privacy policy

notVPN Privacy Policy

We use the minimum data needed to operate your dashboard and subscription. Our core principle: notVPN does not log customer traffic, browsing history, DNS queries or connection contents.

Last updated: May 2026

1. Who we are

notVPN is a managed internet access service built on subscription-based tunneling infrastructure.

The service operator and contact company for legal, payment, administrative and privacy matters is EMIBA ENGINEERING SAS, SIRET 94159971400024, RCS Limoges.

Registered address: LIMOGES SIS, 1 PLACE JOURDAN, 87000 LIMOGES, France. Share capital: 400 EUR. Contact email: soulence.dd@proton.me. For support questions, you may also contact us via Telegram: https://t.me/xNotVPNx.

2. Our privacy principle

notVPN does not log customer traffic.

We do not store browsing history, websites visited, apps or services used through the connection, DNS queries, traffic contents, browsing activity or full connection history.

We do not collect this data because we do not need it to provide the service.

3. What data we collect

We collect only the minimum data needed to create, access and manage your dashboard.

  • email address;
  • Telegram username or Telegram ID;
  • public dashboard token;
  • selected plan;
  • subscription status;
  • subscription start and expiration dates;
  • total traffic usage under your plan limit;
  • one-time verification data, such as code status, expiration time and attempt count;
  • technical identifiers needed to issue and manage your subscription.

4. Traffic and plan limits

notVPN plans may include a traffic limit. To apply this limit, we may process the total amount of traffic used by your subscription.

For example, the system may know that your plan has used a certain amount of GB.

This does not mean that we know what websites, apps, domains or services you used. We do not store destination logs, traffic content logs or browsing activity logs.

5. Why we process data

  • to create and maintain your dashboard;
  • to let you log in through email or Telegram;
  • to issue and manage your subscription link;
  • to show your plan, status, expiration date and traffic usage;
  • to protect against unauthorized account access;
  • to provide customer support;
  • to prevent abuse of the service;
  • to comply with applicable legal obligations.

6. Legal basis

Where European Union, European Economic Area or other applicable data protection rules apply, our legal basis may include performance of a contract, legitimate interests, legal obligation or consent where required.

7. Cookies and local storage

notVPN may use strictly necessary cookies or similar technologies to keep you logged in, remember your selected language, protect registration and login flows, and maintain basic dashboard security.

In the current version of the service, we do not use advertising cookies.

8. Customer support

Support for a specific subscription is available only to the owner of the personal dashboard — the user whose email or Telegram is linked to the account.

This protects users from unauthorized requests by third parties.

9. Fair use and abuse protection

notVPN subscriptions are intended for personal use.

You may use one subscription on several personal devices if your app supports subscription import. All traffic is consumed from the shared limit of the selected plan.

  • do not publish your subscription link publicly;
  • do not resell access;
  • do not use one personal subscription as a shared account for a large group;
  • do not use the service for attacks, spam, fraud, malware, illegal scanning or other abuse;
  • do not attempt to bypass technical limits of the plan.

10. Data retention

We keep personal data only for as long as necessary to operate the service, support users, maintain subscription records, prevent abuse and comply with applicable legal obligations.

When data is no longer needed, we delete or anonymize it.

11. Payments

If payments are enabled, payment processing may be handled by third-party payment providers.

To process a payment, the payment provider may receive data required for the transaction: order identifier, amount, currency, payment status and technical payment-flow data.

notVPN does not store full payment card data, banking passwords or confirmation codes.

We may store the payment order id, payment status, internal EUR amount, provider charge amount in RUB, the EUR/RUB exchange rate used, provider status, timestamps, transaction reference and related technical data needed to activate or extend a subscription, support the user and maintain accounting records.

12. Service providers

We may use providers for hosting, email delivery, Telegram bot functionality, payments, availability monitoring, databases and backups.

We do not sell personal data.

13. International transfers

notVPN infrastructure or providers may be located in different countries. Where personal data is transferred outside the European Economic Area or the user's country, we aim to use appropriate safeguards under applicable law.

14. Security

We use reasonable technical and organizational security measures, including data minimization, separation between public tokens and internal technical identifiers, restricted administrative access, secure verification flows and infrastructure access controls.

No online service can guarantee absolute security, so we also minimize the amount of personal data we hold.

15. Your rights

Depending on applicable law, you may have the right to request access, correction, deletion, restriction of processing, a copy of your data, object to processing or withdraw consent.

Depending on applicable law, you may also lodge a complaint with a competent data protection authority.

16. Legal requests

We may respond to valid legal requests where we are legally required to do so.

Because we do not log customer traffic, we cannot provide traffic logs, browsing history, visited websites, DNS history, communication contents or destination history that we do not store.

We may only provide limited information that we actually hold, such as email, Telegram identifier, public account token, plan, subscription status, aggregate traffic usage or payment/subscription records.

17. Changes to this policy

We may update this Privacy Policy from time to time. The latest version will be available on our website.