Table of Contents
1. Introduction
WINK VPN ("we", "us", "our") operates the WINK VPN mobile application (the "Service"). We are deeply committed to protecting the privacy and security of our users. This Privacy Policy explains in detail what information we collect, how we use it, how we protect it, and your rights regarding your personal data.
By using WINK VPN, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use our Service.
2. Information We Collect
2.1 Account Information
We collect minimal account information necessary to provide our service:
- Email address - required only for premium subscribers, used for account management and billing
- Username - chosen by the user for account identification
2.2 Device Information
To ensure app compatibility and performance optimization, we collect:
- Device type and model
- Operating system version
- App version installed
2.3 Connection Data
We collect limited connection data for service operation and quality assurance:
- Timestamps of VPN connections (date and time only)
- Server location selected
- Aggregate bandwidth usage (total data transferred, not content)
2.4 What We Do NOT Collect
- Browsing history - we cannot see what websites you visit
- DNS queries - your domain lookups are not recorded
- IP addresses of destinations - we don't track where your traffic goes
- Content of your traffic - all data passing through our VPN is encrypted and opaque to us
- Your original IP address - we do not associate your real IP with your VPN sessions
3. Data Encryption
Security is at the core of everything we build. WINK VPN employs multiple layers of industry-leading encryption to ensure your data remains private and secure at all times.
3.1 VPN Tunnel Encryption
All data transmitted through the WINK VPN tunnel is encrypted using AES-256-GCM (Advanced Encryption Standard with 256-bit keys in Galois/Counter Mode). This is the gold standard of symmetric encryption, offering both confidentiality and data integrity. A brute-force attack on AES-256 would require more energy than exists in the observable universe.
3.2 Key Exchange Protocols
For secure key exchange during the VPN handshake, we employ:
- RSA-4096 - 4096-bit RSA keys for initial authentication and key exchange
- ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) - provides forward secrecy with efficient key agreement
3.3 Transport Layer Security
All API communications and control channel data between your device and our servers use TLS 1.3, the latest and most secure version of the Transport Layer Security protocol. TLS 1.3 eliminates legacy cryptographic algorithms and reduces handshake latency.
3.4 Data at Rest
Any data stored on our servers (such as account information) is encrypted at rest using AES-256 encryption. Database access is restricted to essential services only through strict access control policies.
3.5 Perfect Forward Secrecy (PFS)
WINK VPN implements Perfect Forward Secrecy, meaning unique session keys are generated for each VPN connection. Even if a long-term key were somehow compromised, previously recorded sessions would remain encrypted and unreadable. Session keys are ephemeral and destroyed upon disconnection.
4. No-Log Policy
We operate under a strict no-log policy. This is not just a marketing claim - it is a core architectural principle built into how our systems work.
4.1 What We Do NOT Log
- Browsing activity or history
- Connection logs associated with IP addresses
- DNS queries or resolutions
- Traffic data or payload content
- Traffic destinations or metadata
- Session durations linked to user identity
4.2 What We MAY Log
For service quality and infrastructure management only:
- Aggregate bandwidth statistics - total server load, not attributable to individual users
- Connection timestamps - date/time only, with no associated IP address or user identity
- Crash reports - anonymized technical data to fix bugs and improve stability
5. How We Use Your Information
The limited information we collect is used exclusively for the following purposes:
- Service Delivery - to provide, operate, and maintain the VPN service
- Subscription Management - to process premium subscription payments and manage your account
- Service Notifications - to send important updates about your account, service status, or security alerts
- Performance Improvement - to analyze aggregate data for optimizing server performance and app stability
- Legal Compliance - to comply with applicable laws and regulations when legally required
We do not use your data for advertising, profiling, or any purpose beyond what is described above.
6. Data Sharing and Third Parties
We do NOT sell, rent, or trade your personal data to any third party.
6.1 Third-Party Services
We use the following trusted third-party services in our app:
- Firebase Analytics - anonymized usage analytics to understand how users interact with the app (no personally identifiable information is shared)
- Google Play Billing - secure payment processing for premium subscriptions (payment data is handled entirely by Google)
- Firebase Crashlytics - anonymized crash reporting to identify and fix technical issues
6.2 Legal Disclosure
We may disclose information if required by valid legal process (such as a court order), but only to the extent strictly required by law. However, because we do not collect browsing data, DNS queries, or IP addresses, we cannot provide information we do not have, even if legally compelled.
7. Data Retention
We retain data only for as long as necessary to fulfill the purposes outlined in this policy:
- Account data - retained while your account is active; deleted within 30 days of receiving a deletion request
- Connection metadata - automatically purged after 30 days
- Payment records - retained as required by applicable tax and financial laws (typically 7 years)
- Crash reports - retained for 90 days, then automatically deleted
8. Data Deletion
You have the right to request complete deletion of your personal data at any time. We make this process straightforward and accessible.
How to Request Deletion
- In-app: Navigate to Settings, then Account, then Delete Account
- Online: Visit our Data Deletion Request page
- Email: Send a request to support@winkvpn.app
Processing Timeline
All deletion requests are processed within 30 calendar days. You will receive a confirmation email once your data has been removed.
What Gets Deleted
- Account information (email, username, preferences)
- Connection metadata
- App usage data and settings
What Is Retained After Deletion
- Anonymized aggregate statistics - cannot be linked back to you
- Payment/billing records - retained as required by law for tax and financial compliance
9. Your Rights
Depending on your location and applicable laws (including GDPR, CCPA, and other privacy frameworks), you may have the following rights:
- Right to Access - request a copy of your personal data we hold
- Right to Rectification - request correction of inaccurate personal data
- Right to Erasure - request deletion of your personal data
- Right to Data Portability - request your data in a machine-readable format
- Right to Object - object to certain types of data processing
- Right to Restrict Processing - request limitation of how we process your data
To exercise any of these rights, please contact us at privacy@winkvpn.app. We will respond to all valid requests within 30 days.
10. Children's Privacy
WINK VPN is not directed at children under the age of 13. We do not knowingly collect, solicit, or store personal information from children under 13.
If we become aware that we have inadvertently collected personal data from a child under 13, we will take immediate steps to delete such data from our servers.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at support@winkvpn.app and we will promptly remove the information.
11. Security Measures
We implement comprehensive security measures to protect your data against unauthorized access, alteration, disclosure, or destruction:
- AES-256-GCM encryption for all VPN tunnel traffic
- TLS 1.3 for all API and control channel communications
- Regular security audits and vulnerability assessments
- Secure server infrastructure with physical access controls
- Strict employee access controls with role-based permissions and two-factor authentication
- Incident response procedures with defined escalation paths and notification protocols
- Encrypted backups with limited retention periods
12. International Data Transfers
Our VPN servers are located in multiple countries worldwide. When you connect to a server in another country, your encrypted VPN traffic is processed through that server location.
Any personal data (such as account information) may be processed in the country where our central servers are located. We ensure appropriate safeguards are in place for all international data transfers, including encryption in transit and at rest.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you through an in-app notification
- Send an email notification to premium subscribers
Your continued use of WINK VPN after any changes to this Privacy Policy constitutes your acceptance of the updated terms.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
General Support: support@winkvpn.app
Privacy and Data Inquiries: privacy@winkvpn.app
Data Deletion Requests: Submit a request online