Privacy Policy
This policy explains what data sNova VPN handles, why, for how long, and what you can ask us to do with it. It covers the sNova VPN apps for iPhone and iPad, our VPN servers, and the website at snovavpnapp.com.
1. Who is responsible
The controller of your personal data is High Star Co Ltd, Bulgaria. You can reach us at support@snovavpnapp.com for any question about this policy or about your data.
2. What a VPN does with your traffic
When the VPN is on, your device sends its internet traffic through one of our servers. That server forwards the traffic to its destination and returns the answer to you. Websites you visit see the server's address instead of your own.
Our software does not keep a connection log. We do not record or store which sites and services you connect to, your DNS queries, or the contents of your traffic, and we do not build profiles of your online activity or sell such data. We do not use deep packet inspection.
Two honest qualifications, because a policy that overstates is worth less than one that does not.
We speak for our own software and systems. Traffic between you and our servers, and between our servers and the site you reached, crosses networks run by carriers and hosting providers. We do not control those networks, and in some countries they are required by law to keep records of their own. No VPN can promise otherwise, and we will not.
A server that carries traffic must handle addresses in memory in order to route packets, and our systems keep the operational records listed in section 3 — when a session ran, which node carried it, and how much data moved through it.
Your own address
Our servers see the address your device connects from — a server cannot answer a request without it. They do not write it down. It is not saved to our databases and it is not kept in logs beyond the handling of the request itself.
We can do this because we do not need your address to run the service. What identifies a device to us is the access we issue to it, and that already tells us how much it has used and lets us revoke it. The checks that other providers keep addresses for work here without them.
3. What we process
There is no account and no sign-up. Everything below is tied to an identifier that the app creates for your device — not to your name, email or phone number, none of which we have.
| Data | Why | How long |
|---|---|---|
| An identifier the app generates for your device (stored in the device keychain), plus device model and OS version | To apply your starting traffic allowance and referral bonuses, to remember your purchases, and to diagnose problems specific to a model or OS version | For as long as the service operates, or until you ask us to delete it |
| Two flags that Apple's DeviceCheck service stores for your device: whether the starting allowance and the referral bonus were already granted | So that reinstalling the app does not grant the allowance twice | Kept by Apple, tied to the device, not to you; we cannot read anything else from it |
| Amount of data transferred, in bytes, together with the country of the node and the protocol used | To apply the allowance and to detect abuse. We record how much moved, not what it was or where it went | For as long as the service operates |
| Connection records: when a session started and ended, and which node carried it | To operate the network, apply the allowance, and investigate incidents | For as long as the service operates |
| Referral activity: the invitation codes you create, how many were accepted, and the bonuses granted to you and to the people you invited | To grant bonuses and to prevent abuse of the referral programme | For as long as the service operates |
| Subscription status received from Apple | To know whether your subscription is active. Apple does not give us your card details | For as long as the service operates, and as required by accounting law |
| Diagnostics and product analytics: app launches, screens opened, connection successes and failures | To find bugs and understand which parts of the app work badly | Up to 14 months |
| Messages you send to support | To answer you | Up to 24 months |
We keep these records for the life of the service because the traffic allowance, the referral bonuses and your purchases must survive reinstalls and device changes. They are tied to the device identifier; we have no way to connect them to a person unless you write to us yourself.
4. What we never ask for
- Your name, email address, postal address, or date of birth.
- Your phone number.
- Your payment card details — Apple processes payments and never passes them to us.
- Access to your contacts, photos, microphone, camera, or precise location.
5. Legal grounds
Under the GDPR we rely on:
- Performance of a contract — for the VPN connection itself, traffic accounting, referral bonuses, and subscription status.
- Legitimate interests — for security, abuse prevention, and keeping the network running. We keep these records short and narrow for that reason.
- Legitimate interests — also for product analytics: app launches, screens opened, whether a connection succeeded, which versions have trouble. These events carry the device identifier. We read them to fix the app, not to build a picture of you.
- Legal obligation — for accounting records of purchases.
6. Who else is involved
We use a small number of service providers. Each of them receives only what it needs.
- Apple — distributes the app, processes payments, and tells us whether a subscription is active. Apple's own privacy policy applies to the purchase.
- Amazon Web Services and comparable hosting providers — run our VPN nodes and backend. Nodes are located in the countries offered in the app.
- Google (Firebase and BigQuery) — product analytics and the storage of the event history exported from Firebase into our own Google Cloud project. The events carry the device identifier described above and an installation identifier that Firebase creates itself, together with the app and OS versions, the device model and the language; Apple reports purchases and renewals into the same project. Like any service that receives a request over the internet, Google sees the address the request came from and derives an approximate country and city from it — while the VPN is on, that address is our node's, not yours. Our events themselves carry no domains, destinations or server addresses.
- Cloudflare and Resend (on Amazon SES) — carry our support email: Cloudflare receives messages sent to our addresses, Resend delivers our replies. They handle the address and text of the correspondence for that purpose only.
- Apple Search Ads — tells us, in aggregate, which campaign brought an install. This uses Apple's own attribution and does not involve the advertising identifier or tracking across other companies' apps.
We do not track you across other companies' apps and websites, we do not use the advertising identifier, we do not sell personal data, and we do not share it with data brokers or advertising networks for their own purposes.
7. Where data is stored and transferred
Our backend and our nodes run in data centres located in the European Union, the United Kingdom, the United States, Singapore and other countries listed in the app. When data leaves the European Economic Area we rely on the European Commission's Standard Contractual Clauses with the provider concerned.
8. Your rights
If the GDPR or a similar law applies to you, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or send it to another provider. Where we rely on legitimate interests, you can object to that processing at any time. New events will still arrive while you go on using the app: there is no switch for them.
Write to support@snovavpnapp.com. We answer within 30 days. If you believe we handled your request badly, you may complain to the Bulgarian Commission for Personal Data Protection or to the supervisory authority in your own country.
Deleting your data
There is no account to delete, but you can ask us to delete everything tied to your device. Write to support@snovavpnapp.com and include the device identifier shown in the app (open Settings and tap the version number at the bottom); we remove the records within 30 days. Deleting the app alone does not delete them, and deleting them does not cancel an active subscription — subscriptions are managed by Apple and must be cancelled in your Apple account settings.
9. Children
sNova VPN is rated 4+ because it contains no objectionable content, but it is not designed for children and we do not knowingly collect personal data from a child under 16. If you believe a child has given us data, write to us and we will delete it.
10. Security
Traffic between your device and our nodes is encrypted. Access to our servers requires key-based authentication and is limited to the people who operate them. There are no passwords, because there are no accounts. Database backups are kept for 14 days and then overwritten. No system is perfect, and we will tell affected users and the regulator if a breach puts your data at risk.
11. Lawful requests
We respond to requests from authorities only where they are legally valid and binding on High Star Co Ltd.
We do hold data, and we would rather say so plainly here than have you discover it later. We hold the device identifier, the volumes of traffic the device moved, its subscription status and its referral activity — everything listed in section 3. We do not hold your name, email or phone number, so we could not connect these records to a person ourselves. Where a request is lawful and binding on us, we are obliged to act on it under the applicable law.
What we cannot provide is a history of the sites you visited. Our software does not create one, so there is nothing to retrieve. This is a statement about our own systems, not about the carriers and hosting providers described in section 2.
12. Changes
If we change this policy in a way that matters, we will show a notice in the app before the change takes effect. The version and date at the top always identify the current text.