Privacy Policy
This Privacy Policy explains how Devroq Apps LLC ("Devroq", "we", "us", or "our"), located at 15 Cutter Mill Rd, Unit 556, Great Neck, NY 11021, United States, collects, uses, and protects information when you use the HideNow VPN mobile application (the "App"), our website, and related services (together, the "Service"). Devroq is the data controller for the personal data described here.
1. Information We Collect
1.1. Information we do not retain
Our systems are designed so that we do not keep records that would let us reconstruct what you do online. Specifically, we do not retain:
- your browsing history, or the websites and apps you access;
- the content of your network traffic, which we do not inspect;
- DNS queries linked to you or your device — our resolvers answer queries in memory and do not write them to user-linked logs;
- the IP address assigned to you by your internet provider, in any form that can be linked to a specific online activity.
To be precise about what this does not mean: a no-logs design is not the same as no processing at all. Carrying your traffic requires handling it as it passes through our servers, and we process the limited technical and aggregate data described in Section 1.5 to keep the Service running and to protect it from abuse. Those records are not tied to your online activity.
1.2. Account information
When you first launch the App, we automatically create an anonymous account tied to a randomly generated identifier on your device. You do not need to provide your name, email address, or phone number to use the VPN.
1.3. Email address (optional)
If you choose to use the data-breach scan feature, you may enter an email address so we can check it against databases of known data breaches. The address is used for this purpose and, if you enable breach monitoring, to notify you of new breaches. You can remove it at any time in the App.
1.4. Subscription and purchase information
Purchases are processed by Apple through your Apple ID. We receive confirmation of your subscription status (for example, plan type, trial status, expiration date) so we can provide paid features. We do not receive or store your payment card details.
1.5. Connection and diagnostic data
To operate and improve the Service, we process a limited amount of technical data:
- aggregate connection metrics (for example, whether a connection attempt succeeded, server load, total bandwidth per session) that are not linked to your online activity;
- device type, operating system version, App version, and preferred language;
- crash reports and performance diagnostics;
- anonymized product analytics (for example, which screens are used) to improve the App.
2. How We Use Information, and Our Legal Bases
We use the information described above for the purposes below. Where the GDPR or UK GDPR applies to you, the legal basis for each purpose is shown alongside it.
| Purpose | Legal basis |
|---|---|
| Providing the VPN connection and other App features | Performance of a contract |
| Verifying your subscription and providing paid functionality | Performance of a contract |
| Maintaining, securing, and improving the Service, including capacity planning, abuse prevention, and troubleshooting | Legitimate interests (running a reliable, secure service) |
| Responding to support requests you send us | Performance of a contract / legitimate interests |
| Service notifications, such as trial expiration or billing issues | Performance of a contract |
| Email data-breach checks and breach monitoring | Consent |
| Optional product analytics and attribution | Consent, where required by law; otherwise legitimate interests |
| Promotional messages and marketing push notifications | Consent (withdrawable at any time) |
| Complying with legal obligations and responding to lawful requests | Legal obligation |
You can withdraw consent at any time — by removing your email address in the App, turning off analytics and notifications in the App settings or your device settings, or contacting us. Withdrawing consent does not affect processing carried out before the withdrawal.
3. How We Share Information
We do not sell your personal information, and we do not share it with third parties for their own marketing. We share limited information only with the categories of recipients below.
3.1. Service providers (processors)
| Provider | Purpose | Data involved |
|---|---|---|
| Apple Inc. (USA) | App distribution and subscription payments | Purchase and subscription status |
| RevenueCat, Inc. (USA) | Subscription management and receipt validation | Anonymous account ID, subscription status |
| Google Firebase (USA) | Crash reporting and product analytics | Device and App diagnostics, anonymized usage events |
| Sentry (USA) | Error and performance monitoring | Crash reports, stack traces |
| AppsFlyer (USA/Israel) | Install attribution and campaign measurement | Device and attribution identifiers |
| Breach-database providers | Running the email breach check you request | Email address or its hash |
| Cloud and VPN hosting providers | Operating our servers and infrastructure | Aggregate connection metrics; no browsing activity |
All of these providers act on our instructions under written agreements (data processing agreements where required) that restrict their use of the data to the purposes above. Our provider stack changes as the Service develops; we update this section when it does, and the list published here is the current one.
3.2. Other disclosures
- Authorities, if required by valid legal process — noting that, because of our no-logs design, we have no records of your browsing activity to disclose;
- a successor entity in the event of a merger, acquisition, or sale of assets, in which case this Policy will continue to apply.
4. Cookies, SDKs, and Identifiers
On our website. We use strictly necessary cookies that are required for the site to work — these cannot be switched off. Where we use analytics or measurement cookies and similar technologies (pixels, local storage), we do so only with your consent in regions where consent is required, and you can change or withdraw that choice at any time through the cookie controls on the site or your browser settings. Blocking cookies may limit some site functionality.
In the App. Mobile apps do not use browser cookies. Instead, the App may use SDK-based identifiers:
- Apple Advertising Identifier (IDFA) — only if you grant permission through Apple's App Tracking Transparency prompt. If you decline, no IDFA is accessed;
- Firebase installation ID and RevenueCat app user ID — to link diagnostics and subscription status to your anonymous account;
- attribution identifiers — to measure which campaign led to an install;
- push notification tokens — to deliver notifications you have enabled.
You can reset or limit these at any time: iOS Settings → Privacy & Security → Tracking, and the analytics and notification toggles in the App settings.
5. Data Retention and Deletion
We keep each category of data only as long as needed for the purpose it was collected for. The periods below describe our current practice. A period may be extended where we need longer to investigate a security incident, resolve a dispute, or comply with a legal obligation.
| Data | Retention |
|---|---|
| Anonymous account identifier and subscription status | While the account is active; normally deleted within 30 days of account deletion |
| Email address for breach checks (optional) | Until you remove it in the App or delete your account |
| Aggregate connection metrics (not linked to activity) | Up to 12 months, then aggregated or deleted |
| Crash reports and performance diagnostics | Typically up to 90 days; longer where needed to debug a recurring issue |
| Anonymized product analytics | Up to 24 months; fully aggregated statistics may be kept indefinitely |
| Purchase and tax records | As required by tax and accounting law, typically up to 7 years |
| Support correspondence | Up to 24 months after the request is closed |
5.1. Deleting your account
You can delete your account directly in the App (Settings → Delete account). This removes your account identifier, any stored email address, and associated data from our primary systems, normally within 30 days.
5.2. Limits of deletion
We want to be straightforward about what deletion cannot reach immediately. Encrypted backups, and copies held by the third-party providers listed in Section 3, are not erased by the deletion in our primary database — they expire on their own retention schedules, generally within 90 days for backups and according to each provider's policy otherwise. Records we are legally required to keep, such as purchase records retained for tax purposes, are also preserved. If you want data removed from a specific provider, write to contact@devroqapps.com and we will submit the deletion request wherever the provider's tools allow, and tell you the outcome.
6. Security
VPN traffic is protected with modern encryption protocols. We maintain technical and organizational measures appropriate to the data we hold. These measures include encryption in transit, encryption at rest where our infrastructure providers support it, access controls that limit production access to authorized personnel on a least-privilege basis, and secure key storage. Our security measures develop over time as the Service and the threat landscape change. No method of transmission or storage is completely secure and we cannot guarantee absolute security, but we work to protect your information using reasonable and appropriate safeguards.
7. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will delete it.
8. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to opt out of certain processing.
8.1. EEA, UK, and Switzerland
If the GDPR or UK GDPR applies to you, you have the right to:
- access the personal data we hold about you and receive a copy of it;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten"), subject to the limits in Section 5.2;
- restrict or object to processing based on our legitimate interests;
- data portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out.
You also have the right to lodge a complaint with your national data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the supervisory authority of the country where you live or work.
8.2. California residents
Under the CCPA/CPRA you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to not be discriminated against for exercising these rights. We do not sell or "share" personal information as defined by the CCPA/CPRA, and we do not process personal information for cross-context behavioral advertising.
8.3. How to exercise your rights
Use the tools in the App, or contact us at contact@devroqapps.com. We will verify your request and respond within the timeframes required by applicable law — generally within 30 days under the GDPR and 45 days under the CCPA, which may be extended where the law permits. Exercising these rights is free of charge, and you may use an authorized agent where the law allows it.
9. International Transfers
We are based in the United States, and information we hold is processed in the United States and in the countries where our infrastructure and service providers operate. When we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission and, where applicable, the UK International Data Transfer Addendum, together with technical measures such as encryption. You can request further information about the safeguards that apply by contacting us.
10. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you in the App or by other reasonable means before the changes take effect. The "Effective date" above shows when this Policy was last revised.
11. Contact Us
Devroq Apps LLC
15 Cutter Mill Rd, Unit 556
Great Neck, NY 11021, United States
contact@devroqapps.com