Privacy Policy
Last updated: July 2, 2026
This Privacy Policy describes how WorkingVPN (“WorkingVPN”, “we”, “us”) collects, uses, and protects information when you use our VPN services, our website at workingvpn.com, our mobile and desktop apps, and our browser extensions (the “Service”). By using the Service, you consent to the practices below.
Summary
- We do not log your VPN traffic, browsing history, or DNS queries.
- We do not sell or rent user data.
- We collect the minimum needed to run the service: email, payment, basic security signals.
- The free tier is supported by non-personalized ads shown in our mobile apps before you connect. Ads are never based on your VPN activity, and Premium has no ads.
- The VPN runs only when you turn it on, and you can stop it at any time.
- You can delete your account and your data from your My Account page.
VPN Traffic: No Activity Logging
We do not retain records of what you do through the VPN. We do not write to disk, aggregate, or share the websites you visit, your DNS queries, the contents of your traffic, or the source or destination IPs of your connections.
Our servers necessarily process connection information in real time in order to forward your traffic. That information lives only for the moment it is needed to route a packet and is not retained.
We keep limited account-level security information, separate from any VPN traffic: recent sign-in events and the devices you have authenticated from, so we can protect against unauthorized access and let you revoke device sessions.
What We Collect
- Account: email address and a hashed password.
- Billing: subscription plan and billing identifiers. Card details are handled by our payment processors and are not stored on our servers.
- Website request data: standard server logs from workingvpn.com (IP, user agent, referrer, requested page), used for security and operational purposes, kept short-term.
- Session and device records: sign-in time and a short summary of the device used, so you can see active sessions in your account.
- App diagnostics: anonymized crash data through Sentry. Crash reports do not include VPN traffic, browsing content, or page URLs you visit.
- Support communications: emails you send us and our replies.
- Ad attribution (consent-gated): if you arrive at workingvpn.com from one of our own ads, the name of the ad network, a click identifier, and the campaign tags (utm_*) from the landing link, as described in “Measuring Our Own Ads.”
We do not collect your phone number, precise location, contacts, photos, microphone, camera, or biometrics. On our website we do not use retargeting pixels or third-party ad-tracking cookies; the only marketing-related cookie is our first-party ad-attribution cookie described in “Measuring Our Own Ads.” Advertising identifiers are touched only by the ad SDK described in the next section, only in our mobile apps, and only on the free tier.
Advertising on the Free Tier
Our free tier is supported by ads. Users of the free and guest tiers of our mobile apps see an interstitial ad, served by Google AdMob, before the VPN connects. Premium users see no ads, and no ad SDK activity occurs for them.
- Non-personalized only. We request non-personalized ads exclusively. Ads are selected from contextual signals such as approximate (IP-based) location and device type, not from a profile of you. On iOS we never request App Tracking Transparency permission, and we do not track you across other companies' apps or websites.
- What the ad SDK processes: device advertising identifiers (used for frequency capping and fraud prevention, not profiling), IP address and the approximate location derived from it, device information, and ad interaction events (an ad was shown, tapped, or closed). This is processed by Google as an independent service provider; see the Google Privacy Policy.
- Never based on VPN activity. Ads load and display only while the VPN is disconnected, over your regular connection. Your VPN traffic is never used to select ads, and ad requests never carry information about what you do through the tunnel.
- Consent. Where required (for example the EEA and UK), we show Google's consent form before any ad is served, and you can decline.
Cookies and Analytics
On workingvpn.com we use a small number of cookies for authentication, session management, and aggregate analytics via Google Analytics 4. With your consent, we also use Microsoft Clarity to collect session replays and heatmaps that show us how visitors use our pages, so we can improve them. We do not use third-party advertising or retargeting cookies; the only marketing cookie is our own first-party attribution cookie, described next. Where applicable law requires consent for analytics or marketing cookies, we ask for it on your first visit.
Measuring Our Own Ads
We advertise WorkingVPN on ad networks such as PropellerAds.
When you land on workingvpn.com from one of these ads, the
landing link may include a click identifier and campaign tags
(utm_* parameters). We use them for one purpose
only: to measure which of our own ads lead to signups and
purchases, so we can spend our advertising budget sensibly.
This is not profiling — the data says nothing about who
you are or what you do, on the web or through the VPN.
- What is stored: the ad network name and click identifier in a signed, first-party, HTTP-only cookie that expires after 30 days; campaign tags are kept in your session. No third party can read this cookie.
- Consent. Where applicable law requires consent (for example the EEA and UK), the cookie is set only after you accept marketing cookies in our banner; until then the click identifier is held in your session and is discarded if you decline. Elsewhere, you can opt out in the banner at any time. We also honor the Global Privacy Control signal as an opt-out.
- What is shared: if you sign up or purchase, we report the conversion to the ad network that showed you the ad, sending the click identifier only — never your name, email, or any VPN activity.
- Never based on VPN activity. Attribution uses only the landing link parameters; your VPN traffic plays no part in it.
How We Share Information and Subprocessors
We do not sell or rent your information. We share limited data with the service providers that help us run the Service, under agreements requiring them to protect your information and use it only on our instructions:
| Provider | Purpose |
|---|---|
| Stripe, Inc. | Web checkout and recurring card billing |
| Apple Inc. | In-app purchases and subscriptions on iOS and macOS |
| Google LLC (Play Billing) | In-app purchases and subscriptions on Android |
| Google LLC (Analytics 4) | Aggregate website analytics |
| Microsoft Corporation (Clarity) | Website session replays and heatmaps to improve usability (loads only after you accept analytics cookies) |
| Google LLC (AdMob) | Non-personalized ads on the free tier of our mobile apps |
| PropellerAds Ltd. | Measuring which of our ad campaigns lead to signups (receives a click identifier only) |
| Functional Software, Inc. (Sentry) | Application crash reporting |
| Cloudflare, Inc. | CDN, DNS, and storage of downloadable installers |
| Our hosting and VPN-server providers | Running our infrastructure in the country shown for each server |
We may also disclose information when we believe in good faith it is required by valid legal process (such as a subpoena or court order), to protect against fraud or threats to safety, or with your consent. We do not disclose information we do not retain.
Data Retention
- VPN traffic: not retained.
- Account profile: while your account is active; deleted within 30 days of an account-deletion request.
- Sessions and device records: 90 days from last activity.
- Support emails: 24 months after the conversation closes.
- Ad attribution: the attribution cookie expires after 30 days; the conversion record (network, click identifier, campaign tags) is kept while your account is active and deleted with your account.
- Billing records: 7 years, to meet tax-law requirements.
- Encrypted backups: rotated within 30 days.
Your Rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. You can exercise most of these rights from your account page, and you can email [email protected] for anything else.
You can delete your account at any time from the My Account page. Deletion removes your personal data from our active systems within 30 days and cancels any active subscription.
App Store and Google Play Compliance
In accordance with Apple App Store Review Guideline 5.4 and the Google Play Developer Program Policies for VPN apps:
- We do not sell user data to any third party for any purpose.
- We do not use user data for purposes unrelated to providing the VPN service.
- We do not disclose user data to third parties except as needed to operate the service (for example, a payment processor for billing, or the non-personalized ad serving that funds the free tier as described above) or as required by law.
- Data from VPN usage is never used for, or disclosed for, advertising. Ads on the free tier are non-personalized and are served only while the VPN is disconnected.
- Our VPN apps establish a tunnel only when you explicitly enable it and disclose to your operating system that they are acting as a VPN.
Children
WorkingVPN is intended for users 18 and older. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us and we will delete it.
Security
We protect personal information with administrative, technical, and physical safeguards, including TLS in transit, encryption at rest for our databases and backups, hashed passwords, and role-based access controls on production systems. No system is completely secure, and we cannot guarantee absolute security. If we learn of a breach that affects you, we will notify you and the appropriate regulators as required by law.
International Data Transfers
WorkingVPN is operated from Canada. Your information may be transferred to and processed in countries other than your own, including the United States, the European Union, and the country in which your selected VPN server is located. Where required, we rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) for transfers of personal information out of the EEA and the UK.
Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. For material changes that affect you, we will give notice by email and on our website.
Contact
- Email: [email protected]
- Company: WorkingVPN
- Location: Kitchener, Ontario, Canada
If you have a privacy concern, please contact us first at [email protected] so we can try to resolve it. If you're not satisfied with our response, you also have the right to complain to a privacy regulator — in Canada, the Office of the Privacy Commissioner of Canada; in the EEA or the UK, your local Data Protection Authority.
See also our Terms of Service.
WorkingVPN is a registered business name of LoudTronix Inc., an Ontario corporation. Disclosure provided pursuant to the Ontario Business Names Act.