01In short
We hold an email address and a payment record, because a subscription needs both. We do not hold anything about what you do while connected. If someone demanded your browsing history from us, there would be nothing to give them.
VPN Oxide is operated from Nicosia, Cyprus, by the company named in our Terms of Service, which is the data controller for the purposes of the General Data Protection Regulation. Being established in the European Union means the GDPR applies to us in full, and our customers get its protections by default rather than as a courtesy.
02What we never log
- The websites, services or apps you connect to
- Your DNS queries — these run through our own encrypted resolvers and are not written to disk
- The contents of your traffic, in any form
- The IP address you connect to us from
- Connection timestamps or session durations tied to your account
- Bandwidth totals per user, per session or per server
Because none of this is recorded, we cannot reconstruct it later, for you or for anyone else.
03What we do hold
- Account data: your email address, a hashed password, your plan and its renewal date.
- Payment record: the amount, date, currency and the reference our payment provider gives us. We never see or store your full card number.
- Support messages: whatever you write to us, and our replies.
- Aggregate service data: total load on a server location, so we know where to add capacity. This is not linked to accounts.
Paying with cryptocurrency means the only personal detail we hold is the email address you use for your login — and it doesn't have to be one that identifies you.
04Why we hold it
Account and payment data are processed to perform our contract with you: to give you access, take payment, and handle refunds. Support messages are processed on the same basis. Aggregate capacity data and basic fraud prevention rest on our legitimate interest in running a reliable service. Where we send marketing email, we do it on consent, and every message has an unsubscribe link that works.
05Cookies and analytics
The website uses a session cookie to keep you signed in and, if you accept them, cookies that tell us which pages people find useful. Analytics are privacy-respecting and IP addresses are truncated before storage. You can decline non-essential cookies without losing any part of the service, and you can clear them from your browser at any time.
06Who else sees data
We share the minimum necessary with the companies that help us run VPN Oxide — payment processors, email delivery, hosting for the website and account system, and the operators of our server network, some of whom are based outside the European Economic Area, including in Asia. None of them receives your name or email address: VPN accounts are created under a randomly generated username that is not derived from any detail you gave us. Each is bound by a data processing agreement and may only use the data to provide their service to us. We do not sell personal data, and we do not share it with advertisers or data brokers. Your account data is stored and processed inside the European Union. Where a partner sits outside the EEA, the transfer is covered by the European Commission's standard contractual clauses.
07How long we keep it
- Account data: while your account is open, then deleted within 30 days of closure.
- Payment records: seven years, because tax and accounting law in Cyprus requires it.
- Support messages: two years after the conversation ends.
08Legal requests
If we receive a valid legal order from a competent authority, we respond with what we actually hold — which, for questions about someone's internet activity, is nothing. We are not subject to any obligation to retain records of what our customers do online, and we do not create new logging in response to a request. We do not give informal access to anyone. Where the law allows us to tell you that a request concerning your account was made, we will.
09Your rights
Whoever and wherever you are, you can ask us for a copy of your data, ask us to correct or delete it, or ask us to stop sending you marketing. Email us and we respond within 30 days, free of charge.
The GDPR also gives you the rights to restrict processing, to receive your data in a portable format, and to object to processing we base on legitimate interest. If you think we have handled your data badly, you can complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to the supervisory authority in the country where you live.
10Security
Traffic between your device and our network is encrypted with AES-256 over WireGuard, with OpenVPN and IKEv2 available as alternatives. Passwords are stored hashed and salted. Access to account systems is limited to staff who need it and protected by two-factor authentication. No system is perfectly secure, but if a breach ever affected your data, we would tell you and the regulator within 72 hours of finding it.
11Changes
The current version of this policy always lives at vpnoxide.com/privacy. If we make a change that materially affects how we handle your data, we email you before it takes effect.
12Contact
Privacy questions, data requests and everything else: [email protected]. Our registered postal details are in our Terms of Service.