Privacy Policy
Effective date: August 27, 2026 · Last updated: August 27, 2026
The short version. We do not log what you do while connected: no browsing history, no traffic contents, no DNS queries, no record of which sites or services you reach. We keep a small amount of account data — your email address, your subscription status, and the devices signed in to your plan — because a paid service cannot exist without it.
The apps report a short, fixed list of events about the app itself — a connection started, a purchase failed, and so on — so we can fix what is broken. Section 3 lists every one of them.
We never sell your personal data, we never share it with advertisers or data brokers, and we do not use any data from the VPN service for advertising, profiling or tracking you across other apps and websites.
- Who we are
- Our no-log commitment
- What we collect
- Our website
- How we use data and legal bases
- No ads, no tracking, no data sales
- Who we share data with
- International transfers
- How long we keep data
- Deleting your account and data
- Your privacy rights
- Children
- Security
- Legal and government requests
- Changes to this policy
- Contact us
1. Who we are
Atomic VPN is operated by AtomicMail Systems OÜ, a company registered in Estonia at Harju maakond, Tallinn, Kesklinna linnaosa, Harju tn 3 (“Atomic VPN”, “we”, “us”). We are the data controller for the personal data described here.
This policy covers everything we offer under the Atomic VPN name: the VPN service itself, our applications for iOS, iPadOS, macOS, Android, Windows and Linux, our browser extensions, our account pages at auth.atomicvpn.io, and the website at atomicvpn.io. It explains what we collect, why, who else can see it, how long we keep it, and the choices you have.
Using the service is also subject to our Terms of Use, which this policy forms part of. You can reach us about anything in this policy at [email protected].
2. Our no-log commitment
While you are connected to Atomic VPN, we do not collect, monitor, record or store:
- your browsing or download history, or any other record of the sites, apps and services you reach;
- the contents of your traffic;
- DNS queries you make through our resolvers;
- your originating IP address, or the VPN IP address you were given;
- connection logs on the network side — no record of who connected, from where, when or for how long;
- per-user bandwidth records.
Routing your traffic requires your IP address to pass through our systems for as long as the connection lasts — that is how any internet connection works. We do not write it to a log, do not attach it to your account, and do not keep it after the connection ends.
Our apps do report a short list of product-analytics events, described in section 3 — for example that a connection was started, which region and protocol you picked, and how long the session lasted. Those events say how the app was used; they never say what you did online, and they carry no IP address, no destination and no DNS data.
We do not sell, use, or disclose to third parties any data collected through the VPN service, for any purpose. That includes advertising, marketing, profiling, analytics and any form of resale — it is a binding commitment of this policy, not a preference we can change quietly.
Our applications create a VPN configuration on your device for one purpose only: to carry your own traffic to the server you chose. We do not use that configuration to inspect, filter, sell, monetise, redirect or inject anything into your traffic.
3. What we collect
Running a paid service requires a small account layer, which is kept separate from the network that carries your traffic. This is the complete list.
| Data | Why we have it | Where it comes from |
|---|---|---|
| Account data — your email address, an account identifier, your sign-in method, and (for password accounts) a cryptographic hash of your password, never the password itself. | To create and secure your account, sign you in, send verification and password-reset codes, and contact you about the service. | You, when you sign up. |
| Sign-in provider data — if you use Sign in with Apple or Google, we receive the email address and a stable user identifier from that provider. If you use Apple’s “Hide My Email”, we only ever see the private relay address. | To let you sign in without a separate password. | Apple or Google, at your instruction. |
| Device (seat) data — an identifier generated by the app for that installation, the platform it runs on, a device label built from the device model and operating system version (for example “iPhone 15 / iOS 18.2”), and the time it was last seen. | To enforce the device limit included in your plan, and to let you see and sign out devices from your account page. | Our apps, when you sign in on a device. |
| Subscription and billing data — your plan, term, status, renewal date, and the transaction, receipt or invoice references from the payment provider. We never receive or store full card numbers. | To give you the plan you paid for, handle renewals and refunds, and meet accounting obligations. Purchases made in the apps are confirmed by validating the store receipt with Apple or Google. | Stripe, Apple or Google, depending on where you subscribed. |
| Product analytics — a fixed, published list of app events: the app being launched, onboarding finished, a server region chosen, a connection started, succeeded, failed or ended, the paywall opened, and a purchase started, completed or failed. The only details attached are the region you selected, the protocol, how long connecting or the session took, an error category, the plan and the store, plus your platform, app version, OS version and whether your plan is free or premium. | To see where the app is confusing or failing and to fix it. Events are tied to an opaque account identifier, never to your email. IP-based geolocation is switched off in our analytics, session and screen recording is switched off, and the app filters out any value that looks like an IP address, domain, URL or email before an event is sent. | Our apps, through our analytics provider. |
| Crash and diagnostic data — when the app fails, the error and stack trace, the app version, the operating system version and the device model. | To find and fix defects. Before a report leaves your device we strip the request, the user, the machine name and every field whose name suggests an address, host, server, credential or token, and we do not attach screenshots or a view hierarchy. | Our apps, at the moment of a failure, through our error-monitoring provider. |
| Support correspondence — the messages you send us and our replies, including anything you choose to include in them. | To answer you and keep a record of what was resolved. | You, when you contact support. |
| Notifications — on Android, the app shows a status notification while the tunnel is up, which is why it asks for notification permission. | To make it obvious when the VPN is running, as the platform requires. Nothing about the notification leaves your device, and we do not send remote push notifications at all — our apps contain no push messaging service and hold no push tokens. | Your device. |
| Data that stays on your device — your settings, the region you last used, and your sign-in tokens, which are held in the platform keychain or keystore. | To keep you signed in and to remember your preferences. This never leaves your device, and deleting the app deletes it. | Your device. |
| Aggregate service metrics — totals per server location such as overall load and throughput, with no user identifiers in them. | To keep servers from overloading and to plan capacity. | Our systems, in aggregate form only. |
| Technical request data — routine, short-lived records produced by our account API to stop abuse, such as failed sign-in attempts and rate-limit counters. | To protect accounts against credential stuffing and automated abuse. | Our account API. It is never joined to VPN activity, because there is none to join it to. |
If you subscribe inside our iOS, iPadOS or Android app, Apple or Google takes the payment, not us. They do not pass us your payment details; we receive the subscription status and a transaction identifier so we can unlock your plan. Their own privacy policies govern what they collect. Subscriptions bought in a store are also cancelled in that store — see section 10.
4. Our website
The landing page shows you your own IP address, approximate location and internet provider. That lookup happens in your browser through a geolocation service, is displayed only to you, and is not stored by us. It exists to show what any site you visit already sees when you are not connected.
The website and the sign-in pages use Google Analytics to count visits and see which pages people reach — how many, from where, on what kind of device. This is measurement of the website only: it never touches the VPN network and it cannot see your traffic. On the sign-in pages we deliberately report the page path alone and strip the rest of the address, so the one-time codes and the email address that appear in those links are never sent to Google.
We use cookies and similar browser storage for two things: keeping you signed in on the account pages, which is strictly necessary and cannot be switched off without breaking sign-in; and the analytics described above. Blocking analytics cookies, or using any tracker blocker, does not affect the service in any way. Where your browser or extension sends a Global Privacy Control signal, we treat it as an opt-out of analytics.
5. How we use data and legal bases
We use the data in section 3 only for the purposes below. Where the GDPR applies, each purpose has a legal basis:
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account, signing you in, and providing the VPN service on your devices. | Performance of a contract — Art. 6(1)(b). |
| Taking payment, handling renewals, refunds and the device limit of your plan. | Performance of a contract — Art. 6(1)(b). |
| Answering your support requests. | Performance of a contract, or our legitimate interest in helping users — Art. 6(1)(b) and 6(1)(f). |
| Protecting accounts and the service against fraud and abuse. | Legitimate interests — Art. 6(1)(f). |
| Fixing defects using crash and diagnostic data. | Legitimate interests — Art. 6(1)(f). |
| Understanding how the app is used, through the analytics events listed in section 3. | Legitimate interests in improving our own product — Art. 6(1)(f). You can object at any time, see section 11. |
| Sending email notices about your subscription, security or service changes. | Performance of a contract — Art. 6(1)(b). |
| Website analytics. | Consent, where consent is required — Art. 6(1)(a). |
| Keeping invoicing records and answering lawful requests. | Legal obligation — Art. 6(1)(c). |
We do not use your data to build profiles about you, and we do not make decisions about you by automated means that produce legal or similarly significant effects.
6. No ads, no tracking, no data sales
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law and comparable US state laws. We have not done so in the previous twelve months.
- We do not show advertising in our apps or on our website, and we do not use advertising, attribution or cross-app tracking SDKs in our applications.
- We do not track you across other companies’ apps or websites, and we do not link the data we hold with data from data brokers. Our iOS apps do not ask for permission to track, because we have no use for it.
- We do not record your screen or replay your sessions in the apps or on the website.
- We do not use VPN data for any purpose beyond carrying your connection — see section 2.
7. Who we share data with
We share the minimum necessary with a small set of service providers, each bound by a written data-processing agreement and permitted to use the data only to perform its task for us:
- Payment and app-store providers — Stripe for card payments on the web; Apple and Google for purchases made inside our apps. They handle payment details as independent controllers under their own policies.
- Sign-in providers — Apple and Google, only if you choose to sign in with them.
- Email delivery — to send verification codes, receipts and account notices.
- Product analytics — PostHog, which receives the app events listed in section 3 on our behalf and processes them only for us.
- Crash and error monitoring — Sentry, which receives the scrubbed crash reports described in section 3 on our behalf and processes them only for us.
- Hosting, network and security infrastructure providers — the underlying infrastructure the service runs on. They have no access to account contents and receive no record of your VPN activity, because none is produced.
- Website analytics — Google Analytics, for the website statistics described in section 4. It receives website addresses and standard browser data, never VPN activity.
- Professional advisers and authorities — accountants and lawyers where required, and public authorities only where legally compelled, as described in section 14.
If the company is ever involved in a merger, acquisition or sale of assets, personal data may transfer to the successor, which will remain bound by this policy or a policy no less protective; we will tell you before that happens. An up-to-date list of our processors is available from [email protected] on request.
8. International transfers
We are established in Estonia, in the European Union, and your account data is processed there. Some of the providers listed above operate outside the European Economic Area, including in the United States — our analytics and crash-monitoring providers among them. Where that happens, the transfer is covered by an adequacy decision of the European Commission, or by the European Commission’s Standard Contractual Clauses together with additional safeguards where needed. You can ask us for a copy of the safeguards that apply to a specific transfer.
9. How long we keep data
- VPN activity — never stored, so there is nothing to retain, produce or delete.
- Account data — kept while your account exists, then erased within 30 days of deletion.
- Device (seat) records — kept while the device is signed in, and removed when you sign it out or delete your account.
- Invoicing records — kept for 7 years as required by Estonian accounting law. These contain billing details only, never usage data, and they survive account deletion because the law requires it.
- Support correspondence — up to 24 months, or sooner on request.
- Product analytics events — up to 12 months, after which they are deleted or kept only as counts that identify no one.
- Crash and diagnostic data — up to 90 days.
- Technical request data — short-lived, ordinarily days rather than months, and no longer than 30 days.
- Website analytics — retained by Google Analytics for a maximum of 14 months.
10. Deleting your account and data
You can delete your account yourself, at any time, without contacting us:
- In the app — open Settings, then Account, then Delete account, where your version of the app offers it.
- On the web — sign in at auth.atomicvpn.io and use Delete account on your account page.
- By email — write to [email protected] from your account address and we will do it for you.
Deletion cuts off access immediately and removes your account, your device records and your support history within 30 days. The only data that remains afterwards is the invoicing record described in section 9, which Estonian accounting law obliges us to keep, and anonymous aggregate metrics that cannot be traced back to you.
Deleting your account does not by itself cancel a subscription bought through Apple or Google — those are managed by the store: in the App Store, through Settings › your name › Subscriptions; on Android, through Google Play › Subscriptions. Cancel there first if you want billing to stop. Card subscriptions taken on the web can be cancelled from your account page.
11. Your privacy rights
If you are in the EEA, the United Kingdom or Switzerland
You have the right to access your personal data, to correct it, to have it erased, to restrict or object to processing (including processing based on our legitimate interests), to receive a portable copy, and to withdraw consent at any time without affecting processing that already happened. You can lodge a complaint with your local supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee); in the UK, the Information Commissioner’s Office (ico.org.uk).
If you are in California
Under the CCPA as amended by the CPRA you may request to know the categories and specific pieces of personal information we collected about you, the sources, the purposes and the categories of recipients; request deletion; request correction; and opt out of sale or sharing. As stated in section 6, we do not sell or share personal information and do not use sensitive personal information to infer characteristics, so there is nothing to opt out of — but you may still exercise every other right. We will never discriminate against you for exercising them. In the twelve months before the date of this policy, we collected the categories described in section 3, namely identifiers, commercial information (your subscription), internet or network activity relating to our own website, and — only if you write to us — the contents of your messages.
If you are elsewhere in the United States
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana, have comparable rights of access, correction, deletion, portability and opt-out, along with a right to appeal a decision we make on a request. To appeal, reply to our response or write to us with “Appeal” in the subject line.
How to exercise your rights
To object to the product analytics described in section 3, or to exercise any other right, write to [email protected] from the email address on your account. We answer within 30 days, and will tell you if we need a permitted extension. We may need to verify that the request comes from you, which we do through your account email rather than by asking for extra identity documents. An authorised agent may submit a request on your behalf with written proof of authority. These rights are available to every user, wherever you live, and using them costs nothing and changes nothing about your service.
12. Children
Atomic VPN is not intended for children. You must be at least 13 years old to create an account — or 16, where local law sets that higher threshold, as it does in parts of the European Union. We do not knowingly collect personal data from children below that age. If you believe a child has created an account, write to [email protected] and we will delete the account and its data.
13. Security
VPN traffic is protected with modern, industry-standard protocols — such as WireGuard and IKEv2/IPsec — using current ciphers (ChaCha20-Poly1305, AES-256). You can see and change the protocol your app uses in its settings. Account data is encrypted in transit with TLS and encrypted at rest. Passwords are stored only as salted cryptographic hashes, and the sign-in tokens on your device are held in the platform keychain or keystore rather than in ordinary app storage. Access to production systems is restricted to a small number of authorised staff, protected by multi-factor authentication and reviewed regularly, and the account layer is kept separate from the network that carries your traffic.
No system is perfectly secure. If a breach ever affects your personal data, we will notify the competent supervisory authority within 72 hours where the law requires it, and notify you directly without undue delay where the breach is likely to present a high risk to you.
14. Legal and government requests
We respond only to legally valid requests properly served on an Estonian company under Estonian and European Union law. When we receive one, we check its validity, and we can only ever hand over what we actually hold — which for your VPN activity is nothing, because it is never recorded. We will notify you of a request concerning your account unless we are legally prohibited from doing so.
15. Changes to this policy
If we change this policy we will publish the new version on this page and update the date at the top. For material changes we will notify you by email, or in the app, before they take effect, and where the law requires consent we will ask for it. We will not weaken the no-log commitment in section 2. Earlier versions are available on request.
16. Contact us
Privacy questions and requests: [email protected]
Data controller: AtomicMail Systems OÜ, Harju maakond, Tallinn, Kesklinna linnaosa, Harju tn 3, Estonia.