{{-- | This policy describes the schema as actually built. Every retention | figure maps to a configurable setting, and every category listed | corresponds to real columns. Claims are deliberately limited to what | the architecture supports. --}}
We do not claim to be a zero-log service, because that would not be true. Running a VPN requires keeping some operational records — how much data a connection moved, and when a device last completed a handshake. What we do not keep is any record of what you do while connected. Those are different claims, and we think you deserve the accurate one.

What we do not collect

The following are never recorded, and there is nowhere in our database to store them:

  • Websites you visit, or the domains you request
  • DNS queries made through the VPN
  • Destination IP addresses of your traffic
  • The contents of your traffic
  • Your originating IP address, once connected

What we do collect

Account data

Your name, email address and password hash. Required to give you an account and let you sign back into it. Kept while your account exists.

Billing records

Subscription history, invoices, payment amounts, and the brand and last four digits of a payment card. Full card numbers are handled by our payment provider and never reach our servers. Retained as long as tax and accounting law requires.

Operational data

For each of your devices: the assigned VPN address, which server it uses, total bytes sent and received, and the time of the last successful handshake. This is what lets us bill accurately, apply data allowances, size capacity, and answer abuse complaints. It describes volume and timing, not content or destination.

Security logs

Sign-in times, the IP address used to sign in to the website, and administrative actions taken on your account. This is how we detect account takeover and how we can tell you what happened if it occurs.

How long we keep it

Retention is set per category, and an operator can shorten any of these. Defaults:

  • Server health metrics — {{ config('zylovpn.retention.server_metrics') }} days
  • Connection records — {{ config('zylovpn.retention.vpn_connections') }} days
  • Usage totals — {{ config('zylovpn.retention.vpn_usage') }} days
  • Security logs — {{ config('zylovpn.retention.security_logs') }} days
  • Administrative audit logs — {{ config('zylovpn.retention.audit_logs') }} days

Records past their retention period are deleted automatically.

Encryption keys

Each device gets its own WireGuard key pair. Where we store a private key so you can download your configuration again, it is encrypted at rest. Private keys are never written to our logs, never shown in our admin tools, and never included in any API response. Our staff can see your device's public key; they cannot see its private key.

Your rights

You can request a copy of your data, correct it, or ask us to delete your account. Deleting your account removes your personal data; billing records we are legally required to retain are kept for the statutory period and nothing longer. Contact us at {{ settings('company.support_email', 'support@zylovpn.com') }}.

Legal requests

We respond to valid legal process. Because of what we do not collect, we cannot produce browsing history, DNS records or traffic contents in response to any request — that data does not exist. We can only produce what is described above.