Transparency & no-logs
Exactly what we store, what we never store — and how you can check us.
What we store
- Your email address and account details — needed to run your subscription.
- A daily traffic total (GB) per account — used only to bill your plan's included traffic. Deleted automatically after 90 days.
- Payment status from our payment processor. We never see your full card details.
What we never store
- The websites you visit or the apps you use
- Your DNS queries
- The contents of your traffic
- Your source IP address tied to VPN activity
- Connection or session timestamps
- Bandwidth per destination or per site
Enforced in code, not just in policy
Our backend enforces a strict allowlist of operational fields. Anything resembling DNS, domains, URLs, browsing history or packet contents is rejected at code level and can never be written to our database. An automatic daily job purges operational metadata older than 90 days.
Warrant canary
As of the date below, nuVPN has never received a government or law-enforcement request for user data, has never been subject to a gag order, and has never handed user data to any third party. If this notice ever disappears — ask why.
Last reviewed: 19 August 2026
Don't trust — verify
- Connect and confirm your visible IP is your VPN server, not your home address: What is my IP?
- Run a DNS leak test while connected — all DNS queries should resolve through your VPN server only.
- Our Linux builds are GPG-signed — verify the signature against our public key: Download & verify
Independent audit
An independent no-logs audit by an external security firm is on our roadmap. Until then, this page states exactly what our code does — and our code keeps us honest.