Guardex VPN Privacy and Personal Data Processing Policy
Last updated: 30 August 2026
Document version: 2.1
This Policy explains what personal and technical data Guardex VPN processes, for what purposes and legal grounds, to whom data may be provided, how long it is retained, and how a User may exercise data rights.
This Policy is publicly available. Reading it does not replace separate consent to personal-data processing where such consent is required.
1. General Information about the Controller
1.1. The personal data controller and administrator of Guardex VPN is an individual applying the Russian Professional Income Tax (NPD) regime. Full controller details, Russian Taxpayer Identification Number, and contacts are set out in section 22 of this Policy.
Website: https://guardex-vpn.com
Privacy, deletion, and support inquiries: support@guardex-vpn.com
1.2. In this Policy, the controller may also be referred to as “Guardex” or the “Service”.
2. Scope
2.1. This Policy applies when data is processed through:
• the Guardex website and subdomains;
• the user dashboard;
• Android, iOS, Windows, and macOS applications;
• the official Telegram bot;
• VPN infrastructure;
• subscription and payment management;
• technical support.
2.2. This Policy does not replace the privacy documents of third-party services that a User chooses directly, including Google, Apple, Telegram, application marketplaces, and Payment Providers. Those services process data under their own rules in addition to this Policy.
3. Principles
Guardex seeks to:
• process data lawfully, fairly, and transparently;
• collect only data necessary for a specific purpose;
• avoid combining incompatible purposes;
• keep data accurate where reasonably possible;
• apply limited retention periods;
• protect data against unauthorized access;
• not sell personal data;
• not use VPN traffic for advertising, profiling, or data trading.
4. Data Processed
4.1. Account Data
When an Account is registered and used, Guardex may process:
• e-mail address;
• nickname or display name;
• internal User ID;
• password hash;
• Account status;
• Account creation date;
• subscription status and expiry;
• authentication tokens;
• records of accepted versions of the Public Offer, Consent, and other documents, including acceptance date and time, IP address, and User Agent.
A nickname does not have to be the User’s legal name. A fictitious display name may be used.
4.2. Google Authentication
Where Google sign-in is selected, Guardex may receive:
• persistent Google User ID;
• e-mail address;
• e-mail verification status;
• display name, where provided by Google;
• authorization code or token.
Guardex does not receive the User’s Google password and does not request a profile picture.
4.3. Sign in with Apple
Where Sign in with Apple is selected, Guardex may receive:
• persistent Apple `sub` identifier;
• ordinary e-mail address or a Hide My Email address ending in `privaterelay.appleid.com`;
• first and last name only when Apple provides them during the first authorization, after which they may be stored as one display name;
• e-mail verification status;
• a technical authorization code needed to manage the link and revoke credentials.
Guardex does not receive the User’s Apple ID password.
4.4. Telegram Authentication and Interaction
Where Telegram is used, Guardex may process:
• persistent numeric Telegram ID;
• private chat ID for the official bot;
• username, where set;
• first and last name provided by Telegram;
• Telegram interface language;
• time of the latest bot interaction;
• selected Plan, order status, and other information needed to perform the User’s command.
A Telegram phone number is not requested unless the User voluntarily provides it.
4.5. Device and Application Data
For device management, security, and application operation, Guardex may process:
• random Device ID;
• technical device fingerprint;
• device name;
• device model;
• operating system and version;
• platform;
• cryptographic public key of the installation;
• FCM token or another notification token where push notifications are actually used;
• date of the latest device activity.
The technical fingerprint is a SHA-256 value derived from a platform identifier or the installation public key. It is used to recognize an installation and prevent duplicates, may change after reinstallation, and is not an advertising identifier. Guardex may replace this mechanism with a random installation Device ID where possible.
Guardex does not collect IDFA, GAID, or other advertising identifiers for advertising or cross-service tracking.
4.6. VPN Session Metadata
To provide VPN access, enforce Plan limits, display statistics, diagnose errors, and prevent abuse, Guardex may process:
• internal User ID;
• Device ID;
• selected server;
• server country and city;
• session start time;
• session duration;
• bytes sent and received;
• aggregated daily and monthly traffic counters.
The main VPN-session metadata table does not store the originating IP address, exact URLs, destination IP addresses, DNS queries, SNI, traffic content, messages, passwords, files, or packet captures.
4.7. IP Address and Infrastructure Logs
An IP address may be processed:
• in an in-memory rate-limiting mechanism for approximately 15 minutes;
• during authentication, attack prevention, and abuse prevention;
• in Nginx, firewall, journald, monitoring, relay, ingress, exit, and hosting-provider technical logs.
Ordinary server and security logs that may contain an IP address are retained for no longer than 30 days, unless a longer period is required for an active incident, dispute, or legal obligation.
The originating IP address is technically visible to the first VPN node at connection time because routing cannot operate without it. Guardex does not use it to create browsing history.
4.8. Technical Telemetry and Diagnostics
Guardex may process:
• connect and disconnect events;
• application platform;
• selected server identifier;
• connection stage and outcome;
• connection time;
• technical error code;
• server availability information;
• speed measurements;
• first-party Guardex diagnostic events.
As of this version, Guardex does not use Firebase Analytics, Firebase Crashlytics, Sentry, AppMetrica, Google Analytics, Yandex Metrica, PostHog, Amplitude, or advertising SDKs on the website or in the applications.
4.9. Payments and Subscriptions
Guardex may receive and store:
• internal order ID;
• payment or transaction identifier;
• date and time;
• amount and currency;
• selected Plan;
• payment method and status;
• payment error code;
• subscription expiry;
• refund information;
• App Store product ID, transaction ID, and subscription status;
• Google Play product ID, purchase token, and subscription status;
• receipt identifier and URL where implemented.
Guardex does not store full payment-card numbers, CVV/CVC codes, online-banking passwords, card last digits, payer bank, or payer IP address unless a Payment Provider supplies such information and there is a lawful and necessary purpose for processing it.
Payment credentials are entered directly with the Payment Provider or application marketplace.
4.10. Support Data
When support is contacted, Guardex may process:
• User ID;
• e-mail address;
• Telegram ID;
• subject, content, and history of messages;
• source and language of the request;
• status, priority, and assigned support specialist;
• files and technical information voluntarily provided by the User.
There is no automatic user-visible support bundle with preview in the current version. Users must not send passwords, private keys, full payment-card details, or personal traffic content.
4.11. Cookies and Local Storage
The website uses or may use:
• a technical administrative session cookie;
• CSRF protection data;
• localStorage for dashboard tokens, language, theme, and local interface state;
• sessionStorage for temporary interface state.
Advertising cookies and advertising pixels are not used as of this version.
4.12. Administrative and Fraud-Prevention Data
For security, Guardex may process:
• administrator action logs;
• access-grant and access-revocation events;
• technical indicators of bulk registrations, attacks, chargebacks, fraud, and limit evasion;
• suspension and incident-investigation records.
4.13. Special Categories of Personal Data
Guardex does not request or intentionally process biometric data, health data, political opinions, religious beliefs, ethnicity, intimate-life data, or criminal-record information.
A User who voluntarily contacts support should provide only information necessary to resolve the request.
5. VPN Traffic Data Not Recorded as User Activity History
Guardex does not keep a history of:
• websites visited;
• URLs;
• destination IP addresses;
• DNS queries;
• SNI;
• internet-traffic content;
• messages, passwords, or files;
• production packet captures of User traffic.
A destination IP address and DNS query are necessarily processed at the moment traffic is routed. Guardex does not record them as a history of the User’s activity.
The statement that Guardex does not retain browsing history does not mean that the Service processes no Account, device, subscription, traffic-volume, or limited VPN-session metadata.
6. Purposes
Data is processed to:
1. register an Account and verify an e-mail address;
2. authenticate the User and recover access;
3. create and maintain the Account;
4. provide VPN access;
5. manage devices and simultaneous-connection limits;
6. apply the free allowance and Plan conditions;
7. manage a subscription;
8. accept and verify payment, issue a receipt, and process a refund;
9. restore App Store and Google Play purchases;
10. send necessary service notices;
11. provide technical support;
12. diagnose errors and improve stability;
13. prevent attacks, fraud, spam, and abuse;
14. investigate incidents and protect the parties’ rights;
15. comply with tax, payment, and other legal obligations;
16. send advertising and special offers only after separate voluntary consent.
7. Legal Grounds
Depending on the purpose, Guardex processes data on one or more of the following grounds:
• the User’s separate consent;
• necessity to enter into and perform an agreement with the User;
• compliance with a legal obligation;
• exercise of the lawful rights and interests of the Controller or a third party, provided the User’s rights and freedoms are not infringed.
Marketing processing and advertising communications are based only on separate prior consent.
8. Processing Operations and Methods
Guardex may collect, record, organize, accumulate, store, update, retrieve, use, disclose to an authorized processor, anonymize, block, delete, and destroy data.
Processing is primarily automated and involves transmission over the Internet. Support requests, refunds, and investigations may include manual processing.
Guardex does not make solely automated decisions that produce legal effects or similarly significantly affect the User without the possibility of human review. Automated safeguards may temporarily limit suspicious activity; the User may contact support.
9. Recipients and Processors
9.1. Authentication Providers
Google, Apple, and Telegram process data when the User selects the relevant login method. They do not receive from Guardex a history of VPN traffic, DNS queries, or connection content.
9.2. Payment Providers and Application Marketplaces
A Payment Provider, the App Store, or Google Play processes payment data under its own documents. Guardex receives only the data needed to verify a purchase, activate access, process a refund, prevent fraud, and keep mandatory records.
Guardex does not send browsing history or VPN traffic content to them.
9.3. E-mail Provider
Guardex uses Resend to send verification codes, access-recovery messages, receipts, and service notices. For this purpose, Resend receives the e-mail address, message subject and content, and technical delivery information. According to Resend’s published information, customer data, including message content and delivery logs, may be stored in the United States.
9.4. Hosting and Infrastructure Providers
Guardex uses hosting and VPS providers for the website, API, database, monitoring, and VPN nodes. Such providers supply computing infrastructure and may have technical capability to access disks, backups, or memory, but are not authorized to use User data for their own purposes.
9.5. VPN Nodes
Relay, ingress, and exit nodes process technical connection parameters. The first node sees the originating IP address. A foreign ingress node may receive a short-lived access token, installation identifier, and transport parameters. E-mail and payment data are not sent to VPN nodes.
9.6. Support and Authorized Personnel
Access is limited to persons who need it for support, development, security, payment handling, or legal compliance and only within their assigned role and confidentiality obligations.
9.7. Public Authorities
Data may be provided only where and to the extent required by mandatory law and a valid request.
10. Special Commitment Concerning VPN Data
Guardex does not sell, use for advertising, or disclose to third parties for their independent purposes data collected from VPN traffic or through VPN functionality.
Limited VPN-session metadata is processed only to provide and protect the connection, enforce limits, diagnose errors, and prevent abuse. Infrastructure processors are not permitted to use it for their own purposes.
11. Database Location and Cross-Border Processing
11.1. The primary Account database is located on server infrastructure in Moscow, Russian Federation.
11.2. Backups are stored in separate object storage in the Russian Federation, separate from the primary production server, on a rolling basis for up to 30 days.
11.3. Limited data may be processed outside the Russian Federation when the User uses Google, Apple, Telegram, the App Store, Google Play, Resend, foreign VPN nodes, or other foreign infrastructure necessary for a selected function.
11.4. During a VPN connection, a foreign node may technically see the originating IP address, connection parameters, and a short-lived technical access token. The complete Account profile and payment data are not sent to such nodes.
11.5. When service e-mails are sent, Resend may process the e-mail address, message content, and technical delivery data in the United States. Google, Apple, Telegram, App Store, and Google Play also apply their own privacy terms.
11.6. Guardex limits cross-border data to what is necessary for the selected feature and does not send browsing history or VPN traffic content to foreign recipients, or payment profiles to VPN nodes. This Policy describes factual data flows and does not replace any separate action required from the Controller by applicable law.
12. Retention
| Category | Retention period |
|---|---|
| Account, e-mail, nickname, User ID | While the Account exists |
| Password hash and provider IDs | While required for login or until deletion/unlinking |
| Refresh tokens | Until expiry, revocation, or Account deletion; generally up to 30 days |
| Device records | While the device is registered or the Account exists |
| IP in rate-limit memory | Approximately 15 minutes |
| Ordinary server and security logs containing IP | Up to 30 days; longer only for an active incident or dispute |
| VPN-session metadata | Up to 90 days |
| Technical telemetry events | Up to 30 days |
| Speed measurements | Up to 7 days |
| Diagnostic sessions | Up to 90 days |
| Production diagnostic reports | Up to 30 days |
| Detailed per-session and daily counters | Within the VPN-session metadata period |
| Current monthly allowance counter | While the Account exists and the Plan requires it |
| Payment, tax, and receipt records | For periods required for accounting, refunds, and protection of rights |
| Closed support requests | Up to 12 months after closure |
| Payment or legal dispute requests | Up to 3 years, or longer while a dispute remains active or law requires it |
| Support attachments | 14 days after request closure |
| Fraud-prevention records | Up to 12 months; longer during an active dispute or suspension |
| Administrator logs | Up to 12 months |
| Backups | Separate object storage in the Russian Federation; up to 30 days |
| Evidence of document acceptance | While the agreement is in effect and for the period needed to protect rights |
After the purpose is achieved, data is deleted or anonymized within the period required by law unless another lawful ground for retention exists.
13. Account Deletion
Detailed public instructions: https://guardex-vpn.com/account-deletion.
13.1. The User may initiate deletion:
• in the Application: Settings → Account → Delete Account;
• in the user dashboard: https://guardex-vpn.com/dashboard/settings;
• by e-mailing support@guardex-vpn.com.
13.2. Account access ends immediately after automated confirmation or after support completes the request.
13.3. E-mail, nickname, active tokens, devices, and other data no longer needed are deleted or anonymized in operational systems. Payment, tax, fraud-prevention, and dispute records may remain where another lawful ground applies.
13.4. Data in technical logs and backups is removed according to its lifecycle.
13.5. Deleting the Account does not cancel an App Store or Google Play subscription. The User must cancel it separately in the relevant marketplace.
13.6. After deletion, the User may create a new Account with the same e-mail unless that address is blocked for a lawful security or fraud-prevention reason.
14. User Rights
The User may:
• obtain confirmation that data is processed;
• request information about data, purposes, legal grounds, and recipients;
• request correction of inaccurate data;
• request blocking or deletion of unlawfully obtained or unnecessary data;
• withdraw consent;
• request termination of processing where provided by law;
• complain to the competent data-protection authority or a court;
• request a copy of data in an accessible format where technically feasible and without infringing third-party rights.
Requests may be sent to support@guardex-vpn.com. Guardex may request reasonable verification that the requester controls the Account.
A response is provided within the period required by applicable law; as a general rule, no later than 10 business days, subject to any legally permitted reasoned extension.
15. Withdrawal of Consent
Consent may be withdrawn by:
• deleting the Account;
• submitting a request through the dashboard;
• e-mailing support@guardex-vpn.com.
After withdrawal, Guardex stops processing based solely on consent and deletes data that is no longer needed within the period required by law. Processing may continue where necessary to end or perform an agreement, comply with law, keep mandatory records, process a refund, protect rights, or maintain security.
Withdrawal of consent necessary for Account operation may make further use of Guardex impossible.
16. Advertising Communications
16.1. Advertising, promotions, and special offers by e-mail or Telegram are sent only after separate voluntary consent.
16.2. The User may withdraw that consent using an unsubscribe link or by contacting support@guardex-vpn.com.
16.3. Refusing advertising does not affect access to the Service and does not stop necessary service notices relating to security, payment, the Account, or technical changes.
17. Cookies
17.1. Guardex uses technical cookies and local storage necessary for authentication, security, language, theme, interface state, and checkout.
17.2. If analytics or advertising technologies are added, this Policy will be updated and consent will be requested where required.
17.3. The User may remove cookies in browser settings, but some features may then stop working.
18. Security Measures
Guardex applies organizational and technical measures including:
• HTTPS/TLS for the website, API, and applications;
• bcrypt password hashing;
• a protected channel between VPN nodes;
• role-based access control;
• administrator-action logging;
• access limited to what is necessary;
• secrets stored separately from source code;
• token revocation and session termination;
• protection against mass requests and attacks;
• data minimization;
• backup of the primary database to separate object storage in the Russian Federation with limited retention.
No storage or transmission method is absolutely secure, but Guardex takes reasonable measures to reduce risk.
19. Incidents
If unauthorized access or a data leak is identified, Guardex takes steps to contain the incident, revoke compromised keys, investigate, restore security, and notify affected persons and authorities where and within the periods required by law.
20. Age
Guardex is intended only for persons aged 18 or older.
Guardex does not request a date of birth and does not knowingly seek data from minors. If Guardex learns that an Account was created by a person under 18, it may restrict the Account and delete data unless retention is required by law.
21. Changes to this Policy
21.1. A new version is published on the website with its date and version number.
21.2. Material changes may be communicated by e-mail, in the Application, in the dashboard, or through Telegram.
21.3. Where law or the nature of the change requires renewed consent, Guardex requests a separate confirmation.
22. Controller Details and Contacts
Controller: Крайник Борис, individual payer of Professional Income Tax (NPD)
Russian Taxpayer Identification Number: 390003958372
Website: https://guardex-vpn.com
E-mail: support@guardex-vpn.com