Privacy Policy
This is the Privacy Policy for Win's VPN, published by Win's VPN Inc. It explains what data the Win's VPN app and website collect, why, who it is shared with, how long it is kept, and how to ask for it to be deleted.
Version 2026-08-20.v1
English is the controlling legal version of this Privacy Policy. Translations elsewhere on this site are provided for convenience only.
Privacy questions, data access requests, and account deletion requests: privacy@winsvpn.org or support@winsvpn.org.
Privacy Policy, Terms, Acceptable Use, and Liability
Company identity. Win's VPN Inc. operates the Win's VPN service. Win Empire LLC designs and builds the software, websites, scripts, and infrastructure used by the service. Win's VPN Inc. is a Florida nonprofit corporation filing, document number N26000008302, with business phone (424) 946-7876 and principal operations in Florida. The Internal Revenue Service determined, in a letter dated July 21, 2026, that Win's VPN Inc. is exempt from federal income tax under Internal Revenue Code Section 501(c)(3), with an effective date of exemption of June 11, 2026, and classified Win's VPN Inc. as a public charity under Section 509(a)(2) rather than a private foundation. Donors can deduct contributions under IRC Section 170, and Win's VPN Inc. is qualified to receive tax-deductible bequests, devises, transfers, or gifts under Section 2055, 2106, or 2522. Contributions are deductible to the extent allowed by law, deductibility depends on each donor's own circumstances, and Win's VPN Inc. does not provide tax advice. Win's VPN Inc. uses a December 31 accounting period and is required to file an annual Form 990-series return. Tax-exempt status is a determination about the organization; it is not an IRS review, approval, or endorsement of the Win's VPN service. Win's VPN is provided as a privacy, cybersecurity, and anti-censorship technology service. Availability, speed, routing, compatibility, server locations, and payment features may vary by region, network, censorship conditions, device, platform, and maintenance status.
Acceptance. By activating or using Win's VPN, you agree to use the service lawfully, not attack or abuse our services or infrastructure, and accept these Terms, the Verified No Log Policy, Acceptable Use Policy, Hold Harmless Agreement, Limitation of Liability, and Electronic Records consent. Account use requires clickwrap acceptance of the current legal terms inside the app before activation.
Payment terms. All payments, subscriptions, lifetime passes, tech-support passes, and donations are final and non-refundable to the maximum extent permitted by law. Canceling a subscription stops future renewals when supported by the payment provider, but it does not create a refund for past charges, lifetime access, donations, or already-issued account access. Card payments are processed by PayPal, and where cryptocurrency payment is offered and enabled it is processed through a BTCPay Server instance or a Monero wallet service as described below. Card data is entered on PayPal-hosted payment pages and handled by PayPal's PCI DSS compliant payment infrastructure, so Win's VPN does not store card numbers or process raw card data on our servers.
Verified No Log policy. Win's VPN does not collect or keep VPN activity logs. We do not log browsing history, DNS query history, traffic contents, raw VPN traffic, or user destination activity. The only limited service metadata we may store is the minimum needed to operate the service, such as account status, payment/referral status, legal acceptance evidence, security/abuse-prevention records, and privacy-preserving device-limit metadata for enforcing the three-device limit. Transient connection/session state is cleared when the VPN disconnects. Device-limit metadata is deleted or overwritten when the device is deactivated, replaced, or no longer needed for active account operation, and app-collected operational data that is no longer needed is deleted or anonymized within 90 days. The public website may use consent-based analytics and ad conversion tracking to measure page visits, downloads, demo views, payment-link clicks, and donation-link clicks; this website marketing tracking is separate from VPN tunnel traffic and does not track what users do through the VPN.
Privacy Policy and user data handling. Win's VPN may access, collect, transmit, or store only the user data needed for app and service functionality: account number, email address when provided for paid/manual accounts or support, app platform and version, device name/model, local split-tunneling package selections, device identifier bucket, source IP bucket, legal acceptance records, payment confirmation metadata received from PayPal, referral/account-validity metadata including which account referred a new account, prepaid redemption codes submitted on this website, security vulnerability reports submitted through our disclosure form, support messages the user sends, security/abuse-prevention events, diagnostics or crash information when provided by the platform, and website analytics or ad-conversion events when consented to on the website. Before the VPN connects, the app may retrieve a coarse public-IP location by querying Cloudflare's network-metadata endpoint (speed.cloudflare.com/meta) or a first-party Win's VPN edge endpoint, and may request a surrounding map from Apple Maps on Apple platforms or an OpenStreetMap-derived tile service on other platforms. The endpoint that derives the coarse location and the map provider necessarily receive the connection IP and ordinary request metadata used for that request; Win's VPN does not request device GPS for this feature or retain the returned IP, city, postal code, or map-view history. Win's VPN does not sell personal or sensitive user data.
Device or other ID disclosure. After the user accepts the bundled Privacy Policy, the app generates a random app-install identifier on the device and transmits it to Win's VPN with account or free-access identity and device details. The identifier is created locally on first run and is not derived from a device hardware identifier or an advertising identifier. On Android, Windows, and Linux it is kept in the app's private storage and reinstalling the app produces a new one; on Apple platforms it is kept in the device keychain and can survive a reinstall on the same device. It may be linked to the account for app functionality, account management, the three-device limit, fraud prevention, security, and abuse prevention. It is not used for advertising or tracking, sold, or shared for advertising. The hub protects the retained device-limit value; it is deleted or overwritten when the device is deactivated, replaced, or no longer needed.
Device cryptographic identity. In addition to the random install identifier, the app generates a long-lived cryptographic key pair on first use of each account and derives a public key from it. That public key is transmitted to Win's VPN with every account verification and configuration renewal request, not only at activation, and is used as one of the persistent identifiers that identifies this device to the service for connection provisioning, the three-device limit, and abuse prevention. It is a long-lived linkable identifier: it stays the same across app relaunches and reconnects and therefore functions as a repeatable device marker, not a one-time token. It is not derived from hardware identifiers or advertising identifiers. The private key itself never leaves the device; only the derived public key is transmitted. The key pair is stored locally in the app's private storage or the platform keychain, and the corresponding account-side record is deleted or overwritten when the device is deactivated, replaced, or no longer needed.
Gateway recovery and third-party connections. So that the app can still reach a working gateway when the usual DNS or CDN paths are censored, it also requests a small gateway-recovery file hosted on GitHub at raw.githubusercontent.com. GitHub necessarily receives the connection IP and ordinary request metadata for that request. The file can only select among gateways already built into the signed app, and no account number, device identifier, or other user data is sent with the request. This request is made only after the user accepts the bundled Privacy Policy.
Live public-IP display. After the user accepts the bundled Privacy Policy, and while
the app is disconnected, it may query the third-party service api.ipify.org to display the
device's current public IP address next to the connection status indicator. That service necessarily
receives the connection IP and ordinary request metadata for each such request; no account number,
device identifier, or other app data is sent. The request is made to improve the connection-status UI
and is never made while a VPN tunnel is active.
Speed-test endpoints. When the user starts the in-app speed test, the app measures
throughput by downloading from and uploading to third-party test servers. The measured hosts are
speed.cloudflare.com and cachefly.cachefly.net for every region, and, for
nodes in the western United States, losangeles.ca.speedtest.frontier.com,
lsanca-speedtest-ookla-02.st.charter.com, and
speedtest.lax2.sonic.net. Each server receives the connection IP, ordinary request
metadata, and the transferred measurement traffic; no account number, device identifier, or other app
data is included. These requests occur only while the user is running the speed test.
Abuse prevention and rate limiting. To throttle repeated failed attempts and protect accounts, gateways, and infrastructure, the service keeps short-lived request counters and security-event records keyed to a hashed form of the source IP address, device identifier, or account number rather than to the address itself. These records exist only for security, fraud prevention, abuse response, and device-limit enforcement. They are not used to profile a user, are not used for advertising, and never contain VPN traffic, browsing history, DNS query history, or destination activity.
Prepaid redemption codes. When a prepaid card code is entered on this website, the code is sent to Win's VPN so it can be checked and exchanged for account credentials. A redemption code is a bearer credential until it is used: it is submitted in the request body rather than in the page address, and each code can be redeemed only once. The card itself never carries an account number or PIN. A redeemed code is treated as account and payment provisioning data and is handled under the retention terms below.
Referral program data. Referral links take the form /referral/<code>. The code is read from the link address in the browser and passed to Win's VPN when a plan is purchased through it. If an account is created that way, the referring account is recorded against the referred account so the 20% account-validity bonus can be granted to both, and reversed if the funding payment is later refunded, cancelled, or reversed. Referral records are account-to-account only; they do not record what either person does through the VPN.
Security vulnerability reports. Our Vulnerability Disclosure Program page invites security researchers to report weaknesses. Submitting the form sends the name or handle, reply email address, one-line summary, the report detail, and an optional credit preference to our security team. This information is used to triage, reproduce, fix, and credit the reported issue, and to correspond with the reporter. Reporting is voluntary, and a researcher who does not want to be named can say so in the form. Our machine-readable security contact is published at /.well-known/security.txt.
Data use and sharing. User data is used to activate accounts, enforce the three-device limit, provide free and paid VPN access, operate split tunneling, process payments, donations, and prepaid redemptions, credit referrals, send account/service emails, document legal acceptance, detect abuse or attacks, triage and answer security vulnerability reports, answer support requests, improve reliability, and comply with lawful obligations. Data may be shared only with service providers that support those purposes, such as PayPal for payment processing, SMTP2GO for transactional email, Google Play or other app stores for store review and platform services, hosting/CDN/security providers for infrastructure and attack defense, and legal or governmental authorities only when required by valid legal process. GitHub hosts the gateway-recovery file described above and therefore receives the connection IP and ordinary request metadata when the app fetches it; Win's VPN sends GitHub no account, device, or user data. Win's VPN does not share VPN browsing history, DNS query history, traffic contents, or destination activity because it is not designed to collect those records.
Secure handling, retention, and deletion. App-to-service and website communications use encrypted transport where supported, VPN traffic is encrypted from the device to the tunnel endpoint, production secrets are stored outside public source in root-owned server configuration, and operational identifiers are hashed or bucketed where practical. Access to production systems is limited to authorized administrators, and backups/security logs are protected by server access controls. App-collected operational data that is no longer needed for active service operation is deleted or anonymized within 90 days. Account, payment, prepaid redemption, referral, and legal acceptance records are retained only while needed to operate the account, satisfy accounting/legal obligations, prevent fraud or abuse, resolve disputes, or document customer acceptance. Users may request account deletion or privacy help by contacting privacy@winsvpn.org or support@winsvpn.org; some records may be retained longer only where required for payment, legal, security, fraud-prevention, or dispute-resolution reasons.
Acceptable use. Customers may use Win's VPN for lawful privacy, security, education, and anti-censorship purposes. Customers may not use the service for attacks, unauthorized access, fraud, spam, malware, harassment, child exploitation, copyright infringement, torrenting, payment or device-limit evasion, or any activity that violates applicable law or harms people, networks, platforms, or infrastructure. We may suspend access, preserve evidence, cooperate with lawful process when required, and seek recovery of damages, costs, and fees caused by misuse, abuse, attacks, or unlawful conduct. Please note that our VPN is designed in a way we cannot store your data.
Android safety mode. Android camouflage mode is an optional user-safety feature for high-risk censorship environments, including Burma/Myanmar, where visible VPN apps can expose users to retaliation; it does not hide malicious activity, and the Android VPN notification remains user-controlled.
Android VpnService disclosure. On Android, Win's VPN uses Android VpnService as a core user-facing VPN function. After the user starts a connection and approves Android's standard VPN permission prompt, VpnService creates an encrypted device-level tunnel to a Win's VPN endpoint, routes selected device traffic through that tunnel, supports user-selected split-tunneling exclusions, and shows the Android VPN indicator/notification while active. Win's VPN does not use VpnService to inject ads, monetize traffic, manipulate advertising, sell traffic data, or collect browsing history, DNS query history, traffic contents, or destination activity.
Android installed-app visibility for split tunneling. When an Android user opens Exclude Apps From VPN (Split Tunneling), Win's VPN first shows a separate installed-app access disclosure. The app accesses installed application names, icons, and package identifiers only after the user affirmatively chooses Continue; choosing Not now leaves the inventory untouched and the VPN remains usable without per-app exclusions. The installed-app inventory is used locally so the user can search for and select apps to exclude from the VPN. The full inventory is not uploaded to Win's VPN, shared with third parties, sold, or used for advertising or analytics. Only the package identifiers the user selects are retained in local app settings and passed locally to Android VpnService to apply those exclusions. The user can remove selections in the split-tunneling picker, or delete all locally retained selections by clearing Win's VPN app data or uninstalling the app.
Free, trial, donated, and administrator-granted access. These access types are discretionary, non-paid, and revocable. To the maximum extent permitted by law, users of free, trial, donated, or administrator-granted access receive the service without paid-service remedies, waive claims against Win's VPN Inc. and Win Empire LLC arising from that discretionary access, and remain responsible for their own conduct, local-law compliance, and third-party claims.
Software ownership, open-source notices, and quality control. Win's VPN uses Win Empire LLC proprietary code, configuration, deployment automation, and third-party open-source components. We do not claim ownership of upstream third-party projects. Required third-party notices are preserved where applicable. Win Empire LLC maintains internal IP and open-source license compliance, written quality control, release testing, change management, customer acceptance, and company signoff procedures for production releases.
Insurance and risk transfer. Win's VPN Inc. and Win Empire LLC maintain insurance-readiness controls and active cyber insurance through Coalition Inc. to support responsible operations and underwriting requirements. Any insurance coverage is governed only by the issued policy and is for the named insureds only. Insurance does not create a service warranty, direct claim right, third-party beneficiary status, guaranteed recovery, or higher liability cap for any customer or third party.
Hold harmless. To the maximum extent permitted by law, the customer agrees to defend, indemnify, and hold harmless Win's VPN Inc., Win Empire LLC, and their owners, officers, employees, contractors, and affiliates from claims, losses, damages, liabilities, fees, penalties, and expenses arising from the customer's misuse of the service, violation of these terms, unlawful activity, or violation of third-party rights.
Limitation of liability. To the maximum extent permitted by law, Win's VPN Inc. and Win Empire LLC disclaim indirect, incidental, special, consequential, exemplary, punitive, lost-profit, lost-data, business-interruption, censorship, connectivity, speed, geolocation, payment-provider, app-store, and third-party-service damages. The service is provided without a guarantee that every network, country, website, app, streaming service, device, or censorship system will be reachable at all times.
Governing law. These terms are governed by the laws of the State of Florida, United States, without regard to conflict-of-law principles, except where non-waivable consumer protection laws require otherwise.
Electronic records and customer acceptance. By checking the required boxes in the app and continuing activation, the customer consents to electronic records and agrees that the clickwrap acceptance, timestamp, document version, document hash, account or free-access identity, device bucket, source IP bucket, platform, app version, and server HMAC certificate form the service acceptance record. Company signoff is represented by a server-generated acceptance certificate ID and HMAC signature.
Your choices, retention, and additional disclosures
Effective date and updates. This Privacy Policy is Version 2026-08-20.v1. It is effective 20 August 2026 and was last updated on 20 August 2026. Material changes are published on this page with a new version string and a new effective date. The legal terms accepted inside the app carry their own separate version and document hash, which are recorded with the acceptance and may differ from the version of this page.
Additional data categories. In addition to the categories described above, the app sends the device locale, the VPN location selected, and capability flags describing which features the build and platform support, so the service can return a working configuration. The legal acceptance record also stores the email address supplied for a paid or manual account, a one-way hash of the user agent, and the locale. Where payment is made through PayPal, the payer name and the PayPal payer, subscription, plan, and purchase references supplied by PayPal are stored with the account.
Withdrawing consent and your choices. Consent to the bundled Privacy Policy is requested inside the app before the optional processing described above begins, and the bundled policy can be reopened at any time from the Privacy Policy button on the app's main screen. Consent can be withdrawn at any time by tapping Deactivate Device, which ends the session on that device and frees its slot, by clearing the app's data, or by uninstalling the app. Each of those stops further collection from that device. Split-tunneling selections can be removed at any time in the app's settings. To withdraw consent for data the service already holds, or to object to its further processing, email privacy@winsvpn.org. Website analytics and advertising-conversion events are processed only where consent has been given on the website.
Access and correction requests. Requests for access to or correction of personal data are handled by email at privacy@winsvpn.org or support@winsvpn.org. Please send the request from the email address associated with the account, or include the account number, so the request can be verified.
Deleting your account from inside the app. Account deletion is a self-service feature in the Win's VPN app. Open the app on an activated device and choose Delete Account, shown directly below Deactivate Device on the main account screen. The app states the rule that applies to your account, shows a plain warning that deletion is permanent, and requires a second explicit confirmation before anything is sent. No account is ever deleted on the strength of an account number alone: every step is authenticated with the individual device's own credential.
Why more than one device may have to confirm. So that a single lost or stolen device cannot destroy an account, deletion normally requires confirmation from two different active devices. The exact rule is derived from the number of devices actually active on the account at the moment you ask:
- Three active devices: any two must confirm. You do not need all three, so a lost or broken device does not prevent deletion.
- Two active devices: both must confirm.
- One active device: two confirmations are impossible, so that device confirms and the account enters a seven-day waiting period. The account and its data are then erased automatically, with no further action required from you. Signing in on any device during those seven days and choosing Cancel Deletion stops it.
- No active devices: there is no device that can authorise the erase. Activate a device with your account number and setup key, then delete the account from it, or write to us at the addresses above.
While a deletion is pending, the app shows how many confirmations have been received out of the number required, and any active device on the account can cancel it. Deactivating a device is not the same as deleting an account: deactivation removes only that device's record and frees its slot toward the three-device limit. If you cannot use the app -- for example because you no longer have any activated device -- email privacy@winsvpn.org or support@winsvpn.org and we will handle the request manually.
What deletion erases. When a deletion completes, the following records are permanently deleted, not merely marked inactive or hidden: the account record itself, including the account number, any account email address, account status, expiration date, referral code, and the stored hash of the account setup key; every device record on the account, including each device's stored WireGuard private key, public key, pre-shared key, assigned tunnel IP address, device model, and device credential; any Double VPN assignment for those devices; the account's legal-acceptance records; any free-access event records tied to the account; and any unclaimed prepaid-redemption fulfilment record or queued delivery email for the account. The corresponding VPN peers are also removed from the gateway servers, so the tunnel stops working rather than merely losing its database entry. Deletion is immediate and irreversible: any remaining paid time, lifetime access, tech-support access, or referral bonus is forfeited and is not refunded, and referral links you shared stop working.
What is retained after deletion, and why. We are honest that deletion is not total erasure everywhere. The following are kept, because we are required or entitled to keep them:
- Payment and donation records (PayPal, BTCPay, and Monero order records and payment webhook records, including the buyer email supplied at checkout) are retained for tax, accounting, and audit reasons. Win's VPN Inc. is a 501(c)(3) organisation that must file an annual Form 990-series return and substantiate contributions, and payment records are also needed to resolve chargebacks and disputes. This includes the written acknowledgment issued for a charitable contribution — the donor name, any donor email address, the amount, and the date or dates of the gift — because that document is the substantiation the IRS requires a charity to be able to produce, and the donor may need it re-sent in order to claim a deduction. An acknowledgment belongs to the donor rather than to an account, so deleting an account does not remove it.
- Prepaid redemption records. The record that a particular prepaid code was redeemed is retained so the same code cannot be redeemed twice. The account number on that record is replaced by a one-way pseudonym. A separate append-only redemption audit log is protected against modification and deletion by a database-level control that exists specifically to stop tampering, so entries in that log, which can include the account number, are retained for the life of the log rather than erased.
- Referral records. A referral links two accounts, and deleting one must not corrupt or silently orphan the other party's record. The referral record is therefore kept, but the deleted account's number is replaced with a one-way pseudonym so the deleted user's identifier is no longer stored. The referrer keeps bonus days already granted to them: the payment that funded the referral still stands, and a third party should not lose service time because someone else exercised a privacy right. If that funding payment is later refunded, cancelled, or reversed, the bonus can still be reversed.
- Security and abuse-prevention records are keyed to hashed forms of an IP address, device identifier, or account number rather than to the values themselves, are held in a separate store for up to 180 days, and are retained for security, fraud prevention, and abuse response.
- Short-lived rate-limit counters are keyed to one-way hashes, contain no account number or address, and expire on their own.
- A deletion audit record is written so we can demonstrate that the deletion happened. It is deliberately built not to contain the data being deleted: it stores one-way references and counts only, and holds no account number, email address, device identifier, IP address, or key material.
- Backups made before the deletion are kept on their normal schedule (see retention periods below) and age out on that schedule.
None of the retained records are used for advertising or profiling, and none of them contain VPN activity: no browsing history, DNS query history, traffic contents, or destination activity is logged in the first place, so none of it survives deletion either.
Children's privacy. Win's VPN is intended for adults and is not directed to children. The service does not knowingly collect personal data from children under 13, or under the higher minimum age that applies in the user's country where local law sets one. If a parent or guardian believes a child has provided personal data to Win's VPN, email privacy@winsvpn.org and the data will be deleted.
International data transfers. Win's VPN Inc. is established in Florida, United States, and the service is operated from the United States. VPN gateway nodes are located in a number of other countries so that users can select a location. Where the service is used from outside the United States, the account, payment, security, and legal acceptance data described in this policy is transferred to and processed in the United States, and may also be processed by the service providers named in this policy in the countries where they operate. Those transfers are made because they are necessary to provide the service requested. VPN traffic itself is not logged and is not transferred for these purposes.
How long data is kept. App-collected operational data that is no longer needed is deleted or anonymized within 90 days. Other records are kept for the following default periods, which may be shortened or extended where required: security and abuse-prevention event records, up to 180 days; payment order records, up to 180 days; device records that become inactive, about 45 days; free-access connection events, 30 days; declined redemption events, 30 days; payment and referral link click records, 90 days; system backups, 30 days, with backup manifests kept up to 365 days. Payment records flagged for manual review are retained until that review is resolved. Account, payment, referral, and legal acceptance records are otherwise retained only while needed to operate the account, satisfy accounting or legal obligations, prevent fraud or abuse, resolve disputes, or document acceptance of the legal terms.
Additional service providers. Beyond the providers named above, Cloudflare provides hosting, content delivery, and security for the website and necessarily receives connection metadata, including the coarse country and region derived from the connection IP address, which the website uses to display a regional map to visitors. Where cryptocurrency payment is offered and enabled, payments are processed through a BTCPay Server instance or a Monero wallet service, public exchange-rate data is retrieved from Kraken and CoinGecko, and a delivery email address is required for Monero orders. Where the website's AI assistant is enabled, the message typed into it and recent turns of that conversation are sent to the third-party AI provider that powers the assistant, currently Google's Gemini API, in order to generate a reply; sensitive personal information should not be entered into the assistant. These providers act as service providers for the purposes described and do not receive VPN traffic, browsing history, DNS queries, or destination activity.
How to contact us about privacy
- Privacy and data deletion requests privacy@winsvpn.org
- Account and billing support support@winsvpn.org
- Security vulnerability reports Vulnerability Disclosure Program
- Business phone (424) 946-7876