PiVOT VPN
Privacy Policy
Key Principle: We believe that the internet should be free and private. Our primary mission is to ensure your online security while collecting the absolute minimum amount of information necessary to operate the service.
1. About the Application


We process your information in accordance with this Policy when you use the Pivot VPN application and its associated services.
2. The Core: No-Logs Policy


We adhere to a strict no-logs policy. This means that when using Pivot VPN:

We DO NOT track or record your online activities (visited websites, DNS queries).

We DO NOT collect or record your real IP address during the VPN tunnel operation. Your IP address may be used temporarily only during a speed test with your permission (see Section 3C).

We DO NOT store information about what content you download or transmit.

We DO NOT store VPN activity logs, and therefore, we have no technical ability to provide such data to third parties.
3. What Data We Process


To ensure the application functions correctly, we still require a minimal set of technical data.

A. Account Data
When creating an account:

Email: Used for account synchronization across multiple devices and access recovery.

Password: Stored in an encrypted (hashed) format. We do not know your actual password.

Google Sign-In: If you use Google authorization, we receive your email and profile name to create your account.

B. Technical Information
To provide a stable connection, we process:

Device ID: To link the device to your account and manage the connected devices limit.

Device Name and Type: (e.g., phone model) to display in the user's list of connected devices.

Inbound and Outbound Traffic Volume: To monitor traffic limits in the free version of the app. We only track the total volume of data without analyzing its content.

C. Location Data
The app may request access to geolocation solely to determine the nearest server when performing a speed test. Location data is not stored or shared with third parties.

D. Camera
The app may request camera access to scan QR codes when logging into your account. Images are not saved.

E. Payment Information
We do not store your bank card details. All transactions are processed through In-App Purchases.

4. Third-Party Services


We use a limited set of third-party services for app functionality:

Authentication and account data storage.

Install analytics to improve the app. This may use an anonymous advertising ID for the device.

Push notification delivery.

Subscription and purchase management.

Speed Test: When using the built-in speed test, your current IP address is temporarily transmitted to the testing servers.

None of these services have access to the content of your VPN traffic.
5. VPN Connection


We use modern secure protocols to establish a VPN connection. Connection configurations are provided through partner infrastructure, which receives only your VPN account ID and the selected server.
6. Legal Basis and Data Retention


We process data based on:

Contract performance: To provide you with the VPN service.

Consent: When you voluntarily register or contact support.

We store your data as long as your account is active. When an account is deleted, all personal data is removed immediately. Device IDs and traffic usage data are retained to ensure the correct operation of the service.
7. Your Rights


In accordance with international standards (including GDPR), you have the right to:

Access: Request a copy of the data we hold.

Rectification: Change incorrect data in your profile.

Erasure: Demand the deletion of your account and all associated data.

Objection: Withdraw consent for receiving notifications.
To exercise these rights, use the feedback form in the app or email us at hwilo.app.dev@gmail.com.
8. Security


We apply modern encryption standards to protect the VPN tunnel. All personal data in the database is stored in encrypted form. Access to servers is limited to a small circle of technical specialists.
9. Children


Persons under the age of 13 should not use the application without the consent of parents or legal guardians. If we become aware that we have received data from a child without such consent, we will delete it.
10. Changes to the Policy


We may update this policy. If changes are significant, we will notify you through the application.
Made on
Tilda