Legal

Privacy Policy

Last updated: July 15, 2026

MistyVPN ("MistyVPN", "we", "us", or "our") provides a no-logs virtual private network (VPN) service across iPhone, iPad, Android, Mac, and Android TV. MistyVPN is a trading name of Misty Tech Ltd, a company registered in England & Wales (company no. 17269421), with its registered office at Siu Offices, 4–6 Greatorex Street, London, E1 5NF, United Kingdom. Misty Tech Ltd is the data controller for the purposes of this Privacy Policy. This policy explains what we collect, the things we deliberately do not collect, how we use and share information, and the rights you have over your data. It applies to our apps, our website, and our account and subscription systems.

Our guiding principle is simple: we cannot lose, leak, or be compelled to hand over what we never collect. We designed MistyVPN to run on the minimum amount of personal data possible.

1. Our no-logs commitment

While you are connected to MistyVPN, we do not collect, monitor, or store:

  • Your browsing history, or the websites and apps you use
  • The content of your traffic
  • The destinations (IPs or domains) you connect to
  • Your DNS queries
  • Your original (source) IP address
  • Connection timestamps, session duration, or bandwidth logs that could be tied to your identity or activity

We keep no records that could be used to match VPN activity to an individual user. Because these logs do not exist, there is nothing for us to sell, leak, or disclose in response to a request.

2. Information we collect

We collect only what is necessary to operate accounts, deliver and secure the service, process subscriptions, and fix problems.

Account data

If you create an account, we store your email address and a hashed (irreversibly scrambled) version of your password. Every user is also assigned a random account identifier. You can use the free tier without creating an account.

Device data

We generate a random device identifier for each installation. It is used to manage your devices, enforce concurrent connection limits, and deliver your free minutes. It is not linked to any activity log and does not identify you personally.

VPN credentials

To connect, your device holds per-device VPN credentials (such as a username, password, and protocol keys). Where possible these are stored in your device's secure keychain rather than on our servers, and are rotated when you sign in or out.

Subscription and payment status

Subscriptions are purchased and managed through the Apple App Store, Google Play, or — on the web — Stripe. We receive a validation of your subscription status (active, expired, cancelled) and a transaction identifier. We do not receive or store your full card number or bank details; those are handled entirely by the store or payment processor.

Diagnostic and crash data

Released apps send anonymized crash and error reports through Sentry so we can find and fix bugs. These reports are privacy-scrubbed: we strip authentication tokens, VPN credentials, passwords, usernames, and IP addresses before they are sent, and reporting is disabled entirely in development builds.

Aggregate operational data

We use non-identifying, aggregate metrics — such as total server load and overall service health — to keep the network reliable and fast. This data is not tied to individual users or their activity.

Temporary connection data

To enforce the number of devices allowed on one account, our servers briefly process a connection's network address together with your random device identifier while the connection is active. This information is transient, held only for the life of the session (roughly a few minutes), and is not written to any activity log or retained afterwards.

Support communications

If you contact us (for example, by email or chat), we keep the content of that correspondence so we can help you and improve our support.

Website data

Our website uses essential cookies and privacy-respecting analytics needed to run the site, remember your preferences, and process web payments. See Cookies below.

3. Information we do not collect

To be explicit, MistyVPN does not collect or retain: your browsing or traffic content, the sites and services you reach through the VPN, your DNS queries, your real IP address, or any record that links your activity back to you. We do not sell your personal data, and we do not use your data for advertising or profiling.

4. How we use your information

  • To create and manage your account and devices
  • To provide, maintain, and secure the VPN service
  • To validate and manage subscriptions, free minutes, and billing status
  • To prevent abuse and enforce connection limits
  • To diagnose crashes and improve reliability and performance
  • To respond to your support requests
  • To comply with legal obligations that apply to us

5. Legal bases for processing (GDPR)

If you are in the European Economic Area or the United Kingdom, we process your data on these legal bases: performance of a contract (to provide the service you signed up for), legitimate interests (to secure our network, prevent abuse, and improve the product, balanced against your rights), consent (where required, which you may withdraw at any time), and legal obligation (where the law requires it).

6. Payments

In-app subscriptions are processed by the Apple App Store and Google Play under their own terms and privacy policies. Web subscriptions are processed by Stripe. Payment details you enter are handled by those providers — MistyVPN never sees your full card or bank information. You can view, change, or cancel a subscription from your store account or the account portal at any time.

7. How we share information

We do not sell your personal data. We share the limited data above only with service providers who help us run MistyVPN, and only as needed:

  • Apple and Google — to validate and manage in-app subscriptions.
  • Stripe — to process web subscription payments.
  • Sentry — to receive privacy-scrubbed crash and error reports.
  • Infrastructure and hosting providers — to operate our servers and backend.

These providers are bound by confidentiality and data-protection obligations and may only use the information to provide their service to us. We may also disclose information if required by valid legal process — but because we keep no activity logs, we cannot produce records of what you did while connected.

8. International data transfers

MistyVPNoperates servers in many countries so you can connect from wherever you need to. Account and subscription data may be processed in countries other than your own. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

9. Data retention

We keep account and subscription data only for as long as your account is active, or as needed to meet legal, tax, or accounting obligations. When you delete your account, we remove your associated account data. Because we keep no activity logs, there is no browsing history to retain or delete. Transient connection data is discarded when your session ends.

10. Security

We protect your data with encryption in transit, hashed passwords, scoped access controls, and strict limits on who can access our systems. No method of transmission or storage is perfectly secure, but keeping minimal data is itself our strongest safeguard: there is very little to expose. If a breach affecting your personal data occurs, we will notify affected users and regulators as required by law.

11. Your rights

EEA / UK (GDPR)

You have the right to access, correct, delete, or export your personal data; to restrict or object to certain processing; to withdraw consent; and to lodge a complaint with your local data protection authority.

California (CCPA/CPRA)

You have the right to know what personal information we collect, to request its deletion, to correct it, and to opt out of its sale or sharing. We do not sell or share your personal information, and we will never discriminate against you for exercising your rights.

You can delete your account and its data directly in the app at any time. For any other request, contact us at [email protected] and we will respond within the timeframes required by applicable law.

12. Children

MistyVPN is intended for adults and is not directed at children. We do not knowingly collect personal data from anyone under 18 (or under 13 where applicable). If you believe a child has provided us personal data, contact us and we will delete it.

13. Cookies

Our website uses essential cookies required to run the site and process payments, and privacy-respecting analytics to understand how the site is used. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings.

14. Third-party links

Our site and apps may link to third-party websites or services we do not control. This policy does not cover them; please review their own privacy policies.

15. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, announced in the app or by email. Continued use of MistyVPN after an update means you accept the revised policy.

16. Contact us

Questions, requests, or complaints about privacy? Email us at [email protected] and we will be happy to help.