Privacy Policy
Effective and last updated August 28, 2026
AugustVPN is designed not to retain a history of what you do through the VPN. We do retain limited account and operational information needed to provide the service, enforce device limits, measure bandwidth, process payments, diagnose crashes, and protect our systems. This policy explains the difference.
1. Scope and controller
This policy applies to AugustVPN's websites, account and billing flows, applications, and VPN service (together, the “Service”). Okaeri Communications, LLC, a Delaware limited liability company, is the controller of the personal information described in this policy.
This policy does not govern websites, applications, or services you choose to access through the VPN. Those services apply their own privacy practices.
2. VPN activity we do not retain
Our systems do not write the following VPN activity to persistent storage:
- the content of your network traffic or communications;
- websites, services, destination domains, or destination IP addresses you access;
- DNS requests;
- your source IP address or the VPN IP address assigned to you;
- connection start or end times, session duration, or a history of VPN sessions; or
- a record linking a particular online activity to your account or device.
A VPN cannot route a live connection without processing some of this information. During a connection, network addresses, destinations, authentication state, DNS requests, and traffic necessarily pass through volatile memory and network buffers. We use that information only to establish and carry the live connection and do not intentionally persist it as an activity log.
“No logs” in our product materials means no retained VPN activity logs. It does not mean that we hold no account, device, bandwidth, payment, crash, security, or website information. Those categories are described below.
3. Information we retain
Account and payment information
Stripe provides our account and billing system. We may access and retain your email address, Stripe customer and subscription identifiers, subscription status, transaction amount and date, billing history, and related fraud, refund, or chargeback information. Stripe collects and processes payment-method details under its own privacy policy. We do not store full payment-card numbers on AugustVPN systems.
Device identifier and app version
Our apps send a stable, app-scoped device identifier and the app version and build number with configuration requests. A router may instead use its hardware identifier. We associate this information with a subscription to authenticate devices, enforce simultaneous-device limits, maintain compatibility, and troubleshoot version-specific problems. The mobile-app identifier is not an advertising identifier and is not used to track you across other companies' apps.
Aggregate bandwidth
We count the total logical payload bytes transferred for each subscription and report that aggregate usage to Stripe as metered usage. This measurement does not contain traffic content, websites, DNS requests, destination addresses, or a browsing history.
Crash reports and diagnostics
Our apps may send crash reports to help us identify and repair failures. A report may include the app version, operating-system and device type, the technical state of the app at the time of the failure, and error messages. We do not intentionally include VPN traffic content, DNS requests, or browsing history in crash reports. AugustVPN does not use Apple or Google analytics, sign-in, or account-identity services to authenticate you.
Website, account-recovery, and security data
Cloudflare hosts and protects the AugustVPN website and account APIs. When you visit or use them, Cloudflare and AugustVPN may process your IP address, request headers, browser and device information, requested URL, approximate region, timestamps, response status, and security signals. We use short-lived, hashed identifiers for rate limiting and store short-lived grants for single-use account-recovery links. Cloudflare does not carry AugustVPN tunnel traffic.
Our control plane may retain account-service events, such as a configuration being served, with a Stripe customer or subscription identifier and an event timestamp. These records concern account authentication and service operation; they do not record a VPN connection, source IP address, destination, DNS request, or traffic content.
The AugustVPN website does not use advertising trackers or third-party analytics scripts. It uses browser local storage to remember your language choice. If you reveal an AugustVPN credential in the browser, the credential is stored locally on that device so you can return to the configuration page. It is a bearer credential: anyone who obtains it can use the subscription. You can remove it by selecting “Forget on this device” or clearing the site's storage in your browser.
Communications
If you contact us, we receive your email address and the contents and metadata of your message. Please do not include traffic contents, credentials, or other sensitive information in support messages unless necessary.
4. How and why we use information
We use retained information to:
- provide, authenticate, maintain, and bill for the Service;
- enforce subscription and device limits;
- deliver account-recovery and service messages;
- measure capacity and aggregate bandwidth;
- diagnose crashes, fix defects, and maintain app compatibility;
- prevent fraud, spam, abuse, and attacks; and
- comply with law and establish, exercise, or defend legal claims.
Where data-protection law requires a legal basis, we rely on performance of our contract with you, our legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where the law requires it. You may withdraw consent at any time, without affecting processing that occurred before withdrawal.
6. Retention and deletion
We do not have a fixed automatic deletion period for account, payment, aggregate bandwidth, communications, or crash-report data. Unless a shorter technical expiration applies, we may retain these records indefinitely while they remain useful for the purposes described above. You can ask us to delete them at any time.
Active device-lease records ordinarily expire after seven days without a configuration request. Short-lived account-recovery grants and rate-limit records expire automatically after their operational window. Copies may remain temporarily in rotating backups after deletion from live systems.
When we verify a deletion request, we will delete or de-identify information under our control and instruct processors to do the same where applicable. We may retain limited information when required by tax, accounting, fraud-prevention, dispute-resolution, or other law, or when needed to establish, exercise, or defend legal claims. Deleting account or device records may prevent us from continuing to provide the Service.
7. Your rights
Depending on where you live, you may have rights to request access to, a copy of, correction of, or deletion of your personal information; to restrict or object to processing; to withdraw consent; to request portability; and to appeal our response. You may also complain to your local data-protection authority.
California residents may request to know, correct, or delete covered personal information and may receive equal service and pricing for exercising their rights. Because we do not sell or share personal information for cross-context behavioral advertising, there is no sale or sharing to opt out of. We do not use or disclose sensitive personal information to infer characteristics about you.
Submit a request to kevin@augustvpn.com. We may need to verify that you control the relevant email address, subscription, or device before fulfilling a request. An authorized agent may submit a request where applicable, but we may require proof of authorization and verification of the customer.
8. International transfers
AugustVPN is operated from the United States and uses providers and VPN infrastructure in multiple countries. Your information may therefore be processed outside the country where you live. Where required, we use contractual or other lawful transfer mechanisms intended to protect personal information. Privacy protections and government-access rules vary by jurisdiction.
9. Security
We use technical and organizational safeguards appropriate to the nature of the information we process, including encryption in transit, access controls, credential redaction, short-lived and single-use account-recovery links, and data minimization. No system is perfectly secure, and we cannot guarantee that unauthorized access or disclosure will never occur.
A VPN improves privacy between your device and the VPN server, but it does not make you anonymous and cannot control tracking or data collection by websites and services you access.
10. Legal requests and business changes
We respond only to legal demands that we reasonably believe are valid and binding on Okaeri Communications, LLC. We cannot provide retained VPN activity logs that do not exist, but we may be able or required to provide account, device, aggregate bandwidth, payment, crash-report, support, or website-security information described in this policy.
If AugustVPN is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
11. Children
The Service is not directed to anyone under 18, and you must be at least 18 to use it. If we learn that we collected personal information from someone under 18, we will delete it. Contact us if you believe this has occurred.
12. Changes to this policy
We may update this policy as the Service or law changes. We will post the revised policy here and update the date above. If a change materially reduces our privacy commitments, we will provide additional notice when reasonably possible before the change takes effect.
13. Contact
Okaeri Communications, LLC100 W 31st St #23C
New York, NY 10001
United States
kevin@augustvpn.com