Skip to content
KekVPN
How it worksPricingFAQ
My accountGet KekVPN
How it worksPricingFAQMy account

Privacy Policy

This policy explains how KekVPN collects, uses, shares, and protects data.

Updated: September 10, 2026

PrivacyTerms

Contents

Welcome1. What information do we collect about you?2. How do we use your information?3. Who do we share your information with and why?4. Tracking Technologies & Cookies5. Security6. International Data Transfers7. Data Retention8. Your Rights9. Your California Privacy Rights10. Age Restrictions11. Privacy Policy Updates12. Contact Us
Talk to support

Welcome

This Privacy Policy explains how Stix LLC collects, uses, shares, and protects information when you use KekVPN websites, apps, and related services (collectively, the services). This policy is global.

In this policy, personal data means information relating to an identified or identifiable natural person under applicable law.

Who are we?

This policy covers the data processing practices of Stix LLC.

In this policy, we, us, and our means Stix LLC.

1. What information do we collect about you?

We collect only the information needed to operate, secure, and support the services.

1.1 Information you provide to us

  • Support communications. If you contact support, we receive the information you send (for example, your email address, message text, and optional attachments).
  • Support context you choose to send. When you open the in-app support route, the app can prefill an email draft with technical context (for example, app version, language, subscription state, device ID, RevenueCat user ID, selected country, connection state, platform, OS version, and UTC timestamp).
  • Checkout email. When you use the web checkout, we use the email address you provide for access confirmation and one-time recovery. It is not an account password.
  • Recurring card-charge token. When you choose auto-renewal, the payment provider sends us a token for the selected card. KekVPN stores an encrypted payment-provider token only for later charges to the selected card. We do not receive or store the full card number, expiry date, or CVC.

1.2 Information collected when you use our services

  • Device and app technical data. We process technical identifiers and app metadata needed for API operation, such as app version and a device ID generated by the app for service access.
  • Service request metadata. Our backend may log request metadata such as request time, endpoint, status code, and requested country filter to operate and protect the service.
  • Network information. Our backend processes network metadata such as source IP address and user-agent for security, abuse prevention, and reliability.
  • Subscription identifiers. For subscription checks, we process the RevenueCat App User ID and entitlement status.
  • Installation and device data. We use an installation ID and limited device metadata, such as platform, model, app version, and a name provided by the app, to activate access on the purchasing device and enforce the device limit.
  • Telegram connection. If you explicitly choose to connect app or web access to Telegram, we process the Telegram identifier needed to link that access. We do not silently merge access based only on an email address.

1.3 Information we do not collect in normal operation

  • No password-based checkout credentials. KekVPN does not ask you to create a username or password for web checkout. The contact email is not an authentication secret.
  • No payment card details. App-store payments are handled by Apple App Store / Google Play and RevenueCat. Web checkout payment is completed on an external payment provider page. KekVPN does not receive your full payment card number, card security code, or other card details.
  • No VPN traffic logs. We do not log browsing history, traffic contents, DNS queries, or visited websites through the VPN connection.
  • No precise location data. We do not collect precise GPS location.

2. How do we use your information?

We use information for the following purposes:

  • To provide and operate the services. Including VPN server delivery, app compatibility checks, and service availability.
  • To validate subscription access. We use RevenueCat identifiers and entitlement status to determine premium access.
  • To secure and protect the services. Including abuse prevention, fraud detection, troubleshooting, and reliability monitoring.
  • To provide support. Including handling technical support requests and responding to user inquiries.
  • To comply with legal obligations. Including responding to valid legal requests and enforcing our rights.

3. Who do we share your information with and why?

3.1 Service providers and legal cases

We may share limited information with:

  • RevenueCat. For subscription and entitlement processing.
  • Platform billing providers. Apple App Store and Google Play process purchases under their own policies.
  • Infrastructure and support providers. Hosting, technical operations, and email/support tools that help us run the service.
  • Legal authorities and counterparties. When required by law, legal process, or to protect rights, safety, and security.
  • Business transfers. If our business is reorganized, merged, sold, or transferred, data may be transferred as part of that transaction.

We do not sell personal information or share personal information for cross-context behavioral advertising.

3.2 Support email flow

When you open support from the app, technical context can be added to your email draft to speed up troubleshooting. That context is transmitted to us only if you send the message.

4. Tracking Technologies & Cookies

4.1 Website technologies

The website may use cookies and browser storage to remember your language preference and support essential functionality.

During checkout, the current browser tab temporarily uses sessionStorage to keep the selected checkout language, order ID, signed entry token, and status capability so the page can preserve your language and resume payment status after you return from the external provider. KekVPN checkout does not copy these checkout values to localStorage. An entry token can arrive in the checkout link; the order ID and status capability are not added to checkout URLs.

One-time recovery uses a short-lived server session represented by a Secure, HttpOnly, SameSite=Strict cookie. Browser JavaScript cannot read this cookie. The one-time recovery token is removed from the address bar before redemption.

We currently do not use advertising cookies or third-party analytics cookies on the website.

5. Security

We use administrative, organizational, and technical safeguards designed to protect information against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure, but we continuously work to improve protections.

For checkout email lookup, we store a keyed HMAC-SHA-256 representation. The deliverable email address used for confirmation and recovery messages is encrypted using AES-256-GCM. These controls reduce exposure but do not make any system completely risk-free.

6. International Data Transfers

Because our services are global, information may be processed in countries other than your country of residence, including where our providers operate. Laws in those countries may differ from your local laws.

Where required, we implement appropriate safeguards for cross-border transfers.

7. Data Retention

We retain data only for as long as needed for the purposes described in this policy, unless a longer period is required by law.

  • API/server logs. Typically retained up to 30 days for security and troubleshooting.
  • Subscription cache records. Short-lived cache entries (normally minutes) for entitlement checks.
  • Support emails and support history. Retained up to 24 months after the latest correspondence, unless longer retention is required to resolve disputes or comply with law.
  • Recurring card-charge token. We retain it while the agreement is active or a charge is being retried. We delete the token for a replaced or exhausted agreement after related in-flight operations settle or their deadline passes. For a cancelled agreement, we retain the token until the earlier of paid access expiry or 90 days. You can immediately delete the saved card binding in the portal; its encrypted token is deleted immediately.

We may keep limited data longer where required for legal claims, fraud prevention, or compliance.

8. Your Rights

Depending on your location, you may have rights regarding your personal data, including rights to access, correct, delete, restrict, or object to processing, and to lodge a complaint with a data protection authority.

You may also request information about how we process your data and, where applicable, request portability. We may request verification before fulfilling requests.

To submit a request, contact us using the details in Section 12.

9. Your California Privacy Rights

This section applies to California residents.

9.1 Categories of personal information

In the preceding 12 months, we may have collected the following categories:

  • identifiers (for example, device ID and RevenueCat App User ID);
  • internet or network activity information (for example, request metadata, app version, and technical diagnostics);
  • approximate geolocation derived from IP address;
  • customer support communications and submitted information.

9.2 Sale or sharing for advertising

We do not sell personal information and do not share personal information for cross-context behavioral advertising under CCPA/CPRA.

9.3 California requests

Subject to applicable law, California residents may request access to, correction of, or deletion of personal information, and may request details about categories, sources, purposes, and disclosures. We will not discriminate against you for exercising your rights.

You may designate an authorized agent to make requests on your behalf, subject to verification requirements.

9.4 Shine the Light

We do not disclose personal information to third parties for their own direct marketing without your consent.

10. Age Restrictions

Our services are not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe a child provided personal data, contact us and we will take appropriate steps.

11. Privacy Policy Updates

This page contains the current and effective version of our Privacy Policy.

12. Contact Us

If you have questions, complaints, or privacy requests, contact us:

Stix LLC
Registration No. 278.110.1445669
Vardan Ajemyan 165, Armenia, 0005
Email: [email protected]

KekVPN

A simpler way to connect.

Operated by Stix LLC

Registration No. 278.110.1445669

Vardan Ajemyan 165, Armenia, 0005

Explore

How it worksPricingGet KekVPNMy account

Help & details

Talk to supportPrivacy policyTerms of use
© 2026 KekVPN. All rights reserved.All Systems Operational