Legal
Privacy Policy
We do not log your browsing activity, DNS queries or traffic destinations. This policy lists field by field what we actually collect, why, how long we keep it, who it goes to, and how you exercise your rights.
1. Scope and controller
This policy is issued by TP VPN LLC (registered office: registered addresspending, "we", "us"). It covers the tpvpn.com website, the TP VPN client apps, and the VPN node network those apps connect to (together, the "Service").
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we act as the data controller for the processing described here. EU/UK representative, where applicable: DPO / EU representativepending.
2. What we never collect (no-log, defined in engineering terms)
"No logs" is an overused phrase, so we state it as a checkable engineering constraint. The fields below do not exist in our database schema, which means they cannot be queried, exported or handed over:
- Browsing activity — which sites, apps or pages you open is not collected, inferred or stored.
- DNS queries — we do not record which domains you resolve.
- Destinations inside the tunnel — destination IPs, hostnames and TLS SNI are never collected. Nodes forward encrypted packets and perform no content inspection (no DPI).
- Your raw client IP address — it is never written to any table. See the next section.
- Contacts, SMS, photos, precise location — the apps do not request these permissions, so there is nothing to collect.
- Advertising or analytics profiles — we run no ad business and give no data to ad networks.
clientIp or dstAddr to the session or log tables, the build fails. The policy and the data model are not allowed to drift apart.3. About your IP address
To establish a connection the network protocol must deliver your IP address to our edge — any provider claiming to "never see your IP" is being dishonest. What we can commit to is what happens next:
- On connect, your IP is resolved to a country and city in memory only (a GeoIP lookup).
- The result —
entryCountry/entryCity— is stored on the session record, and is used for routing, capacity planning and the "current entry point" shown in the app. - The raw address is discarded when the request finishes. It is never written to the database, to log files, or to backups.
Two clarifications, so this is not read as a stronger promise than it is:
- Edge infrastructure processes your IP in transit. Completing a TLS handshake, routing packets and absorbing DDoS traffic all require it. This is transient transport processing and produces no durable record tied to your account.
- Login and API rate limiting uses short-lived counters. To stop credential stuffing and brute force we keep in-memory counters that expire within minutes. They are not written to the database, are not linked to your account profile, and disappear when the window closes.
4. What we actually collect
The table below lists everything we hold. It maps one-to-one onto our data model: if a field is not listed, we do not have it.
| Category | Data items | Why we need it |
|---|---|---|
| Account identity | The identifier issued by our identity provider (Privy DID); your @handle and display name; your email address (if you sign in with email or left one as a contact); a masked form of other login identifiers (a truncated wallet address, a Telegram username); country of registration; account status | To recognise your account, restore access, send billing and security notices, and attach entitlements to the right person |
| Devices | Device name, platform (iOS/Android/Windows/macOS/Linux), model, OS version, app version, your WireGuard public key, last-active time | To issue tunnel configuration, enforce the device limit of your plan, and let you review and remove devices |
| Sessions and connections | Start/end time, node connected to, protocol, total bytes up and down, handshake latency, entry country and city, exit country; connect / disconnect / auth-failure / kicked events | To show connection state, apply the fair-use threshold, troubleshoot, and plan node capacity |
| Traffic metering | Hourly aggregates of bytes up and down (by account, node and protocol) | Fair-use accounting and capacity planning. Byte counts only — no destination information whatsoever |
| Orders and payments | Order id, plan, amount and currency, payment channel, the channel-side transaction reference, payment and refund status | To complete the transaction, grant entitlements, process refunds, and meet tax and accounting retention duties |
| Referrals and promotions | The invite relationship (who invited whom), reward days granted and their status; discount or redemption codes you have used | To pay out referral rewards, apply discounts and prevent reward farming. Only the account-to-account relationship is recorded — not which page you came from, and with no cross-site tracking |
| Support tickets | Subject, category, the messages exchanged, and anything you choose to include | To answer you. Please never paste passwords, private keys or seed phrases into a ticket |
| Risk and abuse | Risk event type (e.g. abnormal device count, chargeback, credential stuffing, traffic abuse), a score, and an evidence summary | To protect accounts and the network. Evidence summaries contain metadata and third-party complaints only — never your traffic content or destinations |
| Administrative audit trail | A record of our staff actions: admin identifier, action, target, before/after snapshot, staff-side IP | Internal accountability. This constrains us, not you: any staff access to or change of your account is recorded, append-only and immutable |
About your encryption keys
Your WireGuard key pair is generated on your device. The private key never leaves the device and we have never held a copy — only the public key is registered with us. You can reset your keys from the app at any time.
Cookies and local storage on this site
tpvpn.com uses no advertising cookies and loads no cross-site tracking scripts or third-party analytics SDKs. Everything this site stores in your browser is listed below — the table is exhaustive:
| Name | Type | Contents | Lifetime | Sent to us? |
|---|---|---|---|---|
tpvpn.lang | Cookie (first-party) | The interface language you chose (en / zh / zh-hk / es / hi), written only after you switch language | 1 year | Yes — sent with requests, used only to serve pages in your language |
tpvpn.theme | Local storage | Light/dark theme preference | Until you clear site data | No |
tpvpn.session | Local storage | Your session token after you sign in | Until you sign out or clear site data | Yes — only while signed in, sent with your own requests to prove it is you |
tpvpn_ref / tpvpn.ref | Cookie (first-party) + local storage | The inviter's public @handle and a timestamp. A public username and nothing else — no identity data | 30 days, or cleared immediately once an order completes | Yes — the cookie is sent automatically with requests to this site, so the referral reward is credited to the right inviter |
tpvpn.checkout | Session storage | A random idempotency key generated at checkout so the same order is never created twice; contains no identity data | Cleared when you close the browser tab | Yes — sent only with the order request you initiate (the Idempotency-Key header) |
__stripe_mid / __stripe_sid | Cookie (first-party, set by Stripe.js, loaded only on the checkout page) | Random device and session identifiers Stripe uses to detect fraudulent payments | 1 year / 30 minutes | No — sent only to our payment processor Stripe, see the processor table in §7 |
privy:token / privy:refresh_token / privy:id_token | Local storage (set by the Privy SDK, loaded only on the account, checkout and redeem pages) | Access, refresh and identity tokens issued by Privy | The access token is short-lived; the refresh token lasts until you sign out or clear site data | The access token is sent to us to establish your session; the others go only to our identity provider Privy |
The referral item is written only if you arrive through someone's invite link (tpvpn.com/@username). Visiting the site directly never creates it. It is first-party, readable by no third party, and is not used to advertise to you or track you across sites — its only function is to credit the person who invited you with the reward days they are owed.
You can remove all of the above at any time by clearing site data. Doing so only means signing in again and losing any referral attribution; it does not affect your subscription entitlements. If you would rather no attribution be recorded, visit the site directly instead of via an invite link.
5. Purposes and lawful bases
| Purpose | Data involved | GDPR lawful basis |
|---|---|---|
| Delivering the Service: accounts, tunnel configuration, routing, device management | Account identity, devices, sessions | Performance of a contract (Art. 6(1)(b)) |
| Billing, granting and revoking entitlements, refunds | Orders and payments, account identity | Performance of a contract (Art. 6(1)(b)) |
| Fair-use accounting and network capacity planning | Traffic metering (byte totals) | Contract and legitimate interests (Art. 6(1)(b), 6(1)(f)) |
| Preventing abuse, fraud and account takeover; enforcing the Acceptable Use Policy | Risk and abuse records, connection events, devices | Legitimate interests (Art. 6(1)(f)): protecting the network and other users |
| Paying referral rewards and applying discounts | Referrals and promotions, orders and payments | Performance of a contract (Art. 6(1)(b)): the reward is part of what both you and your inviter are owed |
| Customer support | Support tickets, account identity | Performance of a contract (Art. 6(1)(b)) |
| Financial and tax records, responding to valid legal process | Orders and payments, audit records | Legal obligation (Art. 6(1)(c)) |
| Optional crash and performance diagnostics, product update emails | Crash traces (with personal data collection disabled), email address | Consent (Art. 6(1)(a)), withdrawable at any time |
6. Retention periods
The table below is the retention limit we set for each category of data. Expired data is deleted automatically by scheduled purge jobs — you do not need to ask:
| Data | Retention | Notes |
|---|---|---|
| Connection event log (connect / disconnect / auth failure / kick) | 30 days | The minimum window needed for troubleshooting and abuse investigation |
| Session records (no raw IP) | 90 days | Supports usage disputes, device management and billing questions |
| Hourly traffic aggregates (byte counts only) | 13 months | Year-over-year capacity planning; contains no destination information |
| Administrative audit log | 3 years | Staff accountability record; append-only and immutable |
| Account and device records | For as long as the account exists; then as below | See "Account deletion" |
| Order, payment and refund records | 7 years after the transaction (or longer where tax law requires) | A statutory financial retention duty; survives account deletion |
| Support tickets | 24 months after closure | Lets us trace recurring issues; you may ask us to delete them sooner |
Account deletion
You can start deletion from the web at any time: go to the account deletion page. We execute the deletion after a 30-day cooling-off period (you can cancel during it). Profile, devices, sessions and tickets are then erased, and residual copies on backup media disappear within 90 days as backups rotate. Only two things survive: transaction records inside their statutory retention period (minimised so they no longer identify you beyond what the law requires), and an irreversible hash used to stop a banned account from immediately re-registering.
7. Processors and disclosure
We let the providers below touch data only to the extent necessary, and each is bound by a data processing agreement requiring them to act only on our instructions:
| Type of provider | Data they see | Notes |
|---|---|---|
| Identity (Privy) | Your login credentials (email address, wallet address, Apple/Telegram account, passkey credential) | Privy holds and verifies the credentials; we never touch a password, private key or passkey credential. On our side we keep the identifier it issues, your email address, and masked display values for the other login methods |
| Payments (Stripe, Paddle, Apple In-App Purchase, Google Play Billing, crypto processors) | Name/billing details, payment credentials, amounts | We never see full card numbers. The channel returns only a transaction reference and a status |
| Infrastructure (data centres, cloud providers, CDN, DDoS protection) | Connection metadata in transit | Necessary to move packets and absorb attacks; produces no durable per-user record for us |
| Transactional email delivery | Your email address and message contents (codes, ticket replies, billing notices) | Used only for delivery; never resold for marketing |
Other disclosures
- Valid legal process — see "Law enforcement and third-party requests" below.
- Change of control — in a merger, acquisition or asset sale your data may transfer as part of the transaction. We will notify you in-app and by email before it takes effect, the acquirer will be bound by terms no less protective than this policy, and you can delete your account beforehand.
- With your consent — any disclosure beyond the above requires your explicit consent.
8. International transfers
Our node network spans multiple countries, and our control plane and backups may sit outside your country. When data leaves the EEA, the UK or Switzerland we rely on one of: an adequacy decision of the European Commission; or Standard Contractual Clauses (plus the UK Addendum) with the recipient, supplemented where needed by measures such as encryption and access controls.
Note also: whichever country's node you pick is the country your traffic transits. That is how a VPN works, and it stays under your control — you can switch to a node in another country at any time.
9. Security measures
- Tunnel encryption uses WireGuard (Noise protocol framework, ChaCha20-Poly1305); key pairs are generated on your device.
- The site and control plane run TLS 1.3 with HSTS; nodes authenticate to the control plane with rotatable credentials.
- Client credentials are stored in the system Keychain / Keystore, never in plaintext config files.
- Internal access follows least privilege: role-scoped permissions, mandatory confirmation on sensitive actions, every write recorded in the audit log, and enforced two-factor authentication for the admin console.
- Identifiers such as email addresses are masked by default in our internal tools; revealing a full value requires elevated permission and is itself audited.
No system is perfectly secure. If a security incident affects your personal data we will notify the competent supervisory authority within the deadline set by applicable law, and notify you directly where the incident is likely to result in a high risk to you.
10. Your rights (GDPR / UK GDPR)
- Access
- Obtain a copy of the personal data we hold about you.
- Rectification
- Correct inaccurate or incomplete data; most profile fields can be edited in the app directly.
- Erasure
- Delete your data. You can start this yourself from the account deletion page.
- Restriction
- Ask us to pause processing while a dispute is resolved.
- Portability
- Receive the data you provided to us in a structured, commonly used, machine-readable format (JSON).
- Objection
- Object to processing based on legitimate interests; we will re-assess or stop unless there are compelling legitimate grounds.
- Withdraw consent
- Withdraw consent at any time (e.g. crash diagnostics, product emails), without affecting processing already carried out.
- Complaint
- Lodge a complaint with the data protection authority of your habitual residence, place of work, or where the alleged infringement occurred.
How to exercise them
Email legal@tpvpn.com or support@tpvpn.com with your @handle and what you need. To stop someone impersonating you we will ask you to complete one verification through a login method already linked to the account — we do not ask you to send identity documents. We respond within one month; for complex or numerous requests this may extend by two further months, and we will tell you why within the first month. Exercising your rights is free. For manifestly unfounded or excessive repeat requests we may charge a reasonable fee or decline, giving reasons.
11. U.S. state privacy rights (CCPA/CPRA and others)
If you are a California resident — or live in another state with a comprehensive privacy law in force (Virginia, Colorado, Connecticut, Utah, Texas and others) — you have the right to know which categories of personal information we collect, use and disclose, to delete, to correct, and to non-discrimination (exercising a right never results in higher prices or degraded service).
| CCPA category | Do we collect it? | Example |
|---|---|---|
| Identifiers | Yes | @handle, the identifier issued by our identity provider, email address |
| Commercial information | Yes | Order records, subscription status |
| Internet or network activity | Partly | Only session metadata and byte totals; never browsing history, search history, or interactions with websites |
| Geolocation | Coarse only | Country/city derived from IP in memory; no precise location |
| Inferences | Yes | A risk score used for abuse prevention |
| Sensitive personal information | No | No race, religion, health, precise location or contents of communications |
| Biometric, education, employment data | No | — |
We have not sold or "shared" (in the CPRA cross-context behavioural advertising sense) any personal information in the past 12 months, and we do not intend to. We do not collect sensitive personal information to infer characteristics. There is therefore no "Do Not Sell or Share" opt-out to offer — there is nothing to opt out of. You may still email legal@tpvpn.com for written confirmation. An authorised agent may submit a request on your behalf with written permission.
12. Children's privacy
The Service is not directed to children. It may not be used by anyone under 13. In the EEA, the UK and other jurisdictions with a higher threshold, the minimum age is 16 (or the local age of consent for information society services). We do not knowingly collect personal information from anyone below these ages.
If you are a parent or guardian and believe a child has provided us with personal information without your consent, contact legal@tpvpn.com. On verification we will delete the account and the associated data.
13. Law enforcement and third-party requests
- We respond only to legal process that is served in our jurisdiction of incorporation and valid in both form and substance. Informal email demands are refused. Cross-border requests should come through formal channels such as an MLAT.
- We review the scope of every request, challenge demands that are overbroad or disproportionate, and produce only the minimum set the law requires.
- Where the law permits and no valid gag order applies, we notify the affected user before disclosing, so they have an opportunity to seek relief.
14. Changes to this policy
The version, effective date and last-updated date are always shown at the top of this page. For material changes — a new data category, a longer retention period, a new recipient — we notify you in-app and by email at least 30 days before they take effect. Clarifications and typo fixes take effect immediately. Previous versions are available from our legal address on request.
15. Contact us
- Privacy and data rights: legal@tpvpn.com
- General support: support@tpvpn.com (typically within 24 hours during business hours)
- Abuse reports: abuse@tpvpn.com
- Registered entity and address: TP VPN LLC, registered addresspending
- EU/UK representative, where applicable: DPO / EU representativepending
Revision history
- v1.0.2 · 2026-09-02 · Section 4 storage table: added the checkout idempotency key and the keys written by Stripe.js and the Privy SDK
- v1.0.1 · 2026-09-02 · Added the Traditional Chinese (Hong Kong) translation