SupaVPN Privacy Policy
Last Updated: August 22, 2026
This Privacy Policy explains how Nureply Inc. ("Nureply," "we," "us," or "our"), the operator of SupaVPN, handles information in connection with the SupaVPN mobile application and its virtual private network (VPN) service (the "Services"). SupaVPN is built to be privacy-first: it is account-less, it does not require your name or email, and it does not keep logs of your online activity. By using the Services, you agree to the practices described in this policy.
1. Our Privacy Commitment: No Activity Logs
We designed SupaVPN so that we do not know what you do online. Our VPN servers do not keep activity or traffic logs. Specifically, we do not record, store, or associate with you:
- the websites, domains, IP addresses, or services you connect to (destination logs);
- your browsing history or the content of your traffic;
- your DNS queries;
- logs that map your connection to the sites or apps you use.
This is enforced in our server configuration: the VPN core runs at a minimal log level with no access-log file, so browsing destinations are not written anywhere. For service operation and to enforce plan quotas, we track only the aggregate volume of data used by an account (for example, total gigabytes transferred). We never tie that figure to destinations, and it does not reveal what you did online.
2. Account-less by Design
SupaVPN does not have a traditional sign-up. We do not ask for, and you do not create, a username, password, name, or email address to use the app. Instead, the app generates a random identifier (a UUID) that is stored securely in your device's Keychain and used to associate your device with your subscription and VPN configuration. You can reset this identifier by deleting and reinstalling the app, subject to how the operating system preserves Keychain data.
3. Information We Collect
We collect only the limited information needed to run the Services. This maps to the data categories disclosed on our App Store privacy label:
- User ID: the random UUID described above, which identifies your device to our backend and to our subscription provider so we can deliver your VPN configuration and honor your subscription.
- Device ID: a device identifier used together with the User ID to associate your subscription with your device and to help operate and protect the Services.
- Diagnostics and other usage data: limited technical information such as crash and error reports and basic operational signals (including the aggregate data-usage volume described above), used to keep the app working, troubleshoot problems, and enforce plan quotas.
- Support communications: if you contact us for support, we receive the information you choose to send us, such as the content of your message. Providing this is optional.
All of the above is used only to provide app functionality. It is not used to track you across other companies' apps or websites. We do not use advertising identifiers (such as the IDFA / AdSupport), we do not present an App Tracking Transparency prompt because we do not track you, we do not serve third-party advertising, and we do not sell or share your data with data brokers.
4. How We Use Information
- To provide the Services: to deliver your VPN configuration, establish your connection, and associate your device with an active subscription.
- To operate and improve reliability: to diagnose crashes and errors and keep the app functioning.
- To manage subscriptions and quotas: to verify subscription status and enforce plan data limits using aggregate usage volume.
- To provide support: to respond to your inquiries.
- To comply with law and prevent abuse: to meet legal obligations and to protect the security and integrity of the Services and our users.
5. Legal Bases for Processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR: performance of a contract (to provide the Services you request and manage your subscription); our legitimate interests (to operate, secure, and improve the Services and prevent abuse), balanced against your rights; and compliance with a legal obligation (where the law requires it). We do not rely on consent for advertising, because we do not run advertising or tracking.
6. How Information Is Shared: Service Providers and Subprocessors
We do not sell your personal information and we do not share it with advertisers or data brokers. We share limited information only with the service providers that help us operate the Services, and only as needed for them to perform their function:
- Apple — app distribution and payment processing. Purchases and billing are handled by Apple; we do not receive your full payment details.
- RevenueCat — subscription management. RevenueCat is our source of truth for whether a subscription is active, and it processes your User ID and purchase records for that purpose.
- Cloudflare — content delivery, connectivity, and security for our infrastructure.
- VPN hosting providers — the data-center and server providers that host the VPN nodes that carry your encrypted connection.
We may also disclose information if required to do so by law or valid legal process, or where necessary to protect our rights, users, or the public. Because we do not keep activity or destination logs, we cannot produce records of your online activity that we do not have. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
7. International Data Transfers
We and our service providers may process information in countries other than the one in which you live, including the United States. Where personal data is transferred internationally, we rely on appropriate safeguards where required, such as the European Commission's Standard Contractual Clauses or equivalent mechanisms, so that your information remains protected.
8. Data Retention
We keep information only for as long as needed for the purposes described in this policy. We do not retain activity or destination logs at all. Subscription and device identifiers are retained while your subscription or use of the Services is active and for a limited period afterward as needed to operate the Services, comply with legal obligations, resolve disputes, and prevent abuse. Aggregate usage figures are retained only as needed to manage quotas and operate the Services. Support communications are retained as needed to handle your request.
9. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal information. We honor these rights in accordance with applicable law, including the GDPR and the California Consumer Privacy Act as amended by the CPRA:
- Access / Know: request a copy of, or information about, the personal data we hold about you.
- Deletion: request that we delete your personal data, subject to legal and service-related limits.
- Correction: request that we correct inaccurate or incomplete data.
- Restriction and objection: ask us to restrict or object to certain processing.
- Portability: request a portable copy of certain data.
- Non-discrimination and opt-out: we will not discriminate against you for exercising your rights. We do not sell or share your personal information for cross-context behavioral advertising, so there is nothing to opt out of in that respect.
Because SupaVPN is account-less, the main identifier we can act on is the device UUID; to help us locate the limited data associated with your device, please contact us from the device in question or include relevant details. We will respond within the timeframes required by applicable law. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
10. Children's Privacy
SupaVPN is intended for individuals aged 18 and over. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
11. Security
We use industry-standard technical and organizational measures to protect information, including encryption of your VPN connection in transit and secure storage of the device identifier in the iOS Keychain. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but not collecting activity data is itself a core protection: data we never collect cannot be exposed.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and post the revised policy on this page. Your continued use of the Services after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us at: