Privacy Policy

Last updated ·

In short

We sell a VPN subscription. To do that we need to know that your subscription exists, when it expires and — where your plan has limits — how much traffic it has used. We do not log the sites you visit, your DNS queries or the contents of your traffic, and we do not sell or disclose data about you to anyone, for any purpose. The website sets no cookies and runs no analytics. Everything below says exactly what that means, including the exceptions.

This document is published in six languages. The English version is the binding one; the others are provided for convenience.

1Who we are and what this covers

The GAEZO service is operated by [OPERATING ENTITY], a limited liability company organised under the laws of the State of Delaware, United States, with its registered office at [REGISTERED OFFICE ADDRESS], Wilmington, Delaware 19801, United States. In this policy, "GAEZO", "we", "us" and "our" mean that company, and "you" means the person or organisation using the service.

This policy covers everything we operate: the website, the Telegram bot through which subscriptions are bought and configured, the VPN service itself, the client applications we publish for Windows, macOS, Linux, iOS and Android, and the administration dashboard supplied to business customers. We refer to all of it together as the Service.

It does not cover the websites, applications and services you reach through the tunnel — they have their own policies and we have no visibility into or control over them. Nor does it cover Telegram itself, which is operated by Telegram Messenger Inc. under its own terms; when you talk to our bot, Telegram is processing that conversation as well as us.

[OPERATING ENTITY] is the data controller for the processing described here, except where clause 4 says otherwise for business team accounts. Questions about this policy go to [email protected].

2Our commitments

These five statements are the substance of this policy. Everything after them is detail, qualification and honesty about the edges.

  • We do not sell, rent, trade or otherwise disclose to any third party any data about you or your use of the Service, for any purpose.
  • We do not inspect, record or analyse the content of your internet traffic.
  • We do not use your traffic, or anything derived from it, for advertising, profiling, recommendation or the training of any model.
  • We do not operate — and do not permit on our infrastructure — any advertising network, tracking pixel, fingerprinting technique or third-party analytics service.
  • We collect the minimum needed to sell you a subscription and keep it working, and we delete it on the schedule set out in clause 9.

These are binding commitments, not aspirations. If any one of them ever ceases to be true, this document changes before the practice does — not after, and not quietly.

3What we do not collect

"No logs" has been used by the industry to mean so many different things that it has stopped carrying information. Providers have said it while keeping connection metadata, and at least one said it while holding records it later handed to investigators. So instead of the phrase, here is the list.

We do not keep any of the following

  • Browsing history — the websites, pages, applications or services you reach through the tunnel.
  • DNS queries. The DNS logging facility of our tunnel software ships disabled in our configuration and stays disabled.
  • Connection access logs. Our tunnel software's access log is configured to none, so per-connection records are never written in the first place.
  • The contents of your traffic, in any form, whether encrypted or not.
  • Any record associating a subscription with a destination it reached, at any time, for any duration.
  • Your name, postal address, date of birth or government identification. We never ask for them, and you should not send them to us.
  • Advertising identifiers, device fingerprints, contacts, photos, messages, calendars, health data, biometrics or precise device location gathered in the background.

This list is the strongest protection in this document, and it is stronger than a promise to resist. A record that was never created cannot be leaked, sold, subpoenaed or seized. Clause 12 depends entirely on this clause being true.

4What we process to run your subscription

Your subscription record

For every subscription we hold a record containing: a subscription identifier and a label you or we choose for it; which plan it is on and which exit region it uses; whether it is active or disabled; its expiry date; its traffic allowance and simultaneous-device limit, if the plan has them; an optional group label used by business customers to organise seats; and the dates the record was created and last changed.

None of this requires your identity, and we do not attach one to it.

Telegram

Purchase, configuration and support all happen in our Telegram bot. So we hold the Telegram user identifier of the account that talks to it, in order to link a conversation to a subscription, together with whatever you choose to write to us. Your Telegram username, display name and profile photo are visible to the bot because Telegram makes them visible; we do not store them beyond what is needed to answer you.

Traffic counters

Where a plan carries a traffic allowance, our servers keep two running byte totals per subscription per node — one uploaded, one downloaded — so the allowance can be enforced and so you can see what you have used. They are totals, not a history: they record how much, never what, where or when. They are reset each billing period and are not archived.

Simultaneous-device limits

Where a plan limits how many devices may be connected at once, that limit has to be counted, and counting means briefly knowing how many distinct addresses are connected. Our servers read the currently connected source addresses from the tunnel software's live statistics interface — not from an access log, which is disabled — record each with a timestamp so it can be counted, and discard it automatically thirty minutes after it was observed.

That observation is never associated with any destination, is never written to a log file, and does not survive the thirty-minute window. On a plan with no device limit, this does not happen at all.

This is the one place where a source IP address touches our systems in a form that persists for more than an instant, and we would rather name it here than let you discover it. Thirty minutes, no destinations, no archive.

Payments

We do not process card details ourselves and never see or store a full card number. Where you pay by card or a local payment rail, the payment provider handles the transaction and returns to us a confirmation, a reference and the amount. Where you pay in a stablecoin, we hold the receiving address and the transaction hash — both of which are public on the blockchain by design, and neither of which we can delete, because we did not publish them.

Support correspondence

If you write to us, we keep what you wrote for as long as clause 9 allows, so that a second message can be understood in the light of the first. Please do not send us information you do not want us to have.

Business team accounts

Where an organisation buys a plan and issues seats to its people, that organisation decides who gets a seat and what the seats are labelled. In data-protection terms it is the controller for its team members and we are its processor, acting on its instructions. A data processing agreement is available on request. Team members with questions about how their own employer configured their seat should ask their employer; we cannot answer for them.

5The website

The website sets no cookies, and writes nothing to local storage or session storage — not a preference, not an identifier, not a counter. It used to keep one thing there, the light-or-dark appearance you had chosen; the page has one appearance now, so there is nothing left to remember. Opened inside Telegram as our Mini App, Telegram's own code keeps its launch parameters in session storage: we only read them, and they never reach us. It loads no analytics, no tag manager, no advertising or social pixel, no font or script from a third-party host, and no consent banner — because there is nothing to consent to. There is no opt-out here for the same reason there is no opt-in.

Ordinary server records

Like every server on the internet, the machines and network providers that serve the website necessarily see the address a request came from in order to answer it. We keep no application-level record associating a visitor with the pages they viewed. Short-lived operational and security records may exist at the infrastructure layer; they are not used to build any profile and are not combined with anything else in this policy.

The connection readout

The readout in the page header tells you where the internet currently sees your connection coming from — which is the one thing a visitor to a VPN site most wants to check. To produce it, our server derives an approximate location, network operator and network type from the public address your request arrives on.

The result is cached for fifteen minutes against a deliberately truncated form of that address — the first 24 bits for IPv4, the first 48 for IPv6 — and never against the address itself. That truncation is the whole design: a cache keyed on complete addresses would be a log of who visited the site, which is precisely what we refuse to have. There is no database behind this feature and nothing is written to disk.

What else the page can see — and shows you

Opening the readout runs a short check inside your browser and puts the result on screen. It is there because an exit address is not the whole story. An HTTP proxy very often forwards your original address in a request header without mentioning it, and a proxy that carries web traffic but not UDP leaves your real address plainly visible to WebRTC. We look at both — because anything we can see here, every other site you visit can see too.

Concretely, three things. We read the forwarding headers that arrived with your request, which is data your own proxy chose to send us. We ask a STUN server run by Cloudflare what public address your browser's UDP path appears to come from; Cloudflare already terminates every connection you make to this site, so this tells them nothing they were not already handling. And we read the time zone and language list your browser publishes to every page it loads. Nothing is written down, nothing is combined with anything else, and every result is shown to you where it is found.

This runs when you open the readout, and not before. It is a diagnostic about your own setup, displayed only to you: a leak we can find is a leak anybody can find, and the point of the check is that you get to know about it.

Comparing with your own device (optional)

You can ask the page to compare that readout with where your device thinks it is. Nothing happens unless you press the button and then grant your browser's own permission prompt. Your precise coordinates stay inside the page and are never transmitted. A copy rounded to two decimal places — roughly 1.1 kilometres, enough to name a city and not enough to name a street — is sent once to our server so that a place name can be looked up, and is discarded as soon as the answer comes back.

Nothing about the location comparison is stored. Refusing the prompt, or never pressing the button, costs you nothing: the rest of the page behaves identically.

6Why we process it, and on what legal basis

We are a United States company and are not, on the face of it, subject to the European General Data Protection Regulation. We state legal bases in its vocabulary anyway, because it is the clearest language available for saying why a company believes it is entitled to hold something — and because clause 11 grants its rights to everyone regardless.

  • To provide the Service you purchased, including activating, configuring and maintaining your subscription — performance of our contract with you (GDPR Art. 6(1)(b)).
  • To enforce plan limits, keep the network working and prevent abuse of shared infrastructure — our legitimate interests, and those of every other customer on the same node (Art. 6(1)(f)).
  • To answer you when you contact us — performance of our contract and our legitimate interest in supporting our customers.
  • To take payment and to keep the accounting and tax records the law requires of us — contract and legal obligation (Art. 6(1)(c)).
  • To show the connection readout on the website — our legitimate interest in letting a visitor verify for themselves what a VPN site is claiming.
  • To compare that readout with your device's own location — your consent, given through your browser's permission prompt and withdrawable at any time by revoking it (Art. 6(1)(a)).

We carry out no automated decision-making that produces legal or similarly significant effects, and we do not profile you.

7Cookies, tracking, and Do Not Track

We use no cookies of any kind — not necessary ones, not preference ones, not analytics ones. Our client applications contain no advertising identifiers and no third-party analytics or attribution software.

California law requires us to state how we respond to browser Do Not Track signals. Our answer is that there is nothing for such a signal to switch off: we do not track you across sites or over time, on our own property or anyone else's, so a Do Not Track or Global Privacy Control signal changes nothing about our behaviour, because our behaviour already matches what those signals ask for.

8Who else is involved

We rely on a deliberately small number of outside parties. None of them receives your traffic, your browsing history, or anything derived from either — because, per clause 3, those records do not exist for us to pass on.

  • Hosting and network providers, who supply the servers and bandwidth the exit nodes run on. They carry your traffic in the same sense that any transit provider does, and they cannot read it: it is encrypted end to end between your device and the exit.
  • Payment providers and local payment rails, who process card and bank transactions and return only a confirmation and a reference to us. Where you pay in a stablecoin there is no processor at all, and the transaction is public on the relevant blockchain, permanently and beyond anyone's control.
  • Telegram Messenger Inc., whose platform our bot runs on. Your relationship with Telegram is governed by Telegram's own privacy policy, not this one.
  • Geolocation data sources used only by the website readout: ipwho.is and GeoJS; Cloudflare, which already terminates your connection to this site, states its own view of your country in a request header, and whose STUN server answers the browser check described above; the RIPE NCC's RIPEstat service and the RDAP registries operated by IANA and the regional internet registries; and, where enabled, a MaxMind GeoLite2 database queried on our own server so that no address leaves our infrastructure, ipinfo.io and ipregistry. Each of those receives only the single address being looked up.
  • The OpenStreetMap Foundation's Nominatim service, used only for the optional device comparison, and only ever sent a coordinate already rounded to roughly 1.1 kilometres.

We may also disclose information to professional advisers under a duty of confidence, or to an acquirer in connection with a merger or sale of the business — in which case the acquirer takes this policy with the data, and we will say so publicly before the transfer takes effect.

We do not sell, share or otherwise make available personal information to any third party for advertising, cross-context behavioural advertising, or any similar purpose.

9How long we keep things

  • Subscription record — for as long as the subscription is active, and for up to 90 days after it lapses so that it can be restored without you starting again. Then deleted.
  • Traffic counters — reset each billing period, and not archived.
  • Source addresses observed for simultaneous-device limits — 30 minutes from observation, then automatically discarded.
  • Website connection-readout cache — 15 minutes, keyed to a truncated network prefix rather than to an address.
  • Device coordinates from the optional comparison — not retained at all.
  • Support correspondence — up to 12 months from the last message in the conversation.
  • Payment and accounting records — for the period that applicable tax and accounting law requires us to keep them, which in the United States is generally seven years. These are held by us and by our payment providers, and we cannot delete them earlier at your request.
  • Blockchain transactions — permanent and public, recorded by the network rather than by us. Neither we nor you can erase them.

Where a period is expressed as a maximum, we delete earlier if the reason for holding the data has ended. Where the law obliges us to preserve something in connection with a specific legal claim or investigation, we keep that item for as long as the obligation lasts and no longer.

10Where the data is

We are a United States company, and the Service is delivered from servers in several countries — necessarily so, because an exit location in another country is the product. Your subscription record may therefore be processed in the United States and in the countries where the nodes you use are hosted.

Wherever it is processed, the same commitments apply. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland in circumstances requiring a safeguard, we rely on the European Commission's Standard Contractual Clauses or an equivalent mechanism; you can request a copy of the relevant terms from us at the address in clause 16.

11Your rights

We grant every right below to every user, wherever you live. Not because the law in each of our markets requires it — in most of them it does not — but because a right that depends on which passport you hold is not a right.

  • To know what we hold about you and to receive a copy of it.
  • To have inaccurate information corrected.
  • To have information deleted, subject only to the retention periods the law imposes on us in clause 9.
  • To have processing restricted while a dispute about it is resolved.
  • To receive the data you gave us in a portable, machine-readable form.
  • To object to processing we carry out on the basis of legitimate interests.
  • To withdraw consent at any time, without affecting anything done before you withdrew it.
  • To use an authorised agent to make a request on your behalf, and to be treated no differently for having made one.
  • If you are in the European Economic Area or the United Kingdom, to complain to your national supervisory authority. We would rather you came to us first, but that choice is yours and we will not obstruct it.

We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act, and we have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under sixteen.

One caveat, and it works in your favour

Most of what we hold is deliberately not tied to a real-world identity. We never asked for your name, and a subscription identifier does not tell us who you are. So there will be cases where we genuinely cannot connect a request to an account — and where that happens, we may be unable to act on it.

We will not use that as a convenient excuse. We will tell you plainly that we cannot identify the record, explain what would let us proceed, and we will never demand more identification than the request actually needs. In particular, we will not ask you to send us identity documents in order to exercise a right over data we hold no identity for.

To exercise any of these rights, write to [email protected] or message the bot. We will respond within 30 days, and will tell you if we need longer and why.

We respond to valid, binding legal process issued by a court or authority with actual jurisdiction over us. We do not hand over information on an informal request, a police email, or a demand from an authority with no jurisdiction over us, however officially it is worded.

What we can produce is bounded by what exists. We cannot produce browsing history, DNS records, connection logs or traffic content, because we do not have them and never did. No order can compel the production of a record that was never created. This is why clause 3 is written the way it is, and it is a far stronger protection than any promise to fight would be.

We will challenge process that is overbroad, defective, or that we believe to be unlawful, and we will produce the narrowest response that a valid order actually requires. Where we are legally permitted to do so, we will notify an affected user before disclosing anything, and where we are prohibited from notifying immediately we will notify as soon as the prohibition lapses.

We intend to publish a periodic transparency report recording the number of requests received, the number complied with, and the number refused or challenged. We have not published one yet, because the Service is new and there is nothing yet to report; we say this rather than implying a track record we do not have.

13Security

Traffic between your device and our exit nodes is encrypted, and we cannot read it. Our servers use full-disk encryption. Administrative access is limited to the people who need it, protected by multi-factor authentication, and reviewed. Credentials are not shared between staff or between systems.

If a breach occurs that is likely to result in a risk to you, we will notify you and any relevant authority without undue delay, and in any event within 72 hours of becoming aware of it where that standard applies to us.

No system is perfectly secure, and we do not claim otherwise. A VPN protects traffic in transit; it does not protect a device that has already been compromised, an account whose password has been reused, or a service you voluntarily log into with your real name.

14Children

The Service is not directed to children and is sold only to people aged 18 or over, as the Terms of Service require. We do not knowingly collect personal information from anyone under 13.

If we learn that we hold information about a child under 13, we delete it. A parent or guardian who believes we hold such information should contact [email protected] and we will act promptly.

15Changes to this policy

We may update this policy — to describe a new feature, to correct something, or because the law changes. The date at the top of this document is the date of the version you are reading, and it is the version that governs.

Where a change materially reduces the protections described here, we will say so prominently on the website and through the bot before it takes effect, rather than changing the date and hoping nobody looks. We keep previous versions and will provide one on request.

16How to contact us

[OPERATING ENTITY], [REGISTERED OFFICE ADDRESS], Wilmington, Delaware 19801, United States.

17Language

This policy is published in English, Russian, Chinese, Persian, Arabic and Burmese. The English version is the binding one. The other versions are provided so that you can read this in your own language, and in the event of any inconsistency the English text prevails.

GAEZO VPN — Works When Other VPNs Get Blocked