Privacy Policy
HuruVPN ("HuruVPN", "we", "us", or "our") provides a virtual private network (VPN) service and mobile application (the "Service"). Protecting your privacy is the reason this Service exists, and this Policy explains — in plain language — what information we do and do not collect, how we use it, and the choices you have.
1. Information we do NOT collect
- We do not log the websites, services, or apps you access through the VPN.
- We do not store your DNS queries or the content of your network traffic.
- We do not record your original IP address alongside your activity to build a profile of you.
- We do not sell or rent your personal information to third parties.
2. Information we do collect
To operate a reliable, secure Service, we process a limited amount of data:
a. Anonymous device & account data
When you use the app, we create an anonymous device identity so we can issue you a secure VPN configuration. This includes a randomly generated device identifier and a public cryptographic key. No email or personal login is required to use the free tier.
b. Technical session metadata
We keep minimal operational data such as which server a device is provisioned on, aggregate bandwidth counters per account and day, connection timestamps, the device's brand/model, app language and the country it connected from (derived from the network at connection time, never a precise location). This is needed to manage capacity, balance servers, prevent abuse and troubleshoot; it is not used to profile your online behaviour. Connection events are kept with at most a truncated network prefix (for example 203.0.113.0), never your full IP address.
c. Subscription & billing
When you unlock Premium with a coupon, we record which coupon code was activated, on which account, and when, together with the plan it grants and its expiry — this is what lets us verify and enforce your entitlement. If the coupon was issued to an authorized reseller, that reseller can see that the coupon was activated and when (for their sales reporting), but not your identity or activity. Coupons are non-refundable (see the Terms). If you instead purchase Premium through Google Play or the Apple App Store, the transaction is processed by that store and we receive only a purchase token / receipt to activate your entitlement. We do not receive or store your full payment card details.
d. Diagnostics & analytics
The app uses Firebase Crashlytics (crash and stability reports) and Firebase Analytics (anonymous usage statistics such as app opens, connects and the screens used) from Google, and Firebase Cloud Messaging to deliver push notifications. Crash reporting is on by default and can be switched off in Settings → App Crash Report. These services process a device identifier (including the advertising ID on Android), device model, OS version, app version, language and country.
3. Advertising (free tier)
The free tier of HuruVPN is funded by advertising. Ads are shown only to free-tier users; Premium removes all ads. We use Google AdMob (Google LLC) and, through AdMob mediation, Meta Audience Network (Meta Platforms, Inc.) to display banner ads, interstitial ads, app-open ads and rewarded video ads (the ad you can choose to watch in exchange for free VPN time). These ad partners receive the Android advertising ID, IP address, coarse location derived from it, device and app information and ad-interaction data, and may use it to select and measure ads according to their own privacy policies (Google, Meta).
We also use the Meta SDK for install attribution, so we can see which advertising campaign an install came from; this sends the advertising ID and basic app events (install, app open) to Meta.
Your choices. Where the law requires it (for example in the EEA, UK and Switzerland) the app asks for your consent before personalised ads are shown, and you can change your choice at any time in Settings → Ads privacy options. On any Android device you can reset or delete your advertising ID under Settings → Google → Ads, which also stops personalised advertising. Ads are never shown inside your VPN traffic, and we never inject anything into the websites you visit.
4. How we use information
- To provide, maintain, and secure the VPN Service.
- To provision your device with a working, encrypted configuration.
- To manage server capacity and prevent fraud or abuse.
- To verify and activate Premium subscriptions.
- To improve reliability and fix problems (crash reports and anonymous usage statistics).
- To show and measure advertising on the free tier, and to attribute installs to our advertising campaigns.
- To send you service notifications and, if you allow notifications, occasional announcements.
5. Data sharing
We share data only with the service providers named in this Policy (Google — Firebase and AdMob; Meta — Audience Network and install attribution; app-store billing verification; our hosting providers), and only to the extent needed for the purposes above. We do not sell personal information. We may disclose information if required by valid legal process — but we cannot produce activity logs we do not keep.
6. Data retention
Server health and bandwidth statistics are kept for 30 days; connection-event records (with truncated network prefixes) for up to 180 days; per-account daily bandwidth totals for as long as the account exists. A device's VPN peer is removed automatically after about 30 days without use and re-created on the next connection. Anonymous device records may be removed after prolonged inactivity. You can ask for deletion at any time — see Delete my data.
7. Security
Your VPN keys are generated on your device and sealed to it. Traffic is protected with WireGuard using Curve25519 key exchange and AES-256-GCM encryption. We apply administrative and technical safeguards to protect the limited data we hold.
8. Your rights
Depending on your location (including under the GDPR and CCPA), you may have the right to access, correct, or delete personal data we hold about you, and to object to certain processing. Because the free tier is anonymous, we may be unable to identify data relating to a specific individual. To make a request, contact us at [email protected].
9. Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.
10. International transfers
Our servers operate in multiple countries. By using the Service you understand your connection may be routed through, and limited operational data processed in, regions outside your own.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected here with a new "Last updated" date. Continued use of the Service after changes means you accept the updated Policy.
12. Contact us
Questions about privacy? Email [email protected] or visit our Contact page.
Huru