User Data Governance
Privacy Policy
1. INTRODUCTION
This Privacy Policy explains the rules governing the collection, storage, processing, and use of personal data when you install or use the TuxlerVPN Mobile Android application and the related VPN service (collectively, the “Services”). It also covers our website at tuxlervpn.app.
The data controller is Tuxler Digital Services Corp. (“TuxlerVPN Mobile”, “we”, “us”, or “our”), headquartered in Panama, a jurisdiction with no mandatory data retention laws for VPN providers. Contact: [email protected]
By installing or using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. If you do not agree, please discontinue use of our Services.
Google Play Compliance:
Our VPN is designed to comply with Google Play’s Developer Program Policies, including the User Data and VPN Service policies. We do not redirect or manipulate user traffic for monetization, do not modify advertising shown by other apps, and do not collect, transmit, or use data, device resources, or network connections for purposes outside providing and securing the VPN service, verifying subscriptions, supporting users, and fixing crashes as described below. The TuxlerVPN Mobile Android app contains no advertising SDKs, no attribution SDKs, and no general-purpose analytics SDKs other than the crash reporter described below.
2. PROCESSING OF YOUR PERSONAL DATA
TuxlerVPN Mobile does not require you to create an account, provide a name, email address, or phone number to use the Android app. The app does generate a random app-instance identifier on your device so our backend can deliver VPN configurations, manage connect/disconnect requests, verify subscriptions, and prevent abuse without a traditional account. The categories below describe the data the app collects, generates, or transmits.
2.1 App-Instance Identifier, Session Token, and Device Information
• App-instance UUID: On first launch, the Android app creates a random app-instance UUID and stores it locally in the app’s private storage. The UUID is not derived from your name, email, Google account, phone number, advertising identifier, device serial number, or any government identifier. It is used instead of an account login when the app connects to or disconnects from the VPN service and when Premium entitlement checks need to be associated with the current installation. Uninstalling the app, or clearing app data, removes the local UUID from your device.
• Play Integrity and session token: Free-tier and Premium connection attempts use Google Play Integrity to help confirm that requests come from a genuine TuxlerVPN Mobile installation. The Play Integrity token is processed by our backend, and a short-lived session token is stored on your device while it remains valid. These tokens are used for service security and entitlement verification, not for advertising or cross-app tracking.
• Device information: Alongside the app-instance UUID and session token, the app sends the following technical information to our backend so we can deliver compatible VPN configurations, diagnose connectivity issues, and apply the correct app-version behavior:
- Device manufacturer (e.g., Samsung, Google)
- Device model
- Android version
- Android SDK version
- TuxlerVPN Mobile app version and build number
These device fields may also be included in crash reports sent to Sentry (see §2.4) so we can correlate crashes with specific device and OS combinations.
2.2 Subscription and Payment Information
• Google Play Billing: Subscriptions are managed by Google Play Billing. Google handles your payment information directly. TuxlerVPN Mobile does not store or process your full payment details (card numbers, billing address, etc.). Payments made via the Google Play Store are governed by Google’s Privacy Policy and Terms of Service.
• Premium auth: When you connect to a Premium VPN server or restore a purchase, your Google Play subscription token and purchase payload may be sent to our backend for entitlement verification with Google. We use this information to confirm Premium access, handle subscription support and refunds, prevent subscription abuse, and satisfy tax/accounting obligations where applicable. We do not receive your full payment-card details or your Google Play account password.
• Free users: Free-tier connections are authenticated by Google Play Integrity API attestation and the app-instance/session-token flow rather than by personal credentials. See §2.1 for details.
2.3 Communication Data
• Email correspondence: If you contact our support team at [email protected], we collect the email address you write from, the content of your message, and any information you choose to share. Customer support is delivered by a third-party customer-support provider (USA), acting as a data processor on our behalf, and is available 24 hours a day, 7 days a week via email. Premium subscribers who include their Google Play order ID with a support request are routed to a priority queue ahead of Standard-tier requests. The order ID is used to verify the active Premium entitlement for the support request and is not retained beyond the support thread unless needed for refund, abuse-prevention, legal, or accounting records. Support threads themselves are retained while a request is active and are deleted after 90 days of inactivity on the thread, or earlier on request.
• Google Play ratings and reviews: If the app opens a rating prompt, it directs you to Google Play. Ratings and public reviews submitted there are handled by Google Play under Google’s own terms. The Android app does not transmit written rating or review content to the TuxlerVPN Mobile backend. If you want to send feedback directly to us, email [email protected].
2.4 Crash Reports and Diagnostics
• Sentry: The app uses Sentry (operated by Functional Software, Inc., USA) to collect crash reports and basic diagnostics. Crash reports include the type of crash, a stack trace, the version of the app, the Android version, and the device model. The app is configured not to send your name, email address, advertising identifier, request headers, screenshots, view hierarchy, or the contents of your VPN traffic. Debug-level events are filtered out before transmission. Sentry, as the crash-reporting processor, may receive standard network metadata required to receive and secure the crash-report request.
The Sentry SDK is configured so that nothing else is sent to Sentry between actual crash events. The following are all explicitly disabled in the app:
- Session-tracking pings on app foreground and background (Sentry’s “Release Health” feature)
- Breadcrumbs (short diagnostic trail markers Sentry would otherwise attach to a crash report), specifically:
- UI-tap breadcrumbs
- Network-connectivity breadcrumbs (wifi / cellular / offline transitions)
- System-event breadcrumbs (battery, airplane mode, screen on/off)
- App and Activity lifecycle breadcrumbs
- Low-memory and configuration-change breadcrumbs
- Screenshot attachments
- View-hierarchy attachments
2.5 Approximate Location
When the app starts, our backend may derive an approximate location such as country, region, or city from the IP address used to contact the service, so the app can display current-location information, localize server choices, and diagnose routing issues. When you choose a VPN server region (for example, “United States” or “Germany”), that selection is sent to our backend so we can route you to the appropriate VPN gateway. We do not request, collect, or have access to your precise location, GPS coordinates, or Android location services.
2.6 VPN Traffic
The TuxlerVPN Mobile Android app uses Android’s VpnService API and the WireGuard protocol to route your internet traffic through VPN servers we operate. While the VPN is active:
- Your traffic is encrypted between your device and our VPN servers.
- DNS queries are routed through the VPN tunnel to a Tuxler-operated resolver. If the primary resolver is unreachable, your device falls back to Quad9 (
9.9.9.9), a Swiss non-profit public DNS resolver (see §4). - Your device is not used as a server, relay, peer, or exit node for any other user. TuxlerVPN Mobile is a client-only VPN.
- The app does not modify or redirect traffic from other apps for advertising or monetization.
- The app’s own service traffic, such as connection setup, disconnect requests, billing verification, support links, and crash reporting, may go directly to TuxlerVPN Mobile or its processors over HTTPS instead of being routed through the VPN tunnel. This is needed so the app can manage and repair the tunnel while the VPN is active.
- While the VPN is active, the app measures your connection’s throughput on your device for a single purpose: to notice when a free user is nearing their speed limit and show an in-app prompt to upgrade to Premium. That is the only thing this measurement is used for. It stays on your device, is never transmitted to us or stored on our servers, and the samples are discarded when the session ends.
Traffic and metadata logging: As with any VPN provider, our gateway infrastructure must process packets while routing your active connection, and our DNS resolver handles DNS queries while it is selected for the tunnel. We do not inspect, monetize, or retain the content of your VPN traffic, meaning the websites you visit, the data you upload or download, or DNS queries themselves. We also do not retain connection metadata (such as session timestamps, originating IP address, bandwidth used, or which gateway was selected) after a session closes. This information is held only for the duration of the active session and is discarded on disconnect.
2.7 Cookies (Website Only)
Our website at tuxlervpn.app currently sets only strictly-necessary cookies (required for basic site functionality and security). We do not currently use analytics, advertising, or social-media tracking cookies, and no third-party cookies are placed on your device. A cookie consent banner is already deployed for visitors in opt-in consent jurisdictions, and we will require your explicit consent through it before any non-essential cookie is set. Cookies are not used by the Android app. See our Cookie Policy for full details.
2.8 What We Do Not Collect
The TuxlerVPN Mobile Android app does not collect:
- Your name, address, phone number, or government identifiers
- Your precise location (GPS coordinates)
- Your contacts, calendar, photos, videos, or files
- Your messages (SMS, email content, in-app chat content from other apps)
- The content of your browsing while connected to the VPN (URLs visited, websites’ content, payloads)
- Your Google Advertising ID or any advertising identifier
- Data from other apps on your device
The app does not include any advertising SDK, attribution SDK, or general-purpose analytics SDK other than the Sentry crash reporter described in Section 2.4.
The only time TuxlerVPN Mobile sees your email address is if you write to [email protected] or reply to a support thread we have started with you. The app does not collect or transmit your email for account creation, Premium verification, or Google Play ratings/reviews, and never accesses your inbox or your existing emails.
3. LEGAL BASIS FOR PROCESSING PERSONAL DATA
TuxlerVPN Mobile processes personal data under the following legal bases:
• Performance of a Contract: Necessary to provide the VPN Service and to verify your subscription.
• Legal Obligations: Compliance with tax laws, fraud prevention, and other legal requirements.
• Consent: Where you have explicitly agreed to optional processing or where consent is required by law. Core service, security, subscription, support, and crash-reporting processing described in this Policy relies primarily on performance of a contract, legal obligations, and legitimate interests, as applicable.
• Legitimate Interests: Maintaining service stability, investigating bugs, and protecting our infrastructure from abuse. Our legitimate interests do not override your fundamental rights and freedoms.
4. SHARING YOUR PERSONAL DATA
TuxlerVPN Mobile does not sell or rent your personal data. We share data only with the following categories of processors, as needed to operate the Service:
• Google LLC (Google Play Billing): Subscription management and payment processing for Google Play purchases.
• Sentry (Functional Software, Inc., USA): Crash reports and diagnostics.
• Customer-support provider (USA): Email-based customer support delivered by a third-party processor.
• Quad9 (Quad9 Foundation, Switzerland): Fallback DNS resolution. When you connect to a TuxlerVPN gateway, your device is configured with a primary Tuxler-operated DNS resolver and a Quad9 fallback. DNS query metadata reaches Quad9 only when the primary resolver is unreachable. Quad9 is a Swiss-based non-profit foundation operating a global anycast resolver under a public no-logs policy.
• Cloud and hosting infrastructure providers: Hosting providers lease our backend servers, VPN gateway servers, and supporting infrastructure to us under data-processing agreements that meet the requirements of GDPR Article 28. Under those agreements, hosting providers act as sub-processors and do not operate the VPN service or process VPN traffic content on our behalf; in the ordinary course they see only the encrypted network traffic transiting their infrastructure (see §2.6).
• Legal Compliance: We may disclose data in response to valid legal requests under Panamanian law and applicable international regulations, after reviewing the validity of the request.
• Business Transfers: In the event of a merger, acquisition, or corporate restructuring.
5. INTERNATIONAL DATA TRANSFERS
TuxlerVPN Mobile is headquartered in Panama (the data controller). Personal data may also be processed in the following jurisdictions, depending on which processor is involved:
• United States. Sentry crash reporting (Functional Software, Inc.) and customer-support delivery.
• Switzerland. Fallback DNS resolution by Quad9 (Quad9 Foundation, Zurich). Quad9 operates a global anycast resolver; the specific node serving your queries depends on Quad9’s routing. Queries reach Quad9 only when the primary Tuxler-operated resolver is unreachable.
• Canada, the United States, and/or the Netherlands. Our backend infrastructure providers operate data centers in these countries. The specific data center serving your requests depends on routing.
• Various countries worldwide. VPN gateway servers operated by Tuxler on infrastructure leased from hosting providers are deployed in multiple regions to provide the server-selection options shown in the app. VPN traffic content is not logged, and VPN-session metadata is not retained after disconnect (see §2.6).
Where data is transferred outside the European Economic Area (EEA) or the United Kingdom, we rely on Standard Contractual Clauses approved by the European Commission and the UK Addendum where applicable, or on the recipient’s certification under a recognised adequacy framework. A copy of the relevant SCCs is available on request from [email protected].
6. USER RIGHTS UNDER GDPR, CCPA, AND OTHER REGULATIONS
Depending on your jurisdiction, you may have the following rights:
• Access: Request a copy of your personal data.
• Rectification: Correct inaccurate or incomplete data.
• Deletion: Request deletion of your personal data (see Section 11 for the deletion procedure).
• Restriction: Limit how we process your data.
• Objection: Object to certain types of data processing.
• Data Portability: Obtain your data in a structured, machine-readable format.
• Withdraw Consent: Withdraw consent for processing that is based on consent, without affecting processing that occurred before withdrawal.
• Lodge a Complaint: File a complaint with your data protection authority.
For California residents under the CCPA / CPRA, you also have the right to opt out of the sale or sharing of personal information. The website footer carries a “Do Not Sell or Share My Personal Information” link that opens the cookie preference center, and we honor the Global Privacy Control (GPC) browser signal for advertising-related storage. We do not sell or share your personal information for cross-context behavioral advertising.
Because the app does not require you to register an account, we cannot verify requests by login. If you make a privacy-rights request, provide whichever identifiers you have available, such as the email address you used to contact support, your Google Play order ID for Premium purchases, the approximate dates and country from which you used the app, and any app-instance identifier if your app version exposes one or support asks you to provide it. If you uninstall the app before recording an exposed app-instance identifier, we may be unable to locate records tied only to that installation because there is no email account or profile attached to it.
To exercise any of these rights, contact [email protected].
7. DATA SECURITY
TuxlerVPN Mobile employs industry-standard security measures, including:
• Encryption in transit: All communication between the app and our servers uses HTTPS/TLS, and the VPN tunnel itself uses the WireGuard protocol.
• Network security: Cleartext traffic is disabled in the Android app. App-to-service traffic uses HTTPS/TLS, with host allowlisting in the app’s network layer.
• Access controls: Access to systems holding user data is restricted to authorized personnel and is reviewed.
• Regular security reviews of our application code and infrastructure.
No system is 100% secure. If we become aware of a data breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law.
8. DATA RETENTION POLICY
TuxlerVPN Mobile’s default position for VPN traffic is no retention: we do not record the content of your VPN traffic, the websites you visit, or your DNS queries. Some accountless service data is processed so the app can connect, verify entitlement, provide support, prevent abuse, and fix crashes. Specifically:
| Data category | Retention |
|---|---|
| App-instance UUID | Stored locally in the app’s private storage until you uninstall the app or clear app data. Backend copies, where created for VPN resource management, entitlement checks, abuse prevention, support, or diagnostics, are retained only as long as needed for those purposes and deleted on request where legally required. |
| Session token | Stored locally until expiry, refresh, logout-equivalent cleanup, app data clearing, or uninstall. Backend validation state is retained for the token lifetime or until no longer needed for service security. |
| Play Integrity token | Used to validate that a request comes from a genuine app installation and to issue or validate a session token. Not used for advertising or cross-app tracking. |
| Device manufacturer, device model, Android version, Android SDK version, app version, build number | Held as needed to provide compatible VPN configurations, diagnose service issues, and investigate crashes. |
| Approximate location derived from IP address and server-region selection | Used for app display, routing, and troubleshooting. Not precise GPS location. |
| Connection metadata (session timestamps, originating IP, bandwidth, gateway used) | Not retained after the session closes (see §2.6) |
| VPN traffic content, DNS queries, browsing history | Never recorded |
| Sentry crash reports and diagnostics | Retained by Sentry on its standard schedule (typically 90 days) and then deleted |
| Google Play subscription token and purchase payload (Premium users) | Retained while needed to verify entitlement and to handle support, refunds, and abuse prevention. Records that must be kept for tax and accounting are retained for the longer period required by applicable law, and may persist after a deletion request to the extent the law requires. Google holds the underlying transaction receipts; no full payment-card details are held by TuxlerVPN Mobile. |
| Support communications (email correspondence with [email protected]) | Retained while the request is active; deleted after 90 days of inactivity on the support thread, or earlier on request |
When a retention period expires, or when you request deletion under §11, the relevant data is securely deleted or irreversibly anonymized. Two categories are handled differently and worth distinguishing: routine support correspondence is short-lived — deleted after 90 days of inactivity, or earlier on request — while financial and tax records tied to a Premium purchase, such as Google Play transaction records, are kept for the longer period required by applicable tax and accounting law and may be retained after a deletion request to the extent the law requires.
9. CHILDREN’S PRIVACY
TuxlerVPN Mobile does not knowingly collect data from individuals under 18 years of age. Our Services are intended for users aged 18 and above. If we learn that we have collected personal data from a minor, we will delete it promptly. If you believe a child has provided us with personal data, please contact [email protected].
10. GOVERNING LAW AND DISPUTE RESOLUTION
This Privacy Policy is governed by the laws of Panama. Disputes shall be resolved through binding arbitration under Panamanian law, unless otherwise required by applicable jurisdiction. This does not affect any non-waivable rights you have under your local consumer-protection laws.
11. HOW TO REQUEST DELETION OF YOUR DATA
Because TuxlerVPN Mobile does not have user accounts in the traditional sense, deletion is handled by removing the limited records tied to your installation, subscription, crash reports, or support correspondence. The categories that may persist beyond a single session, and which we will purge on request where identifiable and not legally required, are:
- The local app-instance UUID stored on your device, which you can remove by uninstalling the app or clearing app data.
- Backend records tied to an app-instance UUID, session token, entitlement check, server-region selection, or support request.
- Crash and diagnostic logs at Sentry; we can attempt to locate matching records using approximate device model, Android version, app version, dates, and any identifier available in the diagnostic context.
- Support communications you have sent us, including any email correspondence with [email protected].
Premium subscriptions may generate entitlement, refund, fraud-prevention, and tax/accounting records tied to a Google Play purchase token or order ID. We will delete or anonymize those records on request once they are no longer needed to provide Premium, resolve support/refund issues, prevent abuse, or comply with legal obligations.
To request deletion: email [email protected], or follow the dedicated walkthrough at Delete Your Account. Within 30 days we will action the request and confirm by reply.
Information that helps us locate your data:
- The email address you used to contact [email protected] (for support correspondence)
- Your Google Play order ID (Premium users), which we can match against the customer-support thread
- The approximate dates and country from which you used the app
- The app-instance identifier, if your app version exposes one or support asks you to provide it
Self-service options:
- Standard (free) users: uninstalling the app removes the local app-instance UUID and prevents further app data collection from that installation. To request deletion of any backend, support, or crash records that may still be identifiable, email us as above.
- Premium users: cancel your subscription through Google Play to stop billing. Uninstall the app to remove local app state. To request purge of backend entitlement, support, refund, or Sentry crash records, email us as above with your Google Play order ID where available.
12. CHANGES TO THIS PRIVACY POLICY
TuxlerVPN Mobile may update this Privacy Policy periodically. When we make material changes, we will:
- Update the “Last Updated” date below.
- Provide notice through the website, Google Play update notes, or in-app messaging where appropriate.
- Where required by law, obtain your renewed consent.
Continued use of our Services after updates indicates acceptance of the revised Privacy Policy.
Last Updated: 18 August 2026
13. CONTACT INFORMATION
For privacy-related inquiries, contact us at:
Tuxler Digital Services Corp.
World Trade Center 200-B, Suite 157, Calle 53 Este, Marbella, PA, Republica de Panama
Email: [email protected]
Data Protection Officer: Not appointed. Privacy and data-rights inquiries should be directed to the email address above.