Novol VPN Privacy Policy

Privacy Policy for Novol VPN

Last updated: September 3, 2026

Welcome to Novol VPN ("Novol", "we", "our", or "us"). This Privacy Policy explains how we collect, use, store, and protect information when you use the Novol VPN mobile application, website, backend, VPN servers, and related services (collectively, the "Service").

By using Novol VPN, you agree to the practices described in this Privacy Policy and our Terms of Use.

1. Overview

Novol VPN is designed with privacy and security as core principles. Our goal is to provide secure, encrypted internet access while minimizing data collection wherever possible. The app does not require account registration for its core VPN features.

  • We do not sell your personal information to third parties.
  • We do not inspect the contents of your internet traffic.
  • We do not log browsing activity: we do not collect or store visited domains, DNS queries, browsing history, or the contents of VPN traffic.
  • We use limited operational data only to run the VPN tunnel, account for the free daily quota, manage subscriptions across devices, process purchases, prevent abuse, and provide support.

2. Information We Collect

2.1 Anonymous Account and Device Identifiers

Novol VPN does not require an email address, username, or password to use the core VPN service. The app creates and stores technical identifiers needed to operate the Service, including:

  • An anonymous account ID — a random UUID generated by the app that is not tied to your email address, name, or other personal identity
  • A device ID used to register and manage VPN access for that device
  • A hash of the device token used to authenticate the device to the Service
  • A WireGuard public key and an assigned VPN tunnel IP address
  • The selected VPN server ID / location and related server access status
  • Subscription entitlement status and purchase linkage identifiers

We use this information to:

  • Operate and maintain the encrypted VPN tunnel
  • Account for and enforce the free daily quota
  • Manage subscription and entitlement status across your devices
  • Authorize access to free and Premium VPN features
  • Restore purchases and sync entitlement status across devices
  • Prevent abuse and protect service reliability
  • Provide customer support

2.2 VPN Connection and Usage Information

To operate the VPN tunnel and enforce the free daily quota, we may process limited connection metadata, including:

  • Connection start and end timestamps
  • Session duration
  • Traffic volume transferred during the session (in bytes)
  • Server ID / location and device ID associated with the VPN session
  • Approximate country or region used for routing, regional availability, and fraud prevention
  • Operational status such as whether a VPN peer is registered or synchronized

VPN servers necessarily receive your device's source IP address to establish a network connection. We do not use this information to create browsing profiles. We do not log browsing activity: we do not log visited domains, DNS queries, websites or apps accessed through the VPN, or the contents of your traffic.

2.3 Payment Information

Payments and subscriptions are processed by third-party providers, including:

  • Apple App Store and StoreKit for in-app purchases and subscription restoration
  • Google Play Billing for purchase verification on Android, where available
  • YooKassa for regional card payments for users in Russia and similar regions, where available

We do not store full credit card numbers, Apple or Google payment credentials, or card security codes on our servers. Card details for YooKassa payments are processed by YooKassa; we may receive payment amount, payment status, and transaction identifiers as needed. We may also store payment provider identifiers, product period, entitlement expiration time, and related metadata needed to activate Premium access, prevent duplicate processing, handle refunds, and provide support.

2.4 Device, Diagnostics, and Technical Information

To maintain service reliability and prevent abuse, we may collect limited technical data, including:

  • Device type
  • Operating system version
  • App version
  • Crash reports, stack traces, and app hang diagnostics
  • Performance and reliability metrics
  • Network error information and API request status

This data is used strictly for:

  • Service stability
  • Fraud prevention
  • Performance optimization
  • Technical troubleshooting

3. Information We Do NOT Collect

Novol VPN is built to minimize logging. We do not log browsing activity. We do not collect or store:

  • Browsing history
  • Visited domains or websites
  • DNS queries or DNS requests
  • IP addresses associated with browsing activity
  • VPN traffic contents or payloads
  • Messages, files, or transmitted data
  • Persistent traffic activity logs

We do not monitor, inspect, or analyze the content of your encrypted VPN traffic, DNS queries, or visited domains.

4. VPN Infrastructure & Security

All VPN traffic is encrypted in transit using industry-standard protocols (including WireGuard). We implement technical and organizational safeguards designed to protect your information, including:

  • Encrypted communications
  • Secure server infrastructure
  • Access controls
  • Authentication protections
  • Infrastructure monitoring
  • Limited internal access to systems

No method of transmission or storage is 100% secure, but we continuously work to maintain strong security standards.

5. Analytics & Diagnostics

We may use crash reporting and diagnostic tools (including Sentry) to improve the Service and investigate failures. Personally identifiable information (PII) is disabled for diagnostics and is not sent to the diagnostics provider. Diagnostics may include:

  • App performance metrics
  • Crash diagnostics and stack traces
  • App version, device model, operating system version, and event timestamps
  • Network request status and error messages
  • Technical metadata that diagnostic providers may receive, such as IP address, solely for security and delivery of the diagnostic service

Diagnostics are used to improve reliability and service quality. They are not used to record browsing history, visited domains, DNS queries, or the contents of VPN traffic.

6. Cookies & Similar Technologies

If Novol VPN provides a website or web dashboard, we may use cookies or similar technologies for:

  • Authentication
  • Session management
  • Security
  • Website analytics
  • Preference storage

You may control cookies through your browser settings.

7. Third-Party Services

The Service may integrate with third-party providers, including:

  • Apple App Store, StoreKit, and App Store Server APIs for subscriptions and purchase verification
  • Google Play Billing for purchase verification on Android, where available
  • YooKassa for regional card payments (for users in Russia and similar regions): YooKassa processes card details; we may receive payment amount, status, and transaction identifiers
  • Cloudflare Workers and D1 for backend API, entitlement, server, and quota data
  • Novol-controlled VPN servers for encrypted VPN connectivity and WireGuard peer configuration
  • Apple iCloud Key-Value Store for optional cross-device entitlement synchronization
  • Sentry for error diagnostics and reliability monitoring (PII disabled; personal data is not sent)
  • FitSpace/Vercel hosting infrastructure for the public legal pages

These providers process limited information necessary to deliver their respective services. We do not share browsing history, visited domains, DNS queries, or VPN traffic contents with these providers because we do not collect that information.

8. Data Retention

We retain operational and personal information only for as long as necessary to:

  • Provide the Service
  • Maintain VPN access, server assignments, and Premium entitlements
  • Enforce free quota limits and prevent abuse
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements

Free quota records and VPN session duration records are retained only as needed for quota enforcement, abuse prevention, support, and service reliability. Users may request deletion of associated personal information where legally permitted.

9. International Data Transfers

Your information may be processed or stored in countries outside your place of residence. By using the Service, you acknowledge that your information may be transferred to jurisdictions with different data protection laws. We take reasonable measures to ensure appropriate protection of personal data.

10. Children's Privacy

Novol VPN is not intended for children under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that information from a child has been collected without appropriate consent, we will delete it promptly.

11. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access your personal information
  • Correct inaccurate data
  • Delete your data
  • Restrict processing
  • Object to certain processing
  • Request data portability
  • Withdraw consent

To exercise these rights, contact us using the information in Section 16 below.

12. GDPR & EEA Users

If you are located in the European Economic Area (EEA), United Kingdom, or similar jurisdictions, processing of personal data is based on:

  • Contractual necessity
  • Legitimate interests
  • Legal obligations
  • Consent where applicable

You may also lodge complaints with your local data protection authority.

13. California Privacy Rights

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA/CPRA), including rights to know what personal information is collected, request deletion, correct inaccurate information, and limit certain uses of data. Novol VPN does not sell personal information.

14. Abuse Prevention & Legal Compliance

While Novol VPN maintains a strict privacy-focused approach, we may process limited operational data when necessary to detect abuse or fraud, enforce Terms of Service, protect infrastructure, and comply with applicable legal obligations. We only disclose information when legally required to do so or when necessary to protect the Service, users, or third parties.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If material changes are made, we may notify users through:

  • The app
  • Website notices
  • Email notifications

Continued use of the Service after updates constitutes acceptance of the revised Privacy Policy.

16. Contact Us

For privacy-related questions, data requests, or support, contact us at support@fitspace.app.

This document is hosted on the FitSpace website for stable access via a permanent link.