Privacy Policy
NexVeil exists to keep your browsing private. This policy explains — in plain language — the small amount of data we hold, why we hold it, and what we refuse to collect.
Last updated: 30 August 2026The short version: we do not log the sites you visit, the DNS queries you make, your original IP address, your session timestamps, or your bandwidth per site. We keep only the minimum needed to run your account and process payment.
1. Summary
This policy applies to the NexVeil VPN apps, our website, and our support channels. By using NexVeil you agree to the handling described here. If you disagree with any part of it, please stop using the service and contact us for a refund within the guarantee window.
2. What we never log
Our VPN servers run entirely from volatile memory (RAM). Nothing is written to a persistent disk, and every reboot wipes the machine completely. Specifically, we do not record:
- Browsing history, visited domains, or page URLs
- DNS queries made through our resolvers
- Your originating (real) IP address
- Connection timestamps or session duration
- Assigned VPN IP address tied to your account
- Traffic content, metadata, or bandwidth attributed to a destination
Because these records are never created, they cannot be leaked, subpoenaed, sold, or handed over.
3. What we do collect
| Data | Purpose | Required |
|---|---|---|
| Email address | Account login, receipts, service notices | Yes |
| Hashed password | Authentication (bcrypt, never plaintext) | Yes |
| Billing token | Held by our payment processor, not by us | Yes |
| Plan & renewal date | Entitlement and billing | Yes |
| Aggregate server load | Capacity planning — never per-user | No |
| Crash diagnostics | App stability, opt-in only | No |
Payments
Card details are processed directly by our PCI-DSS compliant payment providers. NexVeil never sees or stores your full card number. Cryptocurrency payment is available if you prefer to keep billing separate from your identity.
4. How we use your information
- To create and authenticate your account
- To charge your subscription and send receipts
- To enforce the simultaneous-device limit on your plan
- To respond when you contact support
- To detect abuse such as credential sharing at scale or spam origination
We do not use your data for advertising, profiling, or automated decision-making, and we do not sell it under any circumstance.
6. Retention
Account data is kept while your subscription is active. If you delete your account, we erase your profile within 30 days, except invoices we are legally required to retain for tax purposes. Server-side session state exists only in RAM and disappears the moment you disconnect.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to processing, or to lodge a complaint with a supervisory authority. To exercise any of these, email us from your account address and we will respond within 30 days at no charge.
8. Security
Connections use AES-256-GCM or ChaCha20-Poly1305 with perfect forward secrecy. Internal access to account systems is limited to a small on-call team, requires hardware-key multi-factor authentication, and is audited. No system is perfectly secure, but we design so that a breach exposes as little as possible.
9. Children
NexVeil is not intended for anyone under 16. We do not knowingly collect data from children; if you believe a minor has created an account, contact us and we will remove it.
10. Changes to this policy
We may update this policy as the service evolves. Material changes are announced by email and in-app at least 14 days before they take effect, and the "last updated" date above always reflects the current version.
11. Contact
Privacy questions or requests: privacy@nexveilvpn.com. For everything else, reach our 24/7 team from the contact section.
This document is a template for the NexVeil showcase site and is not legal advice. Have counsel review it before publishing to real customers.