Skip to content
FENDVPN← Back to site

Privacy Policy

This policy describes how FEND VPN handles your information. It is written to describe what the app and our servers actually do — if you find something here that does not match the product’s behaviour, treat that as a bug and tell us.

1. Who we are

FEND VPN (“FEND”, “we”, “us”) is an Android VPN application operated by Kodefirm, registered at 587, Johar Town, Lahore. For the purposes of data protection law, that entity is the data controller for the personal data described in this policy.

Questions about this policy, or any request relating to your data, can be sent to support@fendvpn.com.

2. The short version

  • We authenticate you with Google Sign-In only. We never receive or store a password.
  • Your device generates its own encryption keypair. The private key never leaves your device and is never sent to us.
  • We do not log your browsing traffic. No destination sites, URLs, DNS queries, or content.
  • The VPN server keeps a small session record — bytes transferred, start and end time, and the internal tunnel IP assigned — for billing and abuse prevention.
  • Payments run entirely through Google Play Billing. We never see your card details.
  • Free-tier users see ads served by Google AdMob, which collects data under Google’s own terms.

The rest of this document is the same information in detail. Where the two differ, the detailed sections govern.

3. What we collect

3.1 Account information (from Google Sign-In)

Google Sign-In is the only authentication method FEND VPN supports. When you sign in, Google provides us with:

  • your email address;
  • your display name;
  • the URL of your Google profile photo; and
  • Google’s internal subject identifier for your account (an opaque string Google uses to identify you to us).

We never receive, and never store, your Google password or any other credential. Authentication is performed by Google; we only receive the result.

3.2 Device encryption keys

Each device you install FEND VPN on generates its own encryption keypair locally, on the device. The device sends us only the public key, which the VPN server needs in order to establish a tunnel with it. The private key never leaves your device, is never transmitted to us, and is never stored on our servers. This is a property of how the AmneziaWG protocol and the app are built rather than a policy we apply — there is no copy of your private key for us to disclose, lose, or be compelled to hand over.

3.3 VPN session records

For each VPN session, the VPN server retains a short record so that we can enforce the free-tier allowance and detect abuse of the network:

  • the total number of bytes transferred during the session;
  • the time the session started and the time it ended; and
  • the internal tunnel IP address assigned to your device for that session.

That is the complete list. These records contain no information about what you did while connected.

3.4 Subscription status

If you subscribe to Premium, Google Play tells us the status of that subscription — active, cancelled, or expired — so that the app knows which tier to apply to your account. See section 5 for what we do not receive.

3.5 Advertising (free tier only)

The free tier is supported by ads served through Google AdMob. AdMob collects data about ad delivery and interaction under Google’s own privacy terms, which are not restated here — see How Google uses information from sites or apps that use our services and the Google Privacy Policy. Where regional rules require it, the app asks for your consent to personalised advertising on first launch, and you can decline. Premium removes ads entirely.

4. What we do not collect

We do not log your browsing traffic. We do not record the websites or services you connect to, the URLs you request, your DNS queries, or the contents of your traffic.

This is supported by how the system is arranged rather than by promise alone. Two separate sets of machines are involved:

  • Control-plane servers handle sign-in, accounts, and session requests. Your VPN traffic never passes through them, so they have no browsing activity to see in the first place.
  • VPN servers carry your traffic. Traffic travels directly between your device and the VPN server. What the VPN server retains is the session record described in section 3.3 — volume, timing, and assigned tunnel IP — and nothing about destinations or content.

We also never receive your payment card details (section 5) and never receive your device’s private key (section 3.2).

5. Payments

Premium subscriptions are purchased and billed entirely through Google Play Billing. Google processes the payment; we never receive or store card numbers, bank details, or any other payment instrument. The only payment-related information that reaches us is the subscription status Google reports for your account.

6. How we use this information

  • Account information — to identify your account, apply the correct tier to it, and communicate with you about the service.
  • Public keys — to establish the encrypted tunnel between your device and the VPN server.
  • Session records — to enforce the 1 GB of data per day free-tier allowance, to bill and provision correctly, and to identify abuse of the network such as traffic patterns that threaten service for other users.
  • Subscription status — to unlock or lock Premium features.

We do not sell your personal data, and we do not use your VPN session records to build advertising or behavioural profiles.

Where data protection law (such as the GDPR or the UK GDPR) applies to you, we rely on the following bases:

  • Performance of a contract — processing your account information, public keys, and session records is necessary to provide the service you asked for.
  • Legitimate interests — retaining short session records for abuse prevention and network integrity.
  • Consent — personalised advertising, where your consent is requested in the app and can be withdrawn.
  • Legal obligation — where we are required to retain or disclose information by applicable law.

8. Who else is involved

We share information only with the parties needed to run the service:

  • Google — for authentication (Google Sign-In), subscription billing (Google Play Billing), and advertising on the free tier (AdMob), each under Google’s own terms.
  • Infrastructure providers — the hosting providers that operate the physical servers our control plane and VPN nodes run on.
  • Legal disclosure — we may disclose information where we are legally required to. We cannot disclose information we do not hold: we have no browsing logs, and we have no copy of your device’s private key.

9. How long we keep things

  • Account information — for as long as your account exists.
  • Public keys — for as long as the corresponding device is registered to your account.
  • Session records — up to 30 days, for allowance enforcement, billing, and abuse prevention, after which they are deleted.
  • Subscription status — for as long as your account exists, and afterwards where required for business or tax records.

10. Security

Tunnels are encrypted using AmneziaWG, an obfuscated variant of WireGuard. Keys are generated on your device and the private half never leaves it. Traffic between the app and our control-plane servers is encrypted in transit. No system is perfectly secure, and we do not claim otherwise — but the design deliberately minimises what an attacker (or we) could obtain from our servers.

11. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to or restrict certain processing, withdraw consent, and receive a copy of your data in a portable form. To exercise any of these, contact support@fendvpn.com.

11.1 Deleting your account

You can request deletion of your account at any time. When you do, your personal data is deleted or anonymised — including your account information and the public keys registered to it. Aggregate, de-identified usage records that can no longer be linked back to you may be retained for business records where regionally permitted.

Deleting your FEND VPN account does not cancel a Google Play subscription. Cancel that separately in Google Play, or you may continue to be billed.

12. Children

FEND VPN is not directed at children and is not intended for use by anyone under the age at which they can consent to online services where they live. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at support@fendvpn.com and we will delete it.

13. International transfers

Our servers are located in the countries listed on the servers section of our site, and our service providers may process data in other countries. Where data is transferred out of a region with data-transfer restrictions, we rely on the safeguards available under applicable law.

14. Changes to this policy

We may update this policy from time to time, and the current version is always the one published here. Where a change materially affects how we handle your data, we will give notice in the app before it takes effect.

15. Contact

Kodefirm
587, Johar Town, Lahore
support@fendvpn.com