Privacy Policy
Last updated: 10 August 2026
The short version. We do not log what you do online. We do not sell, rent, or disclose your data to anyone. We keep the minimum needed to run your account and your subscription — and we designed the system so that the browsing data simply does not exist to be handed over.
This policy explains what GRANA VPN ("we", "us") collects when you use our applications and website, why we collect it, and what we will never do with it. It applies to the GRANA VPN apps for iOS, Android, Windows and macOS, and to granavpn.com.
1. What we do not collect
This section comes first because it is the part that matters. While you are connected to GRANA VPN we do not record:
- the websites, services or applications you connect to;
- your DNS queries;
- destination IP addresses, domains, ports or protocols;
- the content of your traffic, in any form;
- timestamps tied to individual connections or sessions on our servers;
- your real IP address in readable form.
This is enforced by how the system is built, not only by policy. Our VPN servers never report the network address a device connects from back to our infrastructure — that field is deliberately excluded from what a server is able to send. Where we need to recognise a repeat source for security purposes, we store a one-way cryptographic digest, which cannot be reversed into an address.
We also do not embed advertising identifiers, analytics SDKs, session recorders, or third-party trackers in our applications.
2. What we do collect
Account data
You can start using GRANA VPN without giving us anything at all: a new installation creates an anonymous account. If you choose to add an email address so your subscription follows you to another device, we store that address and a cryptographic hash of your password. We never store your password itself.
Installation identifier
When the app first runs it generates a random identifier. We store a hashed form of it for one reason: to make sure each installation receives the free trial once. It is not linked to any advertising identifier and cannot be used to identify your device outside our service.
Device keys
Each device generates its own encryption keypair. The private key never leaves your device — we could not obtain it if we wanted to. We store only the public half, together with the private internal address we assign to that device inside our network.
Connection counters
Our servers report, per device, the total number of bytes sent and received and the time of the most recent successful handshake. This is what lets us show usage in your account, size our capacity, and detect abuse. It carries no information about what was transferred or where it went.
Payment records
When you pay we record which plan was bought, the amount, the date, and the transaction reference given by the payment provider. We never see or store your card details — card payments are processed entirely by our payment provider. Purchases made inside the iOS or Android apps are processed by Apple and Google respectively under their own terms. Payments made in USDT are recorded on the public Tron blockchain, which is outside our control.
Support correspondence
If you email us, we keep the message and your address so we can reply.
3. We do not sell or share your data
GRANA VPN does not sell, rent, trade, or otherwise disclose to any third party the data described in this policy, for advertising, profiling, analytics, or any other purpose. We make this commitment unconditionally, and it applies to every category of data we hold.
The only parties that ever handle data on our behalf are the service providers we need to operate: the companies hosting our servers, our payment providers, our email delivery provider, and — for in-app purchases — Apple and Google. Each acts strictly on our instructions and may not use the data for its own purposes.
4. Why we are allowed to hold this data
Where the GDPR applies, we rely on the necessity of processing to perform our contract with you (running your account, providing the tunnel, taking payment), and on our legitimate interest in keeping the service secure and free of abuse (rate limiting, trial-abuse prevention). We do not rely on consent for advertising, because we do not advertise to you.
5. How long we keep it
- Account data — until you delete your account.
- Connection counters — replaced continuously; only the current totals per device exist.
- Sessions and sign-in throttling — expired records are removed automatically; sessions last at most 90 days.
- Payment records — retained as required by tax and accounting law, detached from your identity once your account is deleted.
6. Deleting your account
You can delete your account from inside the app or by writing to us. Deletion is immediate and permanent: your devices are removed from every server, your sessions end, and your account record is erased. Payment records are anonymised rather than destroyed, because financial records must be retained by law — after deletion they no longer point to a person.
7. Your rights
Depending on where you live you may have the right to access the data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable form, and complain to a data protection authority. Write to privacy@granavpn.com and we will respond within 30 days. Residents of California have the right to know what is collected and to request deletion; we do not sell personal information, so there is nothing to opt out of.
8. Legal requests
If we receive a valid legal order we can only produce what we actually hold — account and billing records. We have no browsing history, no DNS logs, and no record of which addresses connected to our servers, so those cannot be produced regardless of who asks or on what authority.
9. Security
Traffic is encrypted with WireGuard®, using modern cryptography with no configurable weak options. Passwords are stored using scrypt with a per-user salt. Communication between our servers is authenticated cryptographically. Access to production systems is limited to the people who operate the service.
10. Children
GRANA VPN is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.
11. International transfers
Our servers are located in many countries so that you can choose where your traffic exits. Account data is held in the European Union. Where data is transferred outside the EEA, it is covered by appropriate safeguards.
12. Changes to this policy
If we change this policy in a way that affects you, we will notify you in the app and by email before the change takes effect. The date at the top always shows the current version.
13. Contact
Questions about this policy: privacy@granavpn.com
General support: support@granavpn.com