Privacy Policy
Last updated:
This policy explains what Warden VPN does with information about you, and what it deliberately does not do. It covers the Warden VPN mobile applications for iOS and Android and this website.
1. Who we are
Warden VPN is operated by HIGHLIGHT APPS LTD, a company registered in England and Wales. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, HIGHLIGHT APPS LTD is the data controller for the personal data described in this policy.
HIGHLIGHT APPS LTD85 Great Portland Street
London, W1W 7LT
United Kingdom
Telephone: 44-7400303964
E-mail: support@warden-vpn.website
2. The short version
Warden VPN exists to carry your traffic, not to read it. In plain terms:
- Your internet activity is not tracked, not logged and not stored. We do not record the sites you visit, the services you use, the content of your traffic or DNS queries made through the tunnel.
- Your IP address is used only to approximate your location and select a server, and it is deleted at the end of the session.
- We collect a small amount of technical and diagnostic data so that the automatic selection of core, transport and location can work, and so that we can fix crashes.
The sections below set out the detail. Where this summary and the detail appear to differ, the detail is what governs.
3. What we collect
3.1 Device and application data
- A device identifier generated by the app, used to associate your installation with your subscription.
- Device model, operating system version, and device settings relevant to the app such as interface language and region.
- Application version and build number.
3.2 Network and connection diagnostics
- Network type (for example mobile data or Wi-Fi) and the general characteristics of the network your device is on.
- Connection diagnostics: connection status, connection and disconnection events, throughput, latency, and which core, transport and location were selected.
- Errors and crash reports, including the technical state of the app at the moment of the failure.
This is the data the automatic selection is built on. Without it the app cannot tell which combination works on your current network.
3.3 IP address
Your IP address is processed when you connect, for two purposes only: to approximate your location so that a suitable server can be chosen, and to establish the connection itself. It is not written to a persistent log against your activity, and it is deleted at the end of the session.
3.4 What we do not collect
- Your browsing history.
- Your activity inside the VPN tunnel, including destinations, DNS queries, traffic content and metadata about individual requests.
- Payment card details. Purchases are handled entirely by Apple and Google; we never see your card.
4. Why we process it, and our legal basis
| What | Why | Legal basis (UK GDPR) |
|---|---|---|
| Device identifier, device model and settings | To provide the app, apply your subscription, and deliver the interface in your language | Article 6(1)(b) — performance of a contract with you |
| IP address | To establish the VPN connection and approximate your location so that a server can be selected | Article 6(1)(b) — performance of a contract with you |
| Network type and connection diagnostics | To select and keep adjusting the core, transport and location, and to keep the service reliable | Article 6(1)(f) — our legitimate interest in a service that connects and stays connected |
| Crash reports | To find and fix defects | Article 6(1)(f) — our legitimate interest in a working product |
| Analytics with identifiers, and advertising identifiers | To understand how the app is used and, in the free tier, to show advertising | Article 6(1)(a) — your consent, which you may withdraw at any time |
Where we rely on legitimate interests, we have considered the effect on you and limited what we process to technical readings that are not tied to what you do online. You may object to that processing — see Your rights.
5. How long we keep it
- IP address — deleted at the end of the session. It is not retained after the connection closes.
- Device identifier and subscription status — kept while your installation is active and for as long as we need it to honour subscription entitlements, then deleted.
- Connection diagnostics and analytics — retained in aggregated or short-lived form according to the retention periods of the processors named below, and not used to build a profile of your activity.
- Crash reports — retained by our crash reporting processor for its standard retention period, then deleted.
6. Who we share it with
We do not sell personal data. We use the following processors, each of whom may process the categories of data described above on our instructions:
- Firebase Analytics (Google) — product analytics.
- Firebase Crashlytics (Google) — crash reporting.
- An advertising network — to serve advertising in the free tier of the app.
- The app store payment platforms — Apple and Google process subscription purchases and billing under their own terms and privacy policies.
We may also disclose data where we are legally required to do so. Because we do not log your activity, there is no record of what you did online for us to disclose.
7. International transfers
Some of our processors are located outside the United Kingdom, and our servers are distributed across many countries. Where personal data is transferred outside the UK, we rely on UK adequacy regulations or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards required in the circumstances.
8. Cookies on this website
This website does not set any non-essential cookie or start any analytics until you have given consent through the banner. Refusing is exactly as easy as accepting: both options appear together on the first screen of the banner, and refusing means nothing beyond your choice is stored.
Your choice is remembered in your browser's local storage so that we do not ask again on every visit. You can change it at any time through Cookie settings in the footer of any page. This is separate from the analytics consent inside the mobile app, which is managed in the app.
9. Your rights
Under the UK GDPR you have the right to:
- ask for access to the personal data we hold about you;
- ask us to correct data that is inaccurate or incomplete;
- ask us to erase your data;
- ask us to restrict how we process it;
- object to processing carried out on the basis of legitimate interests, and to processing for direct marketing;
- receive the data you gave us in a portable, machine-readable form;
- withdraw consent at any time, where we rely on consent, without affecting processing carried out before you withdrew it.
To exercise any of these, write to support@warden-vpn.website. We will respond within one month. To help us find your records, include the device identifier shown on the Settings screen of the app — without it we may not be able to identify the data that relates to you.
If you are not satisfied with our response, you can complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk or on 0303 123 1113.
10. Children
Warden VPN is not directed at children and is not intended for anyone under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the app changes or as the law requires. The date at the top of this page always shows the current version. Where a change materially affects how we handle your data, we will give notice in the app before it takes effect, and where the change requires your consent we will ask for it.
12. How to contact us
For any question about this policy or about your data, write to support@warden-vpn.website, or to:
HIGHLIGHT APPS LTD85 Great Portland Street
London, W1W 7LT
United Kingdom
Telephone: 44-7400303964
E-mail: support@warden-vpn.website