Privacy Policy

Effective: 30 July 2026 Last updated: 30 July 2026

This Privacy Policy explains how HARMANPLUS TECHNOLOGIES LTD (“HarmanPlus”, “we”, “us”) processes personal data when you use HarmanVPN, including the mobile application, website and related services.

1. About this Policy

Please read this Policy together with our Terms of Service and Acceptable Use Policy. If you do not agree, do not create an account or use the service.

We may update this Policy when our practices or legal requirements change. The effective date above will be updated when we publish a revised version.

2. Data Controller

HARMANPLUS TECHNOLOGIES LTD

United Kingdom

General and developer contact: developer@harmanplus.com

Privacy, data rights and support requests: support@harmanvpn.com

3. Scope

This Policy covers the HarmanVPN mobile application and supported platforms, the harmanvpn.com marketing site, authentication and account APIs, VPN node configuration APIs, and related admin operations.

It does not cover third-party websites or services you choose to visit while connected to the VPN.

4. Information We Collect

We collect only categories needed to operate accounts, secure the service, enforce HarmanVPN Free plan quotas, deliver optional notifications, and (when advertising is enabled for HarmanVPN Free users) serve consent-gated ads. Categories are described below.

5. Account Information

When you register we process: name, email address, password (stored only as a one-way hash — we do not store plaintext passwords), locale preference, and timestamps for terms/privacy acceptance.

We may store registration IP address and last login IP/time for security and abuse prevention.

Email verification and password-reset tokens are stored temporarily to complete those flows.

6. Device and Security Information

To manage sessions and devices we may process: device name, client-generated device identifier, platform, app version, OS/build metadata, approximate last-seen time, and last IP associated with the device record.

If you enable push notifications we process a Firebase Cloud Messaging registration token (stored encrypted at rest in our control plane) and related delivery status for campaigns you are eligible to receive.

We record login and security events (success/failure, IP, user-agent summary) for account security.

Admin panel access may use multi-factor authentication secrets and short-lived trusted-device cookies for administrators only.

7. VPN Service and Network Information

To establish a WireGuard tunnel we process technical VPN parameters such as your device’s WireGuard public key, the assigned tunnel address, selected node/region, and connection/disconnection state in our control plane.

WireGuard private keys are generated and stored on your device (protected by platform secure storage). We do not receive your private key.

VPN nodes keep the live peer public key and assigned address while a peer is active so the tunnel can operate. After disconnect/unbind the peer is removed from the node configuration; control-plane binding rows may retain disconnected status and timestamps.

8. VPN Traffic We Do Not Intentionally Record

We do not intentionally record: destination IP addresses of your VPN traffic, DNS query names, URLs, page content, or browsing history.

We do not operate packet-capture or destination logging features in our VPN node configuration for user traffic.

Separately, standard infrastructure access logs on servers (for example reverse-proxy logs for management/API endpoints) may temporarily include source IP addresses and request metadata for security and operations. Those logs are not used to rebuild a browsing history of sites you visit through the VPN tunnel.

9. Usage Quota and Aggregate Data

For Free accounts we measure aggregate bytes transferred (receive + transmit) on a UTC calendar-month basis to enforce the published monthly quota (currently 1 GB unless changed in product settings).

Counters are derived from WireGuard transfer totals reported by nodes. We store per-report deltas, monthly aggregates, and lifetime totals tied to your account. Premium accounts are treated as unlimited under current product rules.

These aggregates do not include destination hosts or DNS names.

10. Advertising and Consent

HarmanVPN Premium does not request or show ads.

HarmanVPN Free may show interstitial ads when our remote configuration enables advertising, you are authenticated, and applicable privacy/consent requirements are met. The mobile client integrates the Google Mobile Ads SDK and Google User Messaging Platform (UMP) for consent where required.

When ads run, Google may process data such as IP address (which can be used to estimate approximate location), advertising/device identifiers, ad interaction events, and diagnostic information, as described in Google’s disclosures for the Google Mobile Ads SDK. Personalisation depends on consent and Google/account/device settings.

Production advertising may remain disabled by configuration even though the SDK is present. Debug builds may use Google’s sample ad units for testing.

We do not sell personal data.

11. Local Storage and Secure Storage

The app stores an authentication token and preferences (such as selected location and language) in platform secure/encrypted storage, plus optional local ad-frequency counters and notification permission flags.

Google’s advertising/consent SDK may store its own state on the device outside HarmanVPN-controlled keys.

Logging out clears the auth token and disconnects VPN sessions on a best-effort basis; it does not by itself erase WireGuard keys or all local preferences. Account deletion removes the server-side account and instructs the app to clear the local session.

12. How We Use Information

We use personal data to: create and secure accounts; authenticate API and VPN access; enforce entitlements and Free quotas; operate WireGuard peers; send transactional email (verification, password reset, security notices); deliver optional push notifications; prevent abuse; comply with law; and improve reliability.

13. Legal Bases

Depending on the context and applicable UK/EU data protection law, we rely on: performance of a contract (providing the VPN service you request); legitimate interests (security, fraud prevention, service integrity, limited operational logging); consent (where required for certain advertising/consent frameworks or optional notifications); and legal obligation where applicable.

You may withdraw consent where processing is consent-based, without affecting the lawfulness of processing before withdrawal.

14. Service Providers and International Transfers

We use processors/sub-processors such as: email delivery infrastructure (configured SMTP or equivalent), Google Firebase Cloud Messaging for push, Google (AdMob/UMP/Mobile Ads) when Free ads are active, and hosting/VPS providers that operate our control plane and VPN nodes.

Data may be processed in the United Kingdom, European Economic Area, and other countries where our providers or VPN nodes are located. Where required, we use appropriate transfer safeguards.

In-app purchases / store billing are not active in the current product; store identifiers may exist in catalog configuration for future use but are not an active payment processor today.

15. Data Retention

Account profile data is retained until you delete the account (or we close it for policy/legal reasons).

Password-reset and email-verification tokens expire automatically (typically within about 60 minutes).

Device records that are revoked or stale may be purged by scheduled jobs (inactive/stale windows are measured in tens of days as configured operationally).

VPN usage aggregates and peer-binding history associated with your user id are deleted when the account is hard-deleted.

Login/security events and support tickets may remain after account deletion with the user reference removed, for security, dispute, and abuse-prevention purposes. Automated purge schedules for those residual records are not fully published yet; we do not retain them to reconstruct VPN destinations or browsing content.

Operational backups and infrastructure logs are retained only as long as needed for resilience and security, then overwritten or deleted according to hosting practice.

16. Security

We use TLS for API traffic, hashed passwords, encrypted storage for certain secrets (such as FCM tokens and admin MFA material), short-lived VPN access tokens, and platform secure storage for on-device keys.

No method of transmission or storage is perfectly secure. Please protect your password and device.

17. User Rights

Subject to UK GDPR / applicable law, you may have rights to access, rectify, erase, restrict, object, and data portability, and the right to lodge a complaint with a supervisory authority (in the UK, the Information Commissioner’s Office).

To exercise rights, contact support@harmanvpn.com. We may need to verify your identity.

18. Account and Data Deletion

You can delete your account in the HarmanVPN app (My account → Delete my account) by re-entering your password and confirming. You can also open Settings → Delete account.

You can also request deletion on the web without installing the app: https://harmanvpn.com/account-deletion (also available under /tr/account-deletion and /en/account-deletion). Submitting the web form does not delete the account immediately; we send a time-limited confirmation link to the email address on the account. Responses are generic so we do not reveal whether an email is registered.

Deletion permanently removes the account and associated user data described above, subject to limited residual security records. Deactivation-only is not used as a substitute for deletion.

19. Children

HarmanVPN is not directed to children under 16 (or the higher digital-consent age in your country). We do not knowingly create accounts for children. If you believe a child has registered, contact support@harmanvpn.com and we will take appropriate steps.

20. Law Enforcement and Legal Requests

We may disclose information if required by law, regulation, court order, or to protect rights, safety, or integrity of the service. Because we do not intentionally retain VPN destination or DNS query logs, we typically cannot produce browsing histories that we do not have.

21. Changes to this Policy

We will publish updates on this page and adjust the last-updated date. Material changes may also be highlighted in the app or by email where appropriate.

22. Contact

HARMANPLUS TECHNOLOGIES LTD

United Kingdom

General and developer contact: developer@harmanplus.com

Privacy, data rights and support requests: support@harmanvpn.com