Legal · Effective 13 August 2026
Privacy Policy
This policy describes exactly what the VPN Defendr+ iOS app collects, what it does not, and what happens to it. It is specific to this app. Nothing in it is generic filler.
1. The short version
The app has no accounts, so we hold no name, email address, phone number or password for you — there is nothing to hold. What we do collect is a small amount of anonymised technical data about how the app itself performs: whether it crashed, how long a connection took to establish, which screens were used. Section 4 lists every item.
Three things are true of all of it. It is not linked to your identity — there is no identity in the app to link it to. It is never used to track you across other companies’ apps or websites. And it is never sold, rented or shared with advertisers, data brokers or anyone else.
Two things necessarily involve another company. Apple takes the payment for a subscription. And the VPN server you select receives your traffic, because that is what a VPN is. Sections 4 and 5 cover both.
2. Who is responsible
The data controller for the VPN Defendr+ iOS application is:
SEAN OOD
Tsar Ivan Shishman str.
Bl. No 33, entr. A, fl. 7, apt. 43
Dupnitsa, Dupnitsa 2600
Bulgaria
Tel. 1-814-7071227
Email [email protected]
This policy covers the iOS app and this website. It does not cover the App Store, which Apple operates under its own privacy policy.
3. What stays on your device
The app stores a small amount of information locally, in its own storage on your iPhone, using standard iOS mechanisms. None of it is transmitted to us.
| Stored locally | Why |
|---|---|
| Selected server location | So the app reconnects to the country you used last instead of asking again. |
| Connection state and session timer | To show whether the tunnel is up and how long it has been running. |
| Subscription status | Whether your plan is currently active, so the app knows what to unlock. It originates from the Apple receipt; how it is verified is described in section 4. |
| The VPN configuration | Created by iOS when you first allow it, and held by iOS — not by us — so the tunnel can be established. |
Deleting the app removes all of it from your iPhone.
4. What leaves the device, and why
Besides the traffic you are routing, the app sends us a short list of technical measurements. They exist so we can tell whether a build is stable and which parts of the app people actually use. Every item below is anonymised before it reaches us: no identifier that points at a person is attached, and we make no attempt afterwards to work out who a record belonged to.
| What we receive | Why | Linked to you |
|---|---|---|
| A per-installation identifier | Lets us tell one installation’s crash reports apart from another’s. It is generated on the device, is not the advertising identifier, and resets when you delete the app. | No |
| Crash reports | The technical state of the app when it stopped working, plus iPhone model and iOS version, so the fault can be reproduced and fixed. | No |
| Performance measurements | How long a connection took to establish, whether it failed, how often it dropped. Used to find servers and code paths that misbehave. | No |
| Subscription receipt | The purchase receipt issued by Apple is sent to our server to confirm the subscription is genuine and still active, so paid features unlock correctly. It records which plan was bought and when it renews. It contains no card number, no billing address and no Apple Account password. | No |
| In-app actions | That a screen was opened or a location was changed, counted as totals, so we can see which features are worth keeping and improving. | No |
That is the whole list. It contains no browsing history, no DNS queries, no message or file contents, no location, and no credentials. Nothing in it is combined with data from any other source, and nothing is passed to a third party. Records are keyed to the installation, not to your name or your Apple Account.
What Apple handles separately
- Payments. Apple is the merchant of record for every subscription and takes the payment. We never receive your card number, billing address or Apple Account credentials, and we cannot browse your purchase history in the App Store or issue a refund.
- App Analytics. Apple gives developers aggregated statistics such as installs, sessions and retention. Apple calculates these, they reach us as totals, and they identify nobody. Apple includes your device only if you have left device analytics sharing switched on in iOS.
- Crash reports through Apple. Where you have allowed sharing with app developers in iOS settings, Apple may also pass us a crash report of its own. It contains no messages, files or browsing information.
Those iOS settings are yours to change at any time, in Settings → Privacy & Security → Analytics & Improvements.
5. Your traffic and IP address
This is the part that cannot happen on the device alone, so we set it out plainly. When you connect, iOS routes your outbound traffic into an encrypted tunnel to the server location you picked. That server has to receive your packets in order to forward them, which means it sees the IP address your internet provider assigned you. Every VPN in existence works this way; a VPN that never contacted a server would not be a VPN.
What matters is what happens with it:
- Your IP address is used only to route the live session. It is not written into a log we can search afterwards.
- We do not record which websites or services you connect to, your DNS lookups, or the content of your traffic.
- Session information is not written to a log after the connection closes. Server health is watched through machine-level metrics such as load and available capacity, which are properties of the server rather than records about anyone using it.
- We do not build a profile, and we have no way to connect a session to an identity, because the app never asked you for one.
One limitation, stated plainly: if a Bulgarian court or another competent authority issues a lawful order, we must hand over the information we actually hold. No provider anywhere can promise otherwise. Because we keep no browsing records, there are no browsing records to hand over.
6. What we do not collect
- No account data. No name, email address, phone number or password is asked for, at any point.
- No location. The app never requests GPS or location permission. The country list refers to server locations, not to yours.
- No contacts, photos, files, calendar, microphone, camera or health data. The app asks iOS for none of these permissions, so it cannot reach them.
- No passwords or credentials. The app does not scan for, test, store or check passwords of any kind.
- No device scanning. The app does not inspect your files or assess the security condition of your iPhone. iOS does not allow it and we do not claim it.
- No browsing or search history. The app does not record the sites you visit, your DNS lookups, or anything you search for.
- No advertising and no tracking. There is no advertising in the app, no advertising identifier (IDFA) is requested, and nothing we collect is combined with data from other companies’ apps or websites for advertising or measurement. Apple’s App Tracking Transparency prompt never appears because there is nothing to ask permission for.
- No sale of data. We do not sell, rent or trade data, and never have. Under the CCPA this means we neither “sell” nor “share” personal information as those terms are defined there.
7. Third parties involved
There are exactly two, and no others:
| Who | Role |
|---|---|
| Apple Inc. | Distributes the app, processes every payment as merchant of record, and supplies the aggregated analytics and crash reports described in section 4. |
| Hosting and network providers | Operate the physical servers that terminate the VPN tunnel, under contract and on our instructions only. They may not use anything passing through for their own purposes. |
The technical measurements in section 4 are received and held by us on our own infrastructure. No advertising network, data broker or attribution service receives anything from this app, and we use no third-party marketing or advertising service of any kind. If you want to know which company hosts the servers in a particular region, ask us at [email protected] and we will tell you.
8. Legal basis for processing
Where the GDPR applies, the limited processing described above rests on:
- Performance of a contract (Art. 6(1)(b)) — routing your connection and delivering the subscription you bought.
- Legitimate interests (Art. 6(1)(f)) — keeping servers available, preventing abuse of them, and diagnosing crashes and performance faults so the app works. We use the minimum that achieves this, and it identifies nobody.
- Legal obligation (Art. 6(1)(c)) — responding to a lawful order, and keeping the accounting records tax law requires.
9. How long anything is kept
- Data on your device: until you delete the app.
- Session routing data: exists only while the connection is open, then it is gone.
- Crash and performance reports: up to 90 days, whether they reach us from the app or through Apple.
- Counts of in-app actions: up to 12 months, as totals.
- Subscription records: for as long as the subscription is active, then as long as Bulgarian accounting and tax law requires.
- Support emails: up to 12 months after the matter is closed.
10. International transfers
We are established in Bulgaria, inside the EU. Apple processes data in the United States and elsewhere under its own privacy policy and transfer mechanisms. Where a hosting provider outside the EEA is involved, the transfer relies on the European Commission’s Standard Contractual Clauses. You can ask us which mechanism applies to a given server region.
11. Your rights
If you are in the EU or EEA, the GDPR gives you the right to access your data, correct it, have it erased, restrict or object to processing, and receive it in a portable form. If you are in California, the CCPA gives you comparable rights to know, delete, correct and opt out, and the right not to be treated differently for using them.
To exercise any of them, email [email protected] with the subject Data request. We reply within 30 days and never charge.
An honest note on what an access request will return. Because the app has no accounts, the technical data described in section 4 is not attributable to a person, so in most cases we cannot connect any record to the individual asking — and we will say so rather than guess. If you send us the per-installation identifier shown on the app’s settings screen, we can find and delete the records tied to that installation. Deleting the app removes everything held locally straight away, without asking us at all.
You may also complain to your national supervisory authority. In Bulgaria that is the Commission for Personal Data Protection (Комисия за защита на личните данни), Sofia.
12. Children
The app is not directed at children and we do not knowingly process data from anyone under 16. If you believe a child has used the app and something reached us, write to us and we will delete it.
13. Changes to this policy
If we change how the app handles information, we update this page and move the effective date at the top. Material changes are also noted in the release notes on the App Store. The date above tells you which version you are reading.
14. Contact
Questions about this policy, or about anything the app does:
Privacy enquiries
SEAN OOD · Tsar Ivan Shishman str., Bl. No 33, entr. A, fl. 7, apt. 43, Dupnitsa 2600, Bulgaria · Tel. 1-814-7071227