Privacy Policy
Last updated: 25 August 2026
Doft VPN ("Doft VPN", "we", "us") is built around a simple promise: what you do online is your business, not ours. This Privacy Policy explains what we do and do not collect when you use the Doft VPN apps and vpn.doft.com. By using Doft VPN you agree to this policy.
Our no-logs commitment
We do not monitor, record, store, or sell your online activity. We do not keep logs of the websites you visit, the apps you use, your DNS queries, your browsing history, the content of your traffic, or the individual IP addresses you connect to through the tunnel.
Because we keep no record of what you do online, there is nothing of that kind to hand over — to anyone, on any grounds. What we do keep is one connection record per device, described in the next section. It holds the last connection, not a history: each new connection replaces the one before it, and after 7 days without activity it is erased. It never says what was done through the connection.
Information we collect
We keep data collection to the minimum needed to run the service:
- A connection record — to carry your traffic we necessarily see the IP address your device reaches us from and which of our servers it is using. We keep only the most recent one: the address, the server and the time. It is overwritten on every new connection and erased automatically once a device has been idle for 7 days. It is never joined to a record of your activity, because we hold none. Separately, the app reports how much data a session moved; those are usage counters rather than addresses, and they are what the free plan's daily allowance is measured against.
- Subscription status — when you buy Premium, Apple or Google tells us that a valid subscription exists and its type (weekly, monthly, yearly). We receive a purchase token/receipt, not your name or payment card.
- Basic diagnostics — technical data such as app version, device type, crash reports, and whether a connection succeeded, used only to keep the app stable. It is stored per device rather than aggregated away, so although it names no one, we do not describe it as anonymous.
- Support messages — if you contact us, we keep what you send us so we can help you.
- A referral code — if you use the invite feature, we store the code so we can grant the reward.
- An abuse counter — to stop a single address from creating unlimited accounts or draining referral credit, we count how many requests come from an address on a given day. The counter is keyed by the address, holds nothing but a number, and deletes itself 48 hours after it is created.
What we never collect
We do not collect your browsing history, traffic content, DNS logs, the sites or services you reach through the VPN, or a record that ties your identity to your activity. We do not require an account, email, or phone number to use the free service.
Subscriptions and payments
Premium subscriptions are sold and processed by the Apple App Store and Google Play. Payment is charged to your Apple ID or Google account. We never see or store your card number or billing address. Subscription management, renewal, and cancellation are handled through your App Store or Google Play account settings.
How we use information
We use the limited data above only to: operate and maintain the VPN service, verify Premium entitlement, prevent fraud and abuse, fix crashes and improve reliability, and respond to your support requests. We do not use it for advertising — Doft VPN contains no ads.
Sharing
We do not sell your data. We share the minimum necessary with service providers who help us operate the app (for example, cloud hosting and the app stores that process payments), and we may disclose information if strictly required by law. Since we keep no activity logs, there is no browsing data to disclose.
One transfer is worth naming plainly: when our own staff open the internal view of devices seen in the last 24 hours, the IP addresses shown there are sent to ipinfo.io, a service based in the United States, to be turned into a city and country. Only the address goes, and only for that lookup.
Data retention
We retain subscription and support data only as long as needed for the purposes above or as required by law, and delete or anonymize it when it is no longer needed. Diagnostic data is aggregated and not tied to your identity.
The connection record described above — the address, the server and the time — is erased automatically once a device has been idle for 7 days. The usage counters, which contain no address, are kept for as long as the device record exists so that the plan's allowances can be applied.
Two shorter-lived records also involve an address, and neither is part of the connection record. The abuse counter described above deletes itself 48 hours after it is created. Our API also records, for each request, the address it came from, the time, and which endpoint was called — never what was done through the tunnel; those logs are deleted after 7 days.
Backups. The database is backed up continuously so the service can be restored after a failure, and those backups are kept for 35 days. A backup taken before a record was erased still contains it, so in the worst case an address can survive in a backup for up to 42 days after a device was last active. Backups are not searchable and are used only to restore the service.
Security
Your connection runs through a strongly encrypted tunnel. We apply reasonable technical and organizational measures to protect the limited data we hold. No method of transmission or storage is 100% secure, but we work to keep your data safe.
Children
Doft VPN is not directed to children and is intended for users aged 17 and older. We do not knowingly collect data from children.
International transfers
Your traffic is routed through one of the servers we operate, which is often outside the country you are in. We handle the limited personal data we hold in line with this policy wherever it is processed.
Your rights
Depending on where you live, you may have the right to access, correct, or delete the personal data we hold about you, and to object to certain processing. To exercise these rights, contact us using the details below. Because the free service requires no account, we hold no name, email or phone number for most users — but we do hold the connection record and the usage counters described above, and you can ask us to delete them.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date above and, for significant changes, notify you in the app or on our website.
Contact us
Questions about this policy or your data? Contact us at support@doft.com or through the in-app support in Doft VPN.