Skip to main content
SPACY

Spacy VPN Privacy Policy

Version of 28 September 2026.

In short

  • We don't keep logs of your VPN activity. We don't record which sites you open, your DNS queries or the content of your traffic. We have nothing to hand over about what you do online, because we don't store it.
  • We keep only what the service can't work without: your account, your list of devices, subscription and payment status, the amount of traffic used and a short security log of sign-ins.
  • Every kind of data has a retention period. It's listed in the table below, and deletion happens automatically.
  • Card details never reach us. Payments are taken by YooKassa; we receive only the payment status.
  • You can delete your account in the app at any time: Profile → Delete account.
  • We don't sell data and don't use advertising trackers or analytics that follow you around.

1. Who we are

The Spacy VPN service (the iOS and macOS apps, the spacy.site website and the service's Telegram bots) is provided by Spacy Network ("we").

We decide why and how your data is processed, which makes us its controller.

2. What data we process

2.1. Account

  • An internal account ID.
  • Your sign-in method. We keep only what we need to recognise you the next time you sign in:
    • Telegram: your numeric Telegram user ID and display name;
    • Apple: the anonymous Apple ID identifier that Apple issues for our app, and your name if you shared it;
    • Google: your Google account ID and name;
    • Email: your email address.
  • The date the account was created.

We don't use or store passwords.

2.2. Devices

For each device signed in to your account:

  • its name (for example, "Kirill's iPhone");
  • platform, model and OS version;
  • the app installation ID (HWID);
  • when it was added and when it was last active;
  • its trust status.

If you allowed notifications, we store your Apple push notification token. We use it to tell you about new sign-ins and other security events.

Sign-in sessions are stored only as cryptographic hashes.

2.3. Subscription and VPN

  • Subscription status and expiry date.
  • Traffic counters: how many bytes were transferred in a period. Volume only, with nothing about where the traffic went.
  • The devices that have received a configuration. We need this for the device limit.
  • Your IP address and device details (model, OS, app version) when the server list is refreshed.

What we don't store:

  • addresses of sites and services you open through the VPN;
  • DNS queries;
  • the content of your traffic;
  • start and end times of VPN sessions linked to your IP.

VPN servers only relay traffic and keep no connection logs.

2.4. Security log

When a security-relevant event happens, we record the event type, the time, the IP address and details of the app or browser (User-Agent). These events are:

  • signing in;
  • adding or removing a device;
  • linking a sign-in method;
  • deleting the account.

The log protects your account from takeover and lets us notify you about new sign-ins. Entries are deleted after 90 days.

2.5. Payments

  • Payment number, plan, amount and currency, status, dates.
  • The promo code applied.

You enter your card on the YooKassa page. Its details never reach us.

Each payment produces an electronic receipt. It is sent to the email you provide at payment.

2.6. Support

If you contact us through the app, the website or Telegram, we process:

  • the text of your message and any attachments;
  • your account ID;
  • the contact we should reply to.

Messages from the app and the website are delivered to support agents in Telegram.

2.7. Website

The website uses only necessary cookies: to sign you in to your account, to protect against forged requests, and to remember your language and your answer to the cookie notice. There are no analytics or advertising cookies. See the Cookie Policy for details.

2.8. What stays on your device only

This data is stored on your device and is not sent to our servers:

  • app settings;
  • the tunnel log (you can clear it in Settings);
  • the cached server list.

You can choose to send the log to support yourself.

When checking your network, the app contacts a few public sites directly, bypassing the VPN: google.com, github.com, ya.ru, gosuslugi.ru. This is how it tells whether the network is restricted by "whitelists". These sites see an ordinary request from your IP address; the result of the check is not sent to us.

3. Why we do this

PurposeDataLegal basis
Create your account and let you into itaccount, devices, sessionsperformance of the contract
Provide the VPN and enforce the device limitsubscription, devices, traffic countersperformance of the contract
Protect your account and tell you about new sign-inssecurity log, push tokenlegitimate interest, your security
Take payments and issue receiptspaymentsperformance of the contract, legal obligation
Answer your requestssupportperformance of the contract, your request

We don't make automated decisions about you that have legal effects, we don't build profiles and we don't show ads.

4. How long we keep data

DataPeriod
Account, sign-in methods, active deviceswhile the account exists
Removed devices90 days after removal
Sign-in sessions30 days after they expire or are revoked
Security log (IP, User-Agent)90 days
Queued push notifications7 days after delivery; undelivered ones, 30 days
One-time sign-in codes and QR codesone day after expiry (they are valid for 2 minutes)
Paymentsthe period required by tax and accounting law; after the account is deleted, with no link to it
Support requestsnot stored in our database; the conversation stays in the Telegram support chat and is deleted at your request

Deletion on these schedules is automatic.

5. Who we share data with

We share data only with contractors the service can't work without, and only as much as their task requires:

WhoWhy
Hosting provider of the API serverhosting our servers
VPN server providers in various countriesrunning the VPN (they receive no account data)
YooKassa (YooMoney NBCO LLC)taking payments and issuing receipts
AppleSign in with Apple, push notifications
GoogleSign in with Google
TelegramTelegram sign-in, the service bot, the support chat
Email servicesending sign-in codes by email

We don't sell data and don't share it for advertising.

Requests from authorities. We respond only to lawful, properly issued requests and disclose only what we have. We have no information about which sites you visited through the VPN.

6. International transfers

The service's servers and contractors are located in different countries. Your data may therefore be processed outside the country you are in. We choose contractors that provide adequate data protection.

7. How we protect data

  • All connections to the app and the website are encrypted (TLS).
  • Session tokens and one-time codes are stored only as hashes.
  • Access to the servers is strictly limited.
  • We notify your trusted devices when a new device signs in.
  • A new device can't delete the account, manage devices or perform other risky actions. For that it must be approved by a trusted device, or it becomes trusted on its own after 3 days.

8. Your rights

You can:

  • find out what data we hold about you and get a copy;
  • correct inaccurate data;
  • delete your account: in the app, Profile → Delete account (from a trusted device), or by writing to us. The account, devices and sessions are deleted immediately; payment records remain, with no link to you;
  • withdraw consent and object to processing;
  • unlink a sign-in method and remove a device from your account;
  • complain to the data protection authority in your country. In Russia that is Roskomnadzor; in the EU and elsewhere, the data protection authority of your country.

Send requests to legal@spacy-network.xyz from the contact method linked to your account. We reply within 30 days.

9. Children

The service is not intended for children under 14. We don't knowingly collect their data. If you learn that a child has given us data, write to us and we will delete it.

10. Changes to this policy

We will announce material changes in advance in the app or on the website. The date of the current version is shown at the top of this document.

11. Contact