Privacy Policy

Updated 2 August 2026
🌐 RU / EN

This Privacy Policy (the “Policy”) describes what data MVPN (the “Service”) collects, what data the Service deliberately does not collect, how collected data is used, and what rights the User has.

By using the Service, the User confirms that they have read this Policy and accept its terms. If the User does not agree with the terms, they must stop using the Service.

1. General provisions

  1. 1.1. This Policy governs how information provided by the User when using the Service is processed and protected.
  2. 1.2. By using the Service, the User confirms their agreement with the Policy. If the User does not agree with the terms, they must stop using the Service.
  3. 1.3. The Service follows the principle of data minimisation: it processes only what is required to deliver paid access and keep it secure.

2. User security as a priority

  1. 2.1. The security and privacy of the User are a priority of the Service. Where completeness of analytics or convenience of administration conflicts with the User’s privacy, the Service chooses privacy.
  2. 2.2. As a consequence of that choice, the Service deliberately forgoes data it would be technically capable of collecting: records of network activity, location, and device characteristics.
  3. 2.3. The limitations in Section 3 apply to the Service’s own administrators. Service personnel have no technical means to determine which resources a particular User accesses.

3. Data the Service does not collect

  1. 3.1. The Service keeps no logs of the User’s network activity. The following is not recorded, not stored and not disclosed:
    • websites visited, domain names, destination addresses and ports;
    • the User’s DNS queries;
    • the content of transmitted traffic;
    • the IP address from which the User connects to the Service;
    • browser, client application and its version, operating system;
    • internet provider, country and city of the User.
  2. 3.2. This follows from how the Service is built, not from a promise: connection logging on the servers is disabled at the configuration level, and the Service’s database contains no fields capable of holding a connecting address, device characteristics, internet provider or location. The Service has physically nowhere to store such information.
  3. 3.3. Compliance with clause 3.1 is verified by automated tests on every change to the Service’s source code: a change that reintroduces collection of the listed data does not pass.
  4. 3.4. Which resources the User accesses, when, and for what purpose is known only to the User. The Service does not hold such information and is unable to reconstruct or reproduce it — including in response to a request from a third party.

4. Data the Service processes

  1. 4.1. To provide access, the Service processes:
    • the Telegram user identifier and username, as supplied by the messenger when the bot is contacted;
    • identifiers of devices the User has added to their own account;
    • the volume of transferred traffic in bytes and the server label — with no information whatsoever about the content or destination of that traffic;
    • subscription status and expiry, payment records and redeemed promo codes;
    • the fact and time at which a device requested its connection configuration.
  2. 4.2. This data reveals the state of a connection and the volume consumed, but does not make it possible to establish the content or direction of the User’s network activity.
  3. 4.3. The Service does not require passport details, documents, photographs, a phone number, an email address, or any other information not listed in clause 4.1.

5. Use of information

  1. 5.1. The Service uses the information received exclusively to:
    • provide and maintain the paid access;
    • communicate with the User — subscription notices and support requests;
    • protect the infrastructure: detect abuse by volume of consumption and prevent attacks on the Service;
    • assess server load in an aggregated, non-identifying form.
  2. 5.2. The Service does not use User data for advertising or profiling, and does not pass it to third-party advertising or analytics systems.

6. Disclosure to third parties

  1. 6.1. The Administration does not disclose processed data to third parties, except where:
    • this is expressly required by applicable law;
    • it is necessary to perform obligations towards the User — for example, when processing a payment;
    • the User has given explicit consent.
  2. 6.2. Lawful requests from authorised bodies are met in respect of the data the Administration actually holds. The data listed in Section 3 is not held by the Administration and therefore cannot be provided, whether on request or otherwise.
  3. 6.3. The Administration does not build or maintain technical means designed to monitor the User’s network activity.

7. Storage and protection

  1. 7.1. The data listed in Section 4 is retained for as long as needed to provide access and to meet statutory record-keeping requirements for settlements, after which it is deleted or anonymised.
  2. 7.2. The User may request deletion of their account. Subscription, device and accumulated traffic records are then deleted; payment records are retained to the extent required for accounting and tax purposes.
  3. 7.3. The Administration applies reasonable, state-of-the-art measures to protect data, but does not guarantee absolute security of information transmitted over the Internet.

8. Limits of this Policy

  1. 8.1. This Policy describes the conduct of the Service and its infrastructure. The Service does not control, and is not responsible for, data collection carried out by the User’s internet provider, the operators of the resources visited, the device manufacturer, or any other third party outside the Service’s infrastructure.
  2. 8.2. The Service does not and cannot guarantee absolute anonymity on the Internet: it also depends on the User’s own actions and on the software they use.
  3. 8.3. Use of the Service does not relieve the User of compliance with the law applicable to them.

9. Disclaimer

  1. 9.1. The User understands and agrees that transmitting information over the Internet always carries risk.
  2. 9.2. The Administration is not liable for loss, theft or disclosure of data caused by third parties or by the User.

10. Changes to the Policy

  1. 10.1. The Administration may amend this Policy. The current version is always available at this address, and the date of the last change is shown at the top of the document.
  2. 10.2. Changes that narrow the User’s privacy relative to Sections 2 and 3 take effect no earlier than 14 calendar days after the new version is published.
  3. 10.3. Continued use of the Service after changes take effect constitutes acceptance of the new version.