Privacy Policy
Effective 2026-06-19 · VPNbyDev (macOS, iOS & Android)
Data Controller
DEVBY.PRO LTD, a company registered in England and Wales (No. 17285382), is the data controller for personal data processed in connection with VPNbyDev. Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Contact: apps@devby.pro.
TL;DR
VPNbyDev tunnels selected traffic for you. We don't log what you do over the tunnel. We can't see your DNS queries, the sites you visit, or the content of your connections.
What we collect
- Device identifier — a random UUID generated on your device. Used to enforce the per-subscription device limit. Never linked to your name, phone, email, or anything else.
- Activation code — one-time string we issued you after purchase. Mapped to your subscription on our side, not to you personally.
- IP address — visible to our edge nodes while the tunnel is up, used to route packets. Not written to logs.
- Telegram ID — purchase happens via @payments_debypro_bot, so your TG user ID is what we use to deliver the activation code back to you. Not associated with VPN traffic in any way.
What we don't collect
- DNS queries (resolved at
1.1.1.1/1.0.0.1, not by us) - Visited domains, URLs, page content
- Bytes transferred, sessions duration
- Real name, address, phone, email — we never ask for any of these
- Device model, OS version, hardware identifiers beyond the random UUID above
Third parties we interact with
- CryptoBot (Telegram-based payment processor) — handles your USDT payment. They see your Telegram ID and amount. We receive a webhook with the payment hash. CryptoBot's policy.
- Cloudflare — proxies our control-plane and download endpoints (not your VPN traffic). They see HTTP request metadata going to those endpoints. Cloudflare's policy.
- Apple App Store / TestFlight — if you installed the iOS app from there, Apple sees that. Apple's policy.
Data retention
- Device + subscription rows: kept until subscription expiry + 90 days, then deleted.
last_seenIP: overwritten on each connection; never archived.- Payment hash (
trxid): kept indefinitely for accounting purposes.
Legal basis (UK / EU GDPR)
- Contract performance (UK GDPR Art. 6(1)(b)) — device UUID and activation code, used to deliver the paid VPN service you bought.
- Legitimate interest (Art. 6(1)(f)) — short-lived IP routing at the edge, payment-hash retention for accounting. Balanced against your privacy: we don't log traffic content and the IP is never archived.
- Legal obligation (Art. 6(1)(c)) — minimal records required by HMRC for tax compliance (payment hash + amount + date).
Your rights under UK / EU GDPR
You have the right to: access, rectify, erase, restrict, port your data, and object to processing. Request any of these by emailing apps@devby.pro — we'll respond within 14 days.
If you believe we've mishandled your data, you can complain to the UK supervisory authority: the Information Commissioner's Office (ICO). EU residents may complain to their local data protection authority.
Children
VPNbyDev is not directed to children under 13 (under 16 in the EU). We don't knowingly collect any data from children.
Changes
If we change this policy, we'll update the effective date at the top and (for material changes) notify active subscribers via the Telegram bot. Continued use after the change means you accept it.
Contact
Operator: DEVBY.PRO LTD · UK company no. 17285382 · 71-75 Shelton Street, Covent Garden, London WC2H 9JQ · apps@devby.pro