Legal
Privacy Policy
Last updated: September 4, 2026
1. Introduction
Fexyn VPN (“Fexyn,” “we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our VPN service, website, and related applications.
By using Fexyn VPN, you agree to the practices described in this policy. If you do not agree, please discontinue use of our services.
2. Information We Collect
Account Information
- Email address (for account creation and communication)
- Display name (optional, for personalization)
- Account credentials (securely hashed, never stored in plaintext)
- Advertising click identifier — only if you arrived through one of our own paid advertisements, and only to attribute your signup to that advertising campaign (see Section 11).
- Affiliate referral identifier. Only if you arrived through an affiliate or partner referral link, and only to credit the referring affiliate if you subscribe (see Sections 8 and 11).
Payment Information
Payments are processed by Stripe. We do not store your credit card numbers, CVV, or full card details. We retain only a transaction reference and the last four digits of your card for billing history.
Device Information
- Device name (as provided by you during registration)
- Fexyn app version (so we can tell which build a problem affects)
- Connection timestamps (when a VPN session starts and ends)
Connection Metadata
- Server connected to (e.g., Frankfurt, Amsterdam)
- VPN protocol used (Fexyn Bolt, Fexyn Stealth, Fexyn Secure)
- Bandwidth consumed per session
- Whether a connection attempt succeeded or failed, and if it failed, which stage it failed at and how long it took. We use this to find protocols and servers that are being blocked.
- The country the connection came from, at country level only. It is read from a header our network provider adds before the request reaches us — we never see or store your IP address.
Aggregate Bandwidth Usage
We record the total number of bytes each account uploads and downloads, aggregated per account and updated periodically. We use this for capacity planning, service quality monitoring, and to enforce the bandwidth fair use rules in our Acceptable Use Policy.
This figure is a count and nothing more. It does not include the websites you visit, your DNS queries, the content of your traffic, the IP addresses you connect to, or the timestamps of individual connections, so it cannot reveal what you did while connected. This aggregate usage data is retained for 90 days and then deleted. It is fully compatible with our commitment to keep no browsing-history, DNS-query, or traffic-content logs.
3. What We Do NOT Collect
Our strict no-logs commitment:
- No browsing history — We never monitor, record, or store the websites you visit.
- No traffic content — We cannot and do not inspect the content of your encrypted traffic.
- No DNS queries — We do not log your DNS requests.
- No originating IP addresses — After your VPN session ends, we do not retain your source IP address.
- No activity logs — We do not log the websites you visit, files you download, or any internet activity. Connection metadata (which server, when, how long) cannot reveal what you did while connected.
4. How We Use Information
- Account management — To create and maintain your account, process authentication, and enable device management.
- Service provision — To allocate VPN resources, manage server connections, and enforce device limits.
- Billing — To process payments, manage subscriptions, and provide invoices.
- Abuse prevention and fair use. To detect and prevent misuse of our service, and to enforce the bandwidth fair use rules in our Acceptable Use Policy, in accordance with our Terms of Service.
- Service improvement — To understand aggregate usage patterns and improve infrastructure performance.
5. Data Retention
- Connection metadata is automatically purged after 90 days.
- Account data is retained while your account is active.
- Upon account deletion, all personal data is permanently removed within 30 days.
- Billing records may be retained for up to 7 years as required by tax and financial regulations.
6. Law Enforcement Requests
Fexyn complies with valid legal process, including subpoenas, court orders, and search warrants issued by courts of competent jurisdiction.
When we receive a legal request, our process is:
- Verify validity — We review every request for legal sufficiency and narrow scope before responding.
- Notify the user — We will notify the affected user of the request unless we are legally prohibited from doing so (e.g., by a gag order).
- Limit disclosure to data actually possessed — Because we do not log browsing history, DNS queries, or traffic content, we cannot provide this information in response to any request. We can only disclose account-level data (email, subscription status, connection metadata) as described in Section 2.
For transparency about government data requests we have received, see our Warrant Canary.
7. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process your data under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation & management | Performance of contract |
| VPN service delivery | Performance of contract |
| Payment processing (via Stripe) | Performance of contract |
| Connection metadata (timestamps, server, bandwidth, connection outcome) | Legitimate interest (service quality & abuse prevention) |
| Security event logging | Legitimate interest (security monitoring) |
| Affiliate referral tracking | Consent (cookie banner) |
| Advertising attribution (ad-network click identifier) | Consent |
| Email communications | Performance of contract / Consent |
You may object to legitimate interest processing at any time by contacting privacy@fexyn.com.
8. Third Parties
- Stripe — Payment processing. Stripe's privacy policy applies to payment data they handle.
- Keycloak — Authentication (self-hosted on our infrastructure). No data is shared with third parties through Keycloak.
- Resend — Transactional email delivery (account notifications, password resets). Resend's privacy policy applies to email delivery data.
- Endorsely. Affiliate attribution. If you arrive through an affiliate or partner referral link, our page sends the referral code, the page path, our Endorsely account identifier, and any other query string parameters present on that link to Endorsely at
app.endorsely.com. As with any request to an external service, Endorsely also receives your IP address and browser user agent. Endorsely returns a referral identifier which is stored in the cookie described in Section 11. Endorsely's privacy policy applies to that data. It is used only to credit the referring affiliate.
When you create an account after clicking one of our own advertisements, we report that conversion back to the advertising network that showed you the ad so the campaign can be measured. Where our agreement with a network pays it a share of the revenue, we also report each subsequent subscription payment, and a reversal if a payment is refunded or charged back. Each report contains the network's own click identifier, the type of event, the amount paid where that amount is in US dollars, and your country. It never contains your name, your email address, or anything about your VPN usage (see Section 11). Beyond that, and beyond the affiliate attribution data sent to Endorsely described above, we do not sell, rent, or share your personal data with advertisers or any other third parties. We do not engage in data brokering.
9. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using TLS 1.2 or higher.
- Databases are encrypted at rest.
- VPN connections use state-of-the-art encryption (Fexyn Bolt: ChaCha20-Poly1305, Fexyn Stealth: TLS 1.3 Reality, Fexyn Secure: AES-256-GCM).
- Authentication credentials are protected with short-lived certificates and secure hashing.
- Infrastructure is hardened with firewalls, intrusion detection, and regular security audits.
10. Your Rights
You have the right to:
- Access — Request a copy of all personal data we hold about you.
- Correction — Request correction of inaccurate personal data.
- Deletion — Request permanent deletion of your account and all associated data.
- Data export — Request an export of your data in a portable format.
To exercise any of these rights, contact us at support@fexyn.com.
11. Cookies
- Session cookies — Used for authentication and maintaining your login session. Essential for service operation.
- Preference cookies — Used to remember your language and theme preferences.
- Affiliate referral cookies. We use two affiliate attribution mechanisms when you arrive through an affiliate or partner referral link (for example a link containing
?ref=). First, we setfexyn_ref, a first-party, same-site cookie recording which affiliate referred you and a random correlation token. Second, we use Endorsely, a third-party affiliate attribution service, which sets a separate cookie calledendorsely_referral. The Endorsely cookie is configured as a cross-site cookie (SameSite=None; Secure), and the referral details listed in Section 8 are transmitted to Endorsely's servers. Endorsely sets the lifetime of its own cookie. Both cookies exist solely to credit the correct affiliate if you later subscribe. Neither is used for advertising, for behavioral profiling, or to follow you around other websites beyond attributing the affiliate who referred you. Neither contains information that identifies you personally beyond the referral source identifier, and you can clear both at any time through your browser settings. - Advertising attribution cookie — If you arrive through one of our own paid advertisements (a link carrying the ad network's click identifier), we set a separate first-party cookie holding that identifier and basic campaign context (ad zone, country, cost, creative). If you then create an account, we store the identifier with your account and echo it back to the advertising network that showed you the ad, so it can count the signup against the campaign you arrived from. Where our agreement with that network pays it a share of the revenue, we also report each subscription payment you make, and a reversal if one of those payments is refunded or charged back. The identifier is kept only for as long as it is needed to report those outcomes: no longer than 90 days for a signup-only campaign, and where renewals are reported, for as long as your subscription can still renew plus 90 days after it ends. It is never used to profile you or follow you across other websites, and it is processed on the basis of your consent. An explicit cookie rejection limits it to your current browser session. It has no connection to your VPN usage, which remains covered by our no-logs commitment.
The Endorsely cookie described above is the only third-party cookie we set, and its purpose is limited to affiliate attribution. Beyond it and the first-party attribution cookies described above, we do not use advertising cookies or third-party analytics cookies, and we do not use any cookie to build advertising or behavioral profiles or to track you across unrelated websites.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by email or through a prominent notice on our website. The “Last updated” date at the top of this page indicates when the policy was last revised. Continued use of our services after changes constitutes acceptance of the updated policy.
13. Contact
If you have any questions about this Privacy Policy or our data practices, contact us at: