HevraVPN is operated by Awrosoft. This policy applies to the HevraVPN mobile apps, website, account services, support services, and VPN infrastructure.
Our VPN privacy commitment
HevraVPN creates an encrypted tunnel between your device and the VPN server you select. Network traffic is processed only as needed to carry it through that tunnel and provide the service.
- We do not log your browsing history or DNS queries.
- We do not sell, rent, or use VPN traffic for advertising or profiling.
- We do not disclose VPN traffic content to third parties.
- Connection history shown in the app is stored locally on your device.
Information we process
Account and security data
If you create an account, we process your email address, password hash, account status, verification state, encrypted multi-factor authentication configuration when enabled, and security-session records.
Device and service data
We process device name, platform, VPN public key, device identifier, subscription and entitlement status, selected server, short-lived tunnel authorizations, and operational events required to connect and protect your account.
Payments
Apple or Google processes payment details. We receive product, purchase, subscription, renewal, cancellation, and entitlement information needed to provide paid service. We do not receive your full payment-card number.
Diagnostics and support
We count aggregate connection outcomes such as successful tunnel starts, reconnects, failovers, and failures. If you contact support, we process your message and any privacy-safe diagnostics you explicitly choose to include. Application request logs omit source IP addresses, source ports, and URL query strings.
Notifications and maps
If notifications are enabled, Firebase Cloud Messaging processes a device notification token. The server map retrieves map tiles from OpenStreetMap infrastructure, which may receive ordinary network request information.
How we use information
- Provide, secure, troubleshoot, and improve the VPN service.
- Authenticate accounts, enforce device limits, and prevent abuse.
- Verify subscriptions and restore purchases.
- Respond to support, privacy, and security requests.
- Meet legal obligations and protect users, the service, and the public.
Service providers
We use infrastructure, communications, notification, payment, and hosting providers solely to operate HevraVPN. They process limited service data on our behalf under contractual and security restrictions. We do not provide them with VPN browsing traffic for advertising or independent use.
Retention and deletion
We retain account and service records only while needed for the purposes described above, including security, fraud prevention, dispute handling, and legal compliance. A confirmed account-deletion request is scheduled with a 30-day recovery period. At the end of that period, the account and associated personal data are deleted unless limited retention is required by law or for a documented security or fraud-prevention need.
You can request deletion in the app or at hevravpn.com/account-deletion.
Your choices and rights
You can review devices, revoke sessions, change account security settings, disable notifications, omit support diagnostics, and request account deletion. Depending on where you live, you may also have rights to access, correct, export, restrict, object to, or delete personal data.
Security
HevraVPN uses encrypted transport, encrypted device credential storage, short-lived authorization, restricted administrative access, and other technical and organizational controls. No system can guarantee absolute security.
Changes and contact
We may update this policy as the service or law changes. Material changes will be communicated through the app, website, or account email when appropriate.
Privacy questions: support@awrosoft.com
