# Privacy Policy

**vploq** · Effective date: 3 August 2026 · Version 1.0

## 1. Introduction

This Privacy Policy describes how **InTallyCon Development - FZCO**, DDP,
Building A1, Dubai, United Arab Emirates ("**vploq**", "**we**", "**us**")
processes personal data in connection with the vploq service. The service
comprises the vploq applications for iOS, macOS, Android and Windows (the
"**App**"), the vploq hardware device (the "**Device**"), our coordination
service and programming interfaces, our team-invitation web pages, and related
transactional communications (together, the "**Service**").

We are the controller of the personal data described in this Policy within the
meaning of Regulation (EU) 2016/679 ("**GDPR**"). References to the GDPR
include, where applicable, the retained EU law version of the GDPR applicable
in the United Kingdom. We are established outside the European Union; our
representative in the Union under Article 27 GDPR may be contacted through the
address in Section 13.

This Policy does not apply to third-party websites, applications or services
that you access through a network connection established by the Service. We do
not observe or control their content.

Questions and requests concerning this Policy or your personal data may be
directed to [**info@vploq.com**](mailto:info@vploq.com) (Section 13).

## 2. Summary of key points

- We process the personal data necessary to operate the Service: your account details, your registered devices, and limited connection metadata required to establish and maintain encrypted tunnels.
- We do not inspect, record or store the content of your network traffic. Traffic between your devices is end-to-end encrypted using the WireGuard® protocol. Our relay servers forward encrypted packets only and hold no keys capable of decrypting them. Traffic leaving an exit Device to the open internet is protected by whatever encryption the visited service itself uses.
- We do not record DNS queries. Resolvers operated as part of the Service are configured with query logging disabled and forward queries upstream exclusively over encrypted transport (DNS over TLS).
- We do not serve advertising, do not use advertising or product-analytics software development kits, do not build behavioural profiles, and do not sell personal data. The App contains a crash-reporting component that operates only with your permission (Section 3.7).
- Connection metadata that we do process is described in Section 4, together with its retention: most records expire within one hour to seven days; security records are kept for up to ninety days; the current public IP address of a registered device is held while it remains registered.
- Service data is stored in the European Union. A limited number of processors are located in the United States; the safeguards applied to those transfers are described in Section 6.
- You may obtain a machine-readable export of your personal data and delete your account directly in the App (Section 9).

## 3. Personal data we process

This Section lists each category of personal data, its source, the purposes of
processing, the legal basis under Article 6 GDPR for each purpose, and the
retention period. Retention is summarised again in Section 7.

### 3.1 Account data

| Category | Details |
| --- | --- |
| Data | Email address; display name; internal account identifier; authentication identifier issued by our authentication provider |
| Source | Provided by you at registration (email and password, or Google Sign-In) |
| Purposes and legal bases | Creating and operating your account, authentication, and service communications — performance of a contract (Art. 6(1)(b)) |
| Retention | For the life of the account; erased upon account deletion following a thirty (30) day grace period (Section 7) |

Authentication is performed by Google Firebase Authentication. We do not
receive or store your password. Where you use Google Sign-In, we receive your
email address and name from your Google account; we receive no other Google
account data.

### 3.2 Device and installation data

| Category | Details |
| --- | --- |
| Data | Device model designation and operating system version; a randomly generated installation identifier; the WireGuard public key of each installation or Device; for hardware Devices additionally: serial number, hardware revision, firmware version and device certificate fingerprint; operational status of hardware Devices (firmware update state, uptime, reboot counters, crash signatures of on-device system services) |
| Source | Generated by, or read from, your device upon registration and during operation |
| Purposes and legal bases | Registering and identifying devices, provisioning encrypted tunnels, and delivering and monitoring firmware updates — performance of a contract (Art. 6(1)(b)). Preventing the activation of counterfeit or cloned hardware — our legitimate interest in the security and integrity of the Service (Art. 6(1)(f)) |
| Retention | For as long as the device remains registered. Device records inactive for ninety (90) days are deleted automatically; a deleted Device may be registered again at any time. Personal data on device records is scrubbed upon account deletion |

The WireGuard private key corresponding to each public key is generated on your
device. We never receive it and therefore cannot decrypt tunnel traffic
transiting our infrastructure.

### 3.3 Connection metadata

| Category | Details |
| --- | --- |
| Data | The public IP address and port of a device as observed by our infrastructure; local network parameters reported by hardware Devices (interface IP address, gateway address, configured DNS server addresses); timestamp of the most recent WireGuard handshake; network address translation behaviour statistics; a current aggregate throughput figure reported by hardware Devices (total bytes over the preceding sixty seconds, as two numbers, with no information as to destinations, connections or content — processed transiently for status display and not stored) |
| Source | Observed by our coordination service and relay servers in the course of operating the Service; reported by hardware Devices |
| Purposes and legal bases | Establishing connectivity between devices (including traversal of network address translation), device status display, and connection recovery — performance of a contract (Art. 6(1)(b)). Abuse prevention — our legitimate interest in the security of the Service (Art. 6(1)(f)) |
| Retention | One (1) hour to seven (7) days per record, as set out in Section 4.3, with two exceptions stated there: device activation events (ninety (90) days) and the current public IP address on the device record (retained while the device remains registered; scrubbed on removal or account deletion) |

### 3.4 Approximate location (country level)

We derive the country in which a device is located from its public IP address,
using a commercial IP-geolocation database (MaxMind GeoLite2) operated as an
embedded, offline copy on our own servers. No geolocation query is transmitted
to any third party. We store the country code and country name only. We do not
store city-level data, coordinates or any location history, and we never access
device GPS or other location sensors; the App requests no location permission.
The stored country value follows the device record: it is overwritten on change
and scrubbed with the device record (Section 3.2). Legal basis: performance of
a contract (Art. 6(1)(b)) — the location is displayed to you in the App and
used to select the nearest relay server.

### 3.5 Team and invitation data

Where you create or join a team, we process: the team name; membership and
role; and a team activity log recording membership and administrative actions
together with the acting user's anonymised IP address and user agent. IP
addresses in team activity logs are anonymised before storage by truncation
(final octet for IPv4; equivalent for IPv6). Legal bases: operating the team —
performance of a contract (Art. 6(1)(b)); the activity log — our legitimate
interest in the accountability of team administration (Art. 6(1)(f)).
Retention: team data for the life of the team; activity logs for ninety (90)
days.

**If you have received a team invitation:** we obtained your email address from
the team member who invited you, and we process it solely to deliver and
administer the invitation — our legitimate interest, and that of the inviting
team, in enabling team collaboration (Art. 6(1)(f)). The invitation email
contains a link to this Policy. If you do not accept, the invitation expires,
and the invitation record, including your email address, is deleted ninety (90)
days after expiry. You may object to further invitations at
[info@vploq.com](mailto:info@vploq.com).

### 3.6 Push notification tokens

A push-notification registration token (Firebase Cloud Messaging) enabling us
to deliver service notifications, such as security events and update outcomes.
On Apple platforms, delivery additionally transits the Apple Push Notification
service (Section 5.1). The token is deleted upon sign-out or account deletion;
tokens that are no longer refreshed by an active installation are deleted
automatically. Legal basis: performance of a contract (Art. 6(1)(b)).

### 3.7 Error and crash reports

The App transmits error and crash reports to our error-monitoring processor
only if you have enabled crash reporting; you are asked at first launch, and
you may change your choice at any time in the App's settings. When disabled, no
report leaves your device. Reports are minimised before transmission: request
bodies, cookies, authentication headers and IP-carrying headers are removed;
the sole user identifier attached is the internal account identifier; values
resembling IP addresses are redacted from connection metadata. Our server
software transmits equivalently minimised error reports. Legal bases: your
consent (Art. 6(1)(a)) for App reports, withdrawable at any time with effect
for the future; our legitimate interest in the reliability of the Service
(Art. 6(1)(f)) for server-side reports. Retention: error reports are retained
by the error-monitoring processor for ninety (90) days.

### 3.8 Device diagnostics

Where a firmware update fails, the hardware Device transmits a diagnostic
bundle so that the failure can be diagnosed and the update repaired. The bundle
is limited to logs of the Device's own system services, kernel messages and
storage utilisation relating to the update process; it does not contain user
traffic. Legal basis: our legitimate interest in the reliability of the update
mechanism you have enabled (Art. 6(1)(f)); you may object as described in
Section 9. Retention: thirty (30) days.

### 3.9 Infrastructure and security logs

Our cloud entry points maintain standard technical logs: load-balancer access
logs recording the connecting IP address, requested API path and user agent
(retained thirty (30) days); network flow logs (fourteen (14) days); and
application logs (fourteen (14) days). These logs concern connections to our
coordination APIs only. They are not, and by design cannot be, records of
tunnel traffic, which does not terminate at those systems. Device activation
events, including the connecting IP address, are retained for ninety (90) days
to detect cloned or counterfeit hardware. Relay servers additionally maintain
operational logs concerning their own service health, which are processed by
our monitoring processor (Section 5.1) and retained on a rolling basis and expire automatically. Legal basis: our legitimate interest in network security, abuse
prevention and service operation (Art. 6(1)(f)).

### 3.10 Data and practices we do not employ

We do not process: the content of your network traffic; browsing history;
per-connection or per-destination records; DNS query logs; advertising
identifiers; analytics or behavioural profiles; device GPS or location-sensor
data; contacts, photographs, camera or microphone data (the App requests no
such permissions); your passwords; or your WireGuard private keys.

Automated checks may refuse the activation of hardware that fails authenticity
verification (Section 3.2). You may contest such a refusal and obtain human
review by contacting [info@vploq.com](mailto:info@vploq.com). We carry out no
other automated decision-making producing legal or similarly significant
effects, and no profiling, within the meaning of Article 22 GDPR.

Our web pages do not use cookies or similar technologies for tracking,
advertising or analytics. Strictly necessary security cookies may be set by our
infrastructure providers.

### 3.11 Whether you are required to provide personal data

Providing an email address is a contractual requirement: without it we cannot
create or operate your account. The device data described in Section 3.2 is
necessary to register a device. You are under no statutory obligation to
provide any personal data. All other data described in this Policy arises from
your use of the Service.

## 4. Traffic and logging

We consider generalised "no-logs" statements insufficiently precise. This
Section describes in detail what the Service records in connection with tunnel
traffic and connectivity; all other records are described in Section 3.

### 4.1 Traffic content

Relay servers forward encrypted WireGuard packets between peers. They do not
hold the cryptographic keys required to decrypt such packets, perform no packet
capture or payload inspection, and maintain no per-user traffic records or
connection logs. Hardware Devices report a single current sixty-second
aggregate byte counter for health display (Section 3.3); it is not stored, and
no history exists. Rate-limiting rules applied against flooding discard excess
packets without logging. Devices configured as exit points route traffic using
stateless network address translation, without logging rules, flow export or
per-destination counters.

### 4.2 DNS

Resolvers operated on exit Devices are configured with query logging disabled
and respond from memory-resident caches only. Queries that cannot be answered
from cache are forwarded exclusively over DNS over TLS (encrypted transport) to
resolver services operated by Mullvad and by Quad9, each of which publishes a
no-logging commitment for its resolver service. Such upstream resolvers observe
queries as originating from the network address of the exit Device and receive
no account identifier or other information from us. No DNS query is written to
persistent storage at any layer of the Service.

### 4.3 Connection metadata retained

| Record | Purpose | Retention |
| --- | --- | --- |
| Device public IP address and port observed by a relay server | Establishment of direct peer-to-peer connections (NAT traversal) | One (1) hour from last observation |
| Connection candidates reported by a device (local and public addresses) | NAT traversal | Seven (7) days from last refresh |
| Most recent WireGuard handshake timestamp | Device status display; connection recovery | Current value only; overwritten upon each report |
| Public IP address on the device record | Routing; country display (Section 3.4); abuse prevention | While the device remains registered; deleted with the device; devices inactive ninety (90) days are deleted automatically |
| Device activation events, including connecting IP address | Detection of cloned or counterfeit hardware | Ninety (90) days |
| Team and administrative activity logs (anonymised IP address; user agent) | Accountability of team and support actions | Ninety (90) days |
| Load-balancer access logs (IP address; API path; user agent) | Security; abuse prevention; fault diagnosis | Thirty (30) days |

No component of the Service creates records associating your identity with the
destinations of your traffic, because no component observes those destinations
in unencrypted form or logs them.

### 4.4 Exit Devices and your IP address

If you enable a Device as an exit point, traffic of other members of your team
exits to the internet through your network connection. The operators of visited
services, and the upstream DNS resolvers named in Section 4.2, will observe
your public IP address as the apparent origin of that traffic. You enable this
function yourself and may disable it at any time in the App.

## 5. Recipients of personal data

### 5.1 Processors

We disclose personal data only to the processors listed below, solely to the
extent necessary to operate the Service, and subject to data-processing
agreements pursuant to Article 28 GDPR. The transfer mechanism column is
explained in Section 6.

| Processor | Processing | Location of processing | Transfer mechanism |
| --- | --- | --- | --- |
| Amazon Web Services EMEA SARL | Hosting of the Service: databases, computing, storage and logging; encrypted at rest | Frankfurt am Main, Germany (eu-central-1) | Not applicable (EU) |
| Hetzner Online GmbH | Operation of relay servers through which encrypted tunnel traffic transits; no traffic data is stored (Section 4.1) | Falkenstein, Germany; Helsinki, Finland | Not applicable (EU) |
| Google Ireland Limited, with Google LLC as sub-processor (Firebase Authentication and Cloud Messaging) | Sign-in identities (email address, authentication identifier); push-notification tokens and payloads | United States | SCCs; EU–U.S. DPF (subject to verification) |
| Apple Inc. (Apple Push Notification service) | Delivery of push notifications on Apple platforms (device push token; notification payload) | United States | SCCs; EU–U.S. DPF (subject to verification) |
| Resend, Inc. | Delivery of transactional email (recipient address; message content, including invitation links) | United States | SCCs; EU–U.S. DPF (subject to verification) |
| Cloudflare, Inc. | Object storage and delivery: firmware updates; time-limited data-export archives; device diagnostic bundles; service-status page | Global network (United States and other countries) | SCCs; EU–U.S. DPF (subject to verification) |
| Functional Software, Inc. (Sentry) | Error and crash reports, minimised as described in Section 3.7 | United States | SCCs; EU–U.S. DPF (subject to verification) |
| Grafana Labs | Operational logs and metrics of relay servers (service health telemetry) | United Kingdom (London); remote access by Grafana Labs personnel may occur from the United States | UK: adequacy decision; US access: SCCs |

### 5.2 Other disclosures

We may disclose personal data where required by a legal obligation to which we
are subject (Art. 6(1)(c)), or by a binding order of a court or competent
authority. We can only disclose what we hold. For traffic content and DNS
activity, we hold nothing (Section 4). We do not sell personal data and have
never done so.

## 6. International data transfers

Personal data is stored within the European Union. Transfers to Grafana Labs'
United Kingdom facilities are covered by the European Commission's adequacy
decision in respect of the United Kingdom. Where a processor listed in Section
5.1 processes personal data in the United States or from other third countries,
the transfer is performed on the basis of the European Commission's Standard
Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, where
the processor holds a valid certification, the EU–U.S. Data Privacy Framework
adequacy decision. Access to personal data by us as controller from the United
Arab Emirates is likewise performed on the basis of the Standard Contractual
Clauses. These safeguards are supplemented by the technical measures described
in this Policy, including transport encryption and data minimisation.

You may obtain a copy of the Standard Contractual Clauses we have concluded
(redacted for commercial terms) by writing to
[info@vploq.com](mailto:info@vploq.com). The Commission's standard text is
published on EUR-Lex ([eur-lex.europa.eu](https://eur-lex.europa.eu)).

## 7. Retention and deletion

Retention periods are stated per category in Sections 3 and 4.3. In summary:
connection metadata, one hour to seven days, except device activation events
(ninety days) and the current public IP address on the device record (life of
the registration); infrastructure logs, fourteen to thirty days; activation,
team and administrative logs, ninety days; error reports, ninety days; device
diagnostics, thirty days; inactive device records, ninety days; expired
invitations, ninety days; data-export archives, forty-eight hours; account
data, for the life of the account. Database backups are retained on a rolling
basis and expire automatically; backups are not used to restore deleted
accounts, and personal data may persist in encrypted backups until the
corresponding backup expires.

Upon account deletion, we immediately: deactivate the account; scrub personal
data from device records and application-level activity records (names,
addresses, IP addresses, location data); revoke the certificates of associated
Devices; delete push-notification tokens and any data-export archives; and
terminate all sessions. Infrastructure logs (Section 3.9) are not retroactively
edited; they expire on their fixed schedules of fourteen to thirty days.
Residual account data is permanently erased upon expiry of a thirty (30) day
grace period, which exists solely to permit reversal of accidental deletion.
Records retained beyond deletion are limited to entries necessary for security
purposes — such as the revocation record of a device certificate and the
deletion event itself — and may include a pseudonymous internal identifier, but
no name, email address or network address.

## 8. Security

We apply technical and organisational measures appropriate to the risk,
including: end-to-end encryption of tunnel traffic using the WireGuard protocol
(ChaCha20-Poly1305; Curve25519), with private keys generated on, and never
leaving, your devices; mutual TLS authentication of Devices against our
services using per-device certificates issued at activation; TLS for all
connections to our APIs and for email delivery; encryption at rest of
databases, secrets and logs using managed keys with automatic rotation;
cryptographic signing of firmware updates, verified by the Device before
installation; and restricted access to production systems using short-lived
credentials.

No system is perfectly secure. In the event of a personal data breach we will
notify the competent supervisory authority and, where required, affected data
subjects in accordance with Articles 33 and 34 GDPR.

## 9. Your rights

### 9.1 Rights under the GDPR

You have the rights of access (Art. 15), rectification (Art. 16), erasure
(Art. 17), restriction of processing (Art. 18) and data portability (Art. 20),
the right to withdraw consent at any time with effect for the future
(Art. 7(3)), and the right to lodge a complaint with a supervisory authority
(Art. 77). You may also request further information on the balancing
assessments underlying our legitimate-interest processing.

**Right to object (Art. 21).** Where we process your personal data on the basis
of legitimate interests (identified per category in Section 3), you have the
right to object at any time, on grounds relating to your particular situation.
We will then cease the processing unless we demonstrate compelling legitimate
grounds that override your interests, rights and freedoms.

### 9.2 Self-service means

The following may be exercised directly in the App:

- **Access and portability.** Profile → My information → Request data export: a machine-readable archive of your personal data, accompanied by a disclosure statement listing recipients and retention periods; available for forty-eight (48) hours following generation; limited to one request per twenty-four (24) hours; subject to re-authentication.
- **Erasure.** Profile → My information → Delete account, with the effects described in Section 7.
- **Rectification.** Account details in the Profile screen; devices may be renamed or removed at any time.
- **Withdrawal of consent.** The crash-reporting setting (Section 3.7) may be changed at any time.

### 9.3 Requests

Requests may also be made to [info@vploq.com](mailto:info@vploq.com). We
respond within one month of receipt; this period may be extended by two further
months for complex or numerous requests, in which case we will inform you
within the first month (Art. 12(3) GDPR). We will verify the identity of the
requester before acting on a request and may ask for further information for
that purpose.

### 9.4 Complaints

You may lodge a complaint with the supervisory authority of your habitual
residence, place of work or the place of an alleged infringement. A directory
of EU supervisory authorities is maintained by the European Data Protection
Board ([edpb.europa.eu](https://edpb.europa.eu)).

## 10. Children

The Service is not directed at children below the age of sixteen (16), and we
do not knowingly process the personal data of such children. Where we become
aware that such data has been collected, we will delete it. Reports may be made
to [info@vploq.com](mailto:info@vploq.com).

## 11. Additional information for certain jurisdictions

This Policy is written to the standard of the GDPR, which we apply to all users
worldwide as our baseline. The following subsections state additional
disclosures required by particular jurisdictions. Where the law of your
jurisdiction grants you further rights, we will honour them; contact
[info@vploq.com](mailto:info@vploq.com).

### 11.1 California

In the preceding twelve months we have collected the following categories of
personal information as defined by the California Consumer Privacy Act:
identifiers (email address, name, account and device identifiers, IP address) —
retained for the life of the account or of the device registration (Sections 3
and 7); internet or other electronic network activity information (limited to
the API access logs and connection metadata described in Sections 3.9 and 4.3;
we do not collect browsing history) — retained between one hour and ninety
days; coarse geolocation data (country, derived from IP address) — retained
while the device remains registered; and sensitive personal information limited
to account log-in credentials, which are processed by our authentication
provider (we never receive your password) and used solely to authenticate you.

We collect this information from you and your devices and, in the case of
invitation email addresses, from the team member who invites you. We use it for
the purposes stated in Section 3 and disclose it only to the service providers
listed in Section 5.1. We do not sell personal information and do not share
personal information for cross-context behavioural advertising, and we have not
done so in the preceding twelve months. We have no actual knowledge of selling
or sharing the personal information of consumers under sixteen (16) years of
age. We do not use or disclose sensitive personal information for purposes
other than providing the Service.

California residents have the rights to know, to delete, to correct, and to
non-discrimination, exercisable in the App (Section 9.2) or at
[info@vploq.com](mailto:info@vploq.com). An authorized agent may submit a
request on your behalf at the same address; we will require proof of
authorization and verify your identity. Because we do not sell or share
personal information, there is no opt-out to be exercised through opt-out
preference signals such as Global Privacy Control; we honour the substance of
such signals by not engaging in the practices they are designed to prevent.

## 12. Changes to this Policy

We may amend this Policy from time to time. Amendments will be published at
this address with an updated effective date; previous versions are available on
request. In the case of material changes — including new categories of personal
data, new purposes of processing or new categories of recipients — we will
provide prior notice through the App or by email.

## 13. Contact

InTallyCon Development - FZCO
DDP, Building A1
Dubai, United Arab Emirates

[info@vploq.com](mailto:info@vploq.com)

We have not appointed a data protection officer, as we are not required to do
so under Article 37 GDPR; the contact above handles all data-protection
matters.

---

*WireGuard is a registered trademark of Jason A. Donenfeld.*
