User Data Governance
Logging & Retention Data
This document describes what data the TuxlerVPN Mobile service generates or receives, how long each category is kept, where it is stored, and what triggers deletion. The authoritative source is the Privacy Policy, in particular sections 2, 5, 7, and 8. Where this page summarises that policy, the Privacy Policy controls in the event of any conflict.
Our default position
TuxlerVPN Mobile’s default position is no retention of VPN traffic content and no retention of VPN-session metadata after disconnect. We do not log the contents of your VPN traffic, the websites you visit, or your DNS queries. Connection metadata needed to operate the tunnel is held only for the duration of an active session and is discarded when the session closes (Privacy Policy §2.6 and §8). Separately, the accountless app uses an app-instance UUID, session token, Play Integrity checks, purchase-token data for Premium, support correspondence, and crash reports as described below.
One thing does happen on your device: while the VPN is active, the app measures throughput solely to prompt free users to upgrade when they are near their speed limit. This is not transmitted to us and is not retained after the session ends.
What we collect, by category
Each category below lists the data type, the purpose, the retention window, and the storage location. Where the Privacy Policy does not name a specific number of days, we describe the retention condition rather than invent one.
App-instance UUID and device information. A randomly generated identifier created on first launch, plus device manufacturer, device model, Android version, Android SDK version, and TuxlerVPN Mobile app version/build number. Purpose: associate an accountless installation with connection requests, deliver a compatible configuration, verify entitlement, prevent abuse, and diagnose issues. Retention: the UUID is stored locally in the app’s private storage until uninstall or app-data clearing. Backend copies, where created for connection management, entitlement checks, abuse prevention, support, or diagnostics, are retained only as long as needed for those purposes and deleted on request where legally required. Storage: your device and the TuxlerVPN Mobile backend. Source: Privacy Policy §2.1 and §8.
Play Integrity and session tokens. Play Integrity tokens are sent to our backend to confirm requests come from a genuine installation; a short-lived session token is stored locally until it expires or app data is cleared. Purpose: service security, entitlement verification, and abuse prevention without requiring a login. Retention: token-lifetime/service-security retention only; not used for advertising or cross-app tracking. Storage: your device and TuxlerVPN Mobile backend. Source: Privacy Policy §2.1 and §8.
Subscription and payment data. Google Play purchase tokens and purchase payloads sent to our backend for entitlement checks (Premium users). The token may be paired with the same app-instance UUID used for Standard users. No email is collected as part of subscription verification, since Google Play Billing does not pass user emails to apps by default. We do not store full payment details (card numbers, billing address, etc.). Those are held by Google. Retention: kept as needed to verify entitlement, handle support and refunds, and prevent subscription abuse; records required for tax and accounting are kept for the longer period required by applicable law and may persist after a deletion request to that extent, while other purchase-related data is deleted on request where legally permitted. Storage: TuxlerVPN Mobile backend, with full payment data held by Google. Source: Privacy Policy §2.2 and §8.
Customer support correspondence. Email correspondence with [email protected] from people who have chosen to write to us. The email address is collected only as a byproduct of an inbound message, since the app does not transmit it. Purpose: respond to your enquiry and any follow-up. Retention: while the request is active; support threads are deleted after 90 days of inactivity on the thread, or earlier on request. Storage: a third-party customer-support provider (USA) acting as a processor, and the TuxlerVPN Mobile backend. Source: Privacy Policy §2.3 and §8.
Google Play ratings and reviews. If the app opens a rating prompt, it directs you to Google Play. Ratings and public reviews submitted there are handled by Google Play under Google’s own terms. The Android app does not transmit written rating or review content to the TuxlerVPN Mobile backend. Direct feedback sent by email is covered under customer support correspondence above. Source: Privacy Policy §2.3.
Crash reports and diagnostics (Sentry). Crash type, stack trace, app version, Android version, and device model. The app is configured not to send your name, email, advertising identifier, screenshots, view hierarchy, request headers, or VPN traffic. The Sentry SDK is configured to transmit data only when an actual crash occurs; session tracking, breadcrumbs, screenshots, and view-hierarchy capture are disabled (see Privacy Policy §2.4 for the full configuration). Retention: Sentry’s standard schedule (typically 90 days) after which records are deleted. Storage: Sentry, operated by Functional Software, Inc. (USA). Sentry records are locatable where possible by device model, Android version, app version, dates, and any diagnostic identifier included with the event. Source: Privacy Policy §2.4 and §8.
Approximate location and server-region selection. Approximate country, region, or city may be derived from the IP address used to contact the service, and your chosen VPN server region (for example, “United States” or “Germany”) is sent to our backend. Purpose: display current-location information, route your session to the appropriate gateway, and troubleshoot connectivity. Retention: retained only as long as needed for service operation, troubleshooting, and abuse prevention; VPN-session metadata is not retained after disconnect. Storage: TuxlerVPN Mobile backend. Source: Privacy Policy §2.5 and §8.
Website cookies. Strictly-necessary cookies set by the TuxlerVPN Mobile website. Purpose: basic site functionality and security. Retention: per the cookie’s individual lifetime as listed in the Cookie Policy. Storage: your browser. Source: Privacy Policy §2.7 and the Cookie Policy.
Storage locations
The data controller, Tuxler Digital Services Corp., is incorporated in Panama. Personal data may be processed in additional jurisdictions depending on which processor is involved: the United States (Sentry crash reporting and third-party customer-support delivery), Canada, the United States, and/or the Netherlands (cloud infrastructure behind our backend), and various countries worldwide where Tuxler operates VPN gateway servers. Source: Privacy Policy §5.
Where data is transferred outside the European Economic Area or the United Kingdom, TuxlerVPN Mobile relies on Standard Contractual Clauses approved by the European Commission and the UK Addendum where applicable, or on the recipient’s certification under a recognised adequacy framework. A copy of the relevant SCCs is available on request from [email protected]. Source: Privacy Policy §4 and §5.
Deletion triggers
Records are deleted when one of the following occurs:
- The active VPN session ends (session-only VPN metadata categories).
- The local app is uninstalled or app data is cleared (local app-instance UUID and session token).
- A subscriber cancels Premium and requests deletion of any remaining backend entitlement records (see Privacy Rights and Delete Your Account).
- A support ticket is fully resolved and any follow-up window has lapsed.
- Sentry’s retention schedule expires.
- A statutory retention period (for example, tax law in Panama) expires.
- The lifetime of a strictly-necessary cookie ends.
To submit a deletion request, follow the steps described in the Privacy Policy §11 and on our Privacy Rights page. Deletion is actioned within 30 days.
What we do not log
Specifically, TuxlerVPN Mobile does not retain or record:
- The websites you visit while connected to the VPN
- The contents of your traffic (URLs, payloads, downloads, uploads)
- DNS queries themselves
- Your originating IP address after a VPN session closes
- Connection metadata (session timestamps, bandwidth used, gateway selected) after a session closes
- Your name, address, phone number, government identifiers, advertising identifiers, or precise location
- Payment card numbers (handled exclusively by Google Play)
Source: Privacy Policy §2.6 and §2.8.
Updates
This document is reviewed when the Privacy Policy is reviewed or when our retention practices change. Last reviewed: 18 August 2026.