Privacy Policy
VPNCN — effective 27 August 2026
What we do not collect
This is the part that matters for a VPN, so it comes first.
- We do not log your IP address. Our servers receive it in
order to carry your connection, and discard it. It is not written to any log
or database.
- We do not log your traffic. No websites, no domains, no
DNS queries, no destinations, no timestamps of individual connections.
- We do not inspect or store what you send.
We cannot hand over records we never created.
What we do hold
- Your Telegram account id, display name, username and interface language,
so the bot can recognise you.
- For website customers, a keyed one-way fingerprint of the normalized email
address, plus the address itself encrypted at rest, so repeat visits use one
account and we can send access and expiry messages.
- Payment records: which plan, how much, when, which method, and the
reference the payment provider gives us.
- Your subscription: plan, expiry date, traffic allowance and how much of it
you have used, as a running total in bytes.
- An internal identifier for your VPN account, stored encrypted, and the
number of devices currently connected.
- If you use a customer referral link, the public referral code, the account
that invited you, and the time we recorded that relationship. We also count a
link open once per Telegram account or website browser. The website uses a
random first-party cookie which is converted to a keyed one-way hash before
storage; we do not use an IP address or device fingerprint for this count. We
retain only the aggregate byte total and activation time needed to determine whether the
referral reached the internal proof-of-use qualification; we do not retain a
connection history or activity record for this purpose.
- Referral reward records: the campaign, milestone, granted VPN time and
delivery status. The inviter sees aggregate link-open, joined-account,
free-trial and buyer counts, but never an email, traffic total, activity,
purchase amount, or connection history. When a new account joins, we notify a
Telegram inviter. That message may include the new Telegram account's public
username; a website account is described only as a website user. We also keep
delivery status for one referral invitation sent three days after a Telegram
account first starts the bot, and for free-trial or post-trial reminders sent
after 8 hours, 2 days, 7 days, one month and monthly after that. Trial prompts
stop after access is granted and post-trial prompts stop after a purchase.
- If you arrive through a Whop affiliate link, the Whop affiliate code and
the time it was captured. A live Whop attribution and an internal customer
referral cannot both be attached to one account.
- If you arrive through a tracked campaign link: the source label and whether
you pressed Start in the bot. For Meta ads this also includes Meta's opaque
ad-click and campaign/ad identifiers. Meta Pixel receives the browser's normal
network information on Meta landing, activated-trial and confirmed-payment pages. Meta events
do not contain your email, Telegram id, messages, card details, or VPN use.
The traffic figure is a single number per account. It shows how much you
used, never what you did.
Why we hold it
To give you what you paid for, to enforce the traffic allowance and device
limit, to handle payments and refunds, to keep the service running, to apply
customer referral rewards after genuine aggregate VPN use, to show whether a
customer referral link was opened and led to a joined account, free trial or
purchase, and to
measure whether a tracked campaign link led to a real bot start, activated
website trial or confirmed purchase instead of counting every link click or
form/checkout visit, and to send one referral invitation three days after a
Telegram account first starts the bot, plus relevant free-trial and post-trial
reminders until access is granted or a plan is purchased.
Who else is involved
We use other companies to operate, and they hold their own data under their
own policies:
- Telegram — the bot runs there, so Telegram sees your
messages with it and holds your account and phone number.
- Payment providers — whichever you choose handles the
payment and holds its own record of it. We never see your card details.
- Whop — if you choose its affiliate program, Whop manages
affiliate signup, verification, tracking, commission and payout information.
We pass an eligible Whop affiliate code into a Whop checkout only when it does
not conflict with an internal customer referral.
- Resend — if you start a website trial, we hand it your
email to send the verification link. If you buy with a card, the address also
travels with the order to the payment provider and back. We use Resend for the
access email, three daily subscription-expiry reminders, and recurring plan
reminders after an unconverted website trial. We store the address only in
encrypted form and do not use it for unrelated newsletters or third-party
advertising.
- Hosting providers — our servers run on rented
infrastructure.
- Meta — Meta ad pages load Meta Pixel and send PageView.
Meta therefore receives ordinary browser and network information and may read
or set its advertising cookies. If you press Start in Telegram, we send Lead.
If your verified website trial is actually granted, we also send Lead. After
the payment provider confirms a website payment, we send Purchase with the
order id, amount and currency. Browser and server copies share an event id so
Meta counts each action once. These events contain no email, Telegram id,
messages, card details, or VPN activity.
We do not sell your data. Meta measurement runs only while the feature is
configured, and server Purchase is sent only for an attributed website order.
How long we keep it
Account and subscription data for as long as your account exists. Referral
relationships, anonymized unique-open records, qualification timestamps,
aggregate byte thresholds and reward
records follow that account retention period so we can prevent duplicate
rewards and resolve support questions. Browser referral cookies contain the
public code and a random visitor value and expire after 30 days; a Whop
affiliate attribution expires after at most 30 days unless it is used for
checkout. Payment records are kept
for as long as we are required to keep them. Meta browser/click
identifiers expire after at most seven days. Server-side copies used for bot
Start and website Purchase are erased after Meta accepts the event; only the
attribution record remains.
Ask us at @adelyaachkaaa to delete your account and we will, keeping only what the
law requires.
Your choices
Ask us at @adelyaachkaaa for a copy of what we hold about you, to correct it,
or to delete it.
Changes
We may update this policy. The current version always lives at this
address, and the effective date above shows when it last changed.
Contact: @adelyaachkaaa on Telegram.