeem codes we issue you, and send service emails such as trial and renewal notices.
- Sign in with Apple or Google identifiers. If you use social sign-in we store the provider's stable account identifier so we can recognize you next time. Apple may give us a private relay email instead of your real one; that is fine with us.
- Subscription state. Which plan you are on, whether it is active, when it renews or expires, and which store billed it. This comes from Apple or Google.
- Device records. A name, platform, and app version for each signed-in device, so you can see and remove your devices and so we can enforce the 5 device limit.
- Push notification token. If you allow notifications, the app stores a push token with your device record so we can tell you when your subscription starts, renews, or ends. The token is removed when you sign out or remove the device.
Operational data
- Live session records. While a tunnel is connected, our API holds the session needed to keep it running: the device's WireGuard public key, the private tunnel address it was assigned, the server it is on, when the session started, and the time of the last handshake (used only to expire dead sessions). When you disconnect, or the session goes stale, the record is deleted within one hour. We do not keep a history of your connections.
- Aggregate bandwidth counters per server. Each VPN server reports totals so we can plan capacity and keep servers fast. These are counters per server node, never per user.
- WireGuard public keys. When a device connects, it registers its public key so the server will accept the tunnel. The matching private key is created on your device and never transmitted anywhere.
- Support messages. If you contact us, we keep the message and our reply so we can actually help you.
- API and website access logs. Like every web service, our API and website servers keep short-lived technical logs (IP address, time, endpoint, response code) for security, rate limiting, and abuse prevention. These are the servers you sign in and manage your account through, not the VPN servers, and they are rotated within 30 days.
What we never collect
- Browsing history or the content of your traffic.
- DNS queries.
- A history of your connections. Live sessions exist only while you are connected and are deleted afterwards.
- Your source IP address on VPN servers. VPN servers do not write connection or activity logs.
- Bandwidth usage tied to an individual user.
Our VPN servers are configured without user-level activity logging. If a server is seized or compromised, there is no history of who connected where, because that history is never written.
Third parties
We do not sell, use, or disclose any of your data to third parties for any purpose other than delivering the service to you. We never share VPN usage data with anyone, because we do not have it. The only companies that process personal data on our behalf are:
- Apple and Google for payments, as described below.
- Adapty, which manages App Store and Google Play subscriptions for us. It receives an anonymous account identifier, your purchase state, and subscription events such as a paywall being viewed or a plan being bought, which we use to understand our own sales; it does not receive your email or any VPN data, and we have disabled its collection of advertising identifiers (IDFA and Google Advertising ID) and of your IP address.
- Amazon Web Services, which delivers our service emails.
- Google Firebase Cloud Messaging and Apple Push Notification service, which relay push notifications to your device. They receive the device's push token and the notification itself, a short subscription status message, and nothing else.
- Hosting providers that run our API and VPN servers. They provide the machines; they do not have access to your account data or traffic.
We do not use advertising SDKs, cross-app tracking, or the advertising identifier, and we never sell your data or use it to advertise other companies' products. Two things come close enough that we want to spell them out: the subscription events Adapty records for us, described above, and Apple Search Ads attribution when we advertise on the App Store, where Apple tells us (through Adapty, using Apple's own AdServices framework rather than the advertising identifier) which of our own ads led to a download so we can measure them. Neither involves your browsing, traffic, or VPN use, and neither is shared with anyone else.
Legal requests
If we receive a lawful request for user data, we can only provide what we hold: the account data listed above. We have no connection logs, browsing data, or traffic to hand over, and we will contest overbroad requests where the law allows.
Payment processors
All purchases are made through the app stores, so we never see or store your card details. Payments are handled by:
- Apple App Store for purchases made on iPhone, iPad, and Mac App Store builds.
- Google Play for purchases made on Android.
Each processor has its own privacy policy that applies to the payment itself.
Service emails, such as sign-in codes and receipts, are delivered through Amazon Simple Email Service. We send transactional email only. We do not send marketing email unless you have explicitly opted in, and every non-essential email includes a working way out.
Data retention
- Account data is kept while your account exists.
- If you delete your account, in the app under Settings, your account is deactivated immediately: all devices and sessions are removed and, if you signed in with Apple, we revoke the Sign in with Apple token. Signing in again within 30 days restores the account; after 30 days your email, sign-in identifiers, and device records are permanently erased and any remaining billing records are anonymized.
- Live VPN session records are deleted within one hour of the session ending.
- One-time sign-in codes expire within 10 minutes and are stored only as hashes.
- Technical access logs for the API and website are rotated within 30 days.
- Aggregate server counters contain no personal data and may be kept for capacity planning.
Why we are allowed to process this data
If you are in the EEA or the UK, the GDPR requires us to name a legal basis for each purpose. Ours are:
- Performance of a contract. Your email, sign-in identifiers, subscription state, device records, live session records, and WireGuard public keys. Without these we cannot give you an account or a working tunnel.
- Legitimate interests. Short-lived API and website access logs, aggregate per-server bandwidth counters, and acting on credible abuse reports. Our interest is keeping the service secure, available, and fast; we have balanced it against your privacy by keeping these records minimal, aggregated where possible, and short-lived.
- Consent. Marketing email, which we send only if you opt in and which you can withdraw at any time. Withdrawing consent does not affect processing that already happened.
- Legal obligation. Retaining billing and tax records, and responding to lawful requests, where the law requires it of us.
Where your data is processed
We are based in India and our processors and servers are located in several countries, so your personal data is transferred internationally. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), or on an adequacy decision where one covers the destination, and we require each processor to apply security measures appropriate to the data. You can ask us for details of the safeguards used for a specific transfer.
Your rights
Wherever you live, we extend the same rights to you: access, correction, export, and deletion of your personal data, and objection to processing. If you are in the EEA or UK these are your GDPR rights, which also include the right to restrict processing and the right to data portability; in California, your CCPA rights, including the right not to be discriminated against for exercising them; in India, your rights under the Digital Personal Data Protection Act, 2023. To exercise any of them, use the contact page or email support@securemevpn.com from your account email. We respond within 30 days, and we do not charge for this.
We would rather hear from you first, but you always have the right to complain to a regulator. In the EEA that is the data protection supervisory authority of the country you live or work in; in the UK, the Information Commissioner's Office; in India, the Data Protection Board of India.
Children
SecuremeVPN is not directed at children under 16 and we do not knowingly collect data from them.
Changes to this policy
If we change this policy in a way that matters, we will notify you by email or in the app before the change takes effect. The effective date below always reflects the current version.
Contact
Privacy questions go to support@securemevpn.com or the contact page.
Data controller: Dharam Digital Private Limited
710-711, Tower B, Emaar Digital Greens, Sector 61, Gurgaon, Haryana 122001, India
+91 124 4009257
support@securemevpn.com
SecuremeVPN