Privacy Policy
Last updated: 29 August 2026
RunVPN is built around a simple idea: a VPN should protect your privacy, not profit from it. This policy explains what we do and — just as importantly — do not collect when you use our apps and services.
1. Who we are
RunVPN is operated by Sparrow Tech, Inc., a corporation incorporated in the State of Delaware, USA (the “data controller”). Registered address: 1111B S Governors Ave STE 39232, Dover, DE 19904, USA. For any privacy question, contact privacy@runvpn.app.
2. Our no-logs commitment
We do not keep browsing or activity logs. We do not record the websites or apps you use, DNS queries, domains, URLs, HTTP requests, readable traffic destinations, traffic content, or the data you send and receive through the VPN tunnel.
We keep only the limited connection, diagnostic and abuse-prevention metadata described below. It cannot be used to reconstruct browsing history; the destination fingerprint can only be compared with a destination already supplied in a specific abuse report.
3. Information we collect
Account data: an identifier you use to sign in (such as an email address or a sign-in token from a provider you choose) so we can restore your access across devices.
Subscription status: whether your plan is active and when it renews. Payments are processed by the app stores or payment providers — we do not receive or store your full card details.
Approximate location from IP: when you open the app we look up the approximate city of your current IP address to show the connection indicator on the map. This lookup runs on our own servers against an offline database. The IP used for this map lookup is not sent to a third party or retained as part of the lookup. The separate, limited retention of a VPN connection source IP for abuse prevention is described below.
Connection and support diagnostics: for up to 30 days we keep your account identifier, app and operating-system version, coarse network type, VPN connection stages and fixed success or failure categories, selected transport or server, and the approximate country and network provider (ASN) of the connection. These records never contain websites, apps used through the tunnel, DNS queries, readable traffic destinations, traffic contents or byte counters.
Server request logs: for up to 3 days our API server keeps the time, request path without query parameters, response status and duration, the app user agent and a truncated network address (the last part of the IP address is removed). We use them only to investigate outages and overload and to protect the service. These logs never contain tokens, request bodies or anything sent through the VPN tunnel.
Abuse-prevention metadata: for no more than 30 days we keep the account identifier, source IP address used to connect to the VPN server, VPN server and exit IP, protocol, connection opening and closing times, the temporary outbound source port, and a keyed one-way fingerprint of the destination IP and port. The fingerprint does not contain a readable destination and is used only to compare a provider report with a specific VPN connection. We do not store domains, DNS queries, URLs, HTTP request details or paths, or traffic payloads for this purpose.
iOS app: RunVPN does not initialize third-party analytics, crash-reporting, advertising-attribution, or push-notification SDKs on iOS. We do not collect, use, sell, or disclose your VPN traffic, browsing activity, DNS queries, connection contents, or app-usage analytics to third parties.
Android app: limited technical and diagnostic data (app version, operating system, crash and performance diagnostics) may be processed through Firebase to keep the app stable. Android may also use a mobile advertising identifier and related installation identifiers for campaign measurement through our analytics and attribution providers. These Android-only practices are disclosed before use and can be controlled through device settings.
Android push notification token: if you allow notifications, a Firebase Cloud Messaging device token lets us send service, security and account notifications. You can turn notifications off at any time in device settings.
4. How we use information
To provide and maintain the service, manage your subscription, respond to support requests, keep the service secure, prevent abuse and fraud, measure marketing performance in aggregate, and comply with legal obligations.
5. Legal bases
Where the GDPR applies, we process data to perform our contract with you, on the basis of our legitimate interests in operating and protecting the service, investigating specific abuse reports and preventing fraud, and — where required — with your consent, which you may withdraw at any time.
6. Service providers we use
We do not sell your personal data. We share the limited data above only with processors that help us operate the service, and only as far as needed:
Apple App Store and Google Play — payment processing and subscription billing.
RevenueCat, Inc. (USA) — subscription management and purchase-receipt validation.
Telegram — optional sign-in and in-app payments (Telegram Stars).
Google LLC — optional Google sign-in. Firebase Analytics, Firebase Crashlytics diagnostics, and Firebase Cloud Messaging are used by the Android app only and are disabled in the iOS app.
Tenjin — Android install attribution and marketing analytics only. Advertising and installation identifiers are not collected or sent by the iOS app.
Cloud hosting providers — operating our servers and the VPN infrastructure.
We may disclose the limited data we hold where legally required, but we cannot disclose browsing history, DNS, URLs, readable destinations or traffic contents that we do not keep.
7. International transfers
Our VPN infrastructure is operated to avoid mandatory data-retention requirements. Where data is transferred internationally (including to the USA, where the company is incorporated), we rely on appropriate safeguards such as standard contractual clauses.
8. Data retention
Connection, support-diagnostic and abuse-prevention records are deleted after no more than 30 days and are not included in longer-lived backups. We keep account and subscription-status data for as long as your account is active and as needed to comply with legal obligations, after which it is deleted or anonymised. App Store billing records remain subject to Apple’s retention rules.
9. Security
We use technical and organisational measures to protect your data against unauthorised access, loss or alteration.
10. Your rights and account deletion
Subject to applicable law, you may request access to, correction or deletion of your data, restrict or object to processing, and request portability.
You can delete your account from within the app (Settings → Profile → Delete account), or by emailing privacy@runvpn.app. Account deletion does not cancel an App Store or Google Play subscription; store subscriptions must be cancelled in the relevant store. On deletion we remove account, access, profile, marketing and identity records, revoke the Sign in with Apple credential where available, and anonymise financial records that must be retained by law. Connection, diagnostic and abuse-prevention records already collected expire within the fixed 30-day period and may be retained until then where necessary to protect the service, investigate abuse or establish legal claims.
11. US state privacy rights (California and others)
We do not sell or “share” your personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA), and we do not use it for cross-context behavioural advertising. California and other US-state residents have the right to know what we collect, to request deletion, and not to be discriminated against for exercising these rights. To exercise them, contact privacy@runvpn.app.
12. Children
RunVPN is not directed to children and is not intended for anyone under the age required by the laws of their country to consent to use such a service.
13. Changes
We may update this policy from time to time. Material changes will be reflected by the date below and, where appropriate, announced in the app or on this site.
14. Contact
Sparrow Tech, Inc. — privacy@runvpn.app