Privacy Policy
What UCN VPN collects, why we collect it, what we deliberately do not collect, who else sees it, how long we keep it, and the control you have over all of it.
Last updated Aug 29, 2026
Who We Are
The company behind UCN VPN, and how to reach us about privacy.
UCN VPN is a consumer virtual private network service operated by UCNHUB LLC, a limited liability company formed under the laws of the State of Delaware, United States. Where this policy says “we”, “us”, or “UCN VPN”, it means UCNHUB LLC.
For the personal data described in this policy, UCNHUB LLC is the entity that decides why and how the data is processed. Because of how the service is built, that data is far smaller than most companies collect — see What We Do Not Log.
- Legal entity
- UCNHUB LLC
- Entity type
- Delaware limited liability company
- File number
- 10710550
- Registered office
- 254 Chapman Rd, Suite 101-B
Newark, DE 19702, United States - Privacy contact
- contact@ucnvpn.com
- Support
- ucnvpn.com/contact-us
Scope of This Policy
What this policy covers, and what it does not.
This Privacy Policy applies to the UCN VPN platform: the ucnvpn.com website, the customer dashboard, the UCN VPN applications and browser extensions, and the VPN servers and DNS resolvers we operate.
It describes how we handle personal data about you as our customer or as a visitor to our website. It also describes how we treat the traffic you route through the tunnel, which is handled differently — see Your Traffic.
What this policy does not cover
The websites and services you reach through the tunnel, each of which has its own privacy policy and can still identify you by what you do there; your internet service provider; the app store you install from; and any third-party VPN client you choose to point at our servers. Once your traffic leaves our exit server for its destination, that destination handles it under its own policies.
A VPN is not anonymity
We can hide the origin of your connection. We cannot hide what you choose to reveal at the other end. Signing in to an account, accepting cookies, or being fingerprinted by a browser identifies you regardless of which IP address the request arrives from. Treat UCN VPN as protecting the connection, not your identity.
Your Traffic
The thing this service exists to not look at.
Running a VPN means carrying packets. Your traffic passes through our servers because that is the entire mechanism — there is no way to route a connection without handling it in memory as it goes by.
What we do not do is record any of it. Packets are forwarded and discarded. We do not write your destinations, your DNS queries, or your payloads to disk, we do not inspect their contents, we do not sell or share them, and we do not train anything on them.
Servers that run from RAM
Our VPN servers run from volatile memory with no persistent storage for operational data. There is no disk holding a history of who connected or where they went, and a reboot wipes the machine's state entirely. This is a design decision that removes the possibility of a log rather than a promise to delete one.
Shared IP addresses
Many customers share each exit IP address at the same time. This is deliberate: it means an observed connection cannot be attributed to one subscriber by address alone, because at any moment that address represents a crowd rather than a person.
DNS inside the tunnel
Your lookups resolve on our own resolvers, inside the encrypted tunnel, rather than at your ISP in the clear. Queries are answered and discarded; we do not build a record of the domains you resolve. Our ad and tracker blocking works by refusing to answer for domains on a blocklist, which requires no record of who asked.
Staff access
Our staff cannot read your traffic, because it is not retained anywhere for them to read. Access to production systems is limited to the engineers whose role requires it, for the purpose of keeping the network running.
What We Do Not Log
The specific list, so there is no ambiguity.
UCN VPN does not record any of the following, at any time, for any user:
- Your originating IP address, once a session is established
- The VPN IP address assigned to you
- The websites, services, or hosts you connect to
- The DNS queries you make
- Connection timestamps, session start and end times, or session durations
- Bandwidth or data volume attributable to an individual user
- Any traffic contents, metadata, or payloads
- Which server or country an individual account connected to
Note
Because these records are never created, we cannot produce them — for you, for a court, or for anyone else. A request for your browsing history can only be answered one way: we do not have it. See Government and Legal Requests.
Important
This is a statement about what we store, not a guarantee about what is observable elsewhere. Your ISP can still see that you are connected to a VPN, and the sites you visit can still identify you by what you do on them.
Information We Collect
Everything we do hold, and where it comes from.
We collect only what the service needs to run. Most of it comes directly from you; some is generated automatically when you use our website or dashboard.
Account information
Your email address and a password stored only as a salted cryptographic hash. We never hold your password in a readable form and cannot recover it for you — we can only reset it. If you sign in with Google, we receive your email address and basic profile details from Google instead of a password.
Subscription and billing information
Your plan, billing period, renewal date, invoice history, amounts charged, and the payment-method token, card brand, and last four digits returned to us by Stripe. Full card numbers, expiry dates, and security codes go directly to Stripe and never reach our servers.
Free tier usage counters
For accounts using Free Access we hold the remaining time in the current day's allowance and the time earned from watching advertisements. This is a running counter, reset daily. It records how much time is left, not where or how it was spent.
Support and contact form data
When you write to us through the contact form or by email, we receive your name, email address, subject, and message, along with anything you choose to include. We keep the correspondence so we can follow up and so we have a record of what was asked and answered.
Website and dashboard technical data
IP address, browser and device type, operating system, referring page, and timestamps for requests to ucnvpn.com and the dashboard, plus authentication events such as sign-in, sign-out, password change, and failed sign-in attempts. This is ordinary web server and account security data about our website. It is entirely separate from the VPN tunnel and tells us nothing about your browsing through it.
App diagnostics
If an App crashes, it may report the crash and basic device and version information so we can fix the fault. Diagnostic reports do not contain your browsing activity or the contents of your tunnel.
Analytics data
If you allow analytics cookies, we collect aggregate usage measurements about the pages you visit on our public website. See Cookies, Tag Manager, and Analytics for exactly what runs and when.
Note
We do not buy personal data from data brokers, we do not build advertising profiles from your account, and we do not enrich your account with information bought from third parties.
Advertising on the Free Tier
The one place a third party sees anything.
Free Access gives you one hour of protected time per day. On Android and iOS, you can choose to watch an advertisement to add more time to that day. Watching is optional and is the only advertising anywhere in UCN VPN.
To serve and measure those advertisements, our advertising providers may process device and advertising identifiers, coarse device and network information, and whether an advertisement was shown and completed. They act under their own privacy policies for that data.
- Advertisements are rendered inside the App. We do not inject advertising into, or otherwise modify, the traffic in your tunnel
- Advertising providers do not receive your browsing activity, your VPN destinations, your DNS queries, or the contents of your tunnel — none of which exist in a form we could pass on
- Your device's ad-personalisation control applies here: Opt out of Ads Personalisation on Android, and Allow Apps to Request to Track on iOS
- A paid Subscription removes advertising entirely, and with it this category of processing
Note
This is the single exception to “nothing about you reaches a third party”, and we would rather name it plainly than let the no-logs claim imply more than it delivers. It is confined to advertising inside the mobile App, and it stops the moment you subscribe or stop watching ads.
How We Use Information
Every purpose we process data for.
We use the information described above for the following purposes, and no others:
- Providing the service — creating and authenticating your account, enforcing the device limit and the free daily allowance, and giving your devices access to the network.
- Billing — charging your subscription, issuing invoices, handling failed payments, and keeping the financial records the law requires us to keep.
- Support — answering your questions, investigating problems you report, and following up on them.
- Security and abuse prevention — detecting credential stuffing, account takeover, payment fraud, and abuse of the free allowance, and protecting the network and its shared IP addresses.
- Network operation — monitoring aggregate server load and capacity so we can keep the network fast and decide where to add servers. These measurements are aggregate and not attributable to an account.
- Service communications — sending you account, billing, security, and outage notices. These are not marketing and you cannot opt out of them while you hold an account.
- Improving the product — understanding, in aggregate, which parts of the site and dashboard are used, so we know what to fix and build next.
- Legal compliance — meeting our tax, accounting, and regulatory obligations and responding to lawful requests.
Legal Bases for Processing
Why each use is lawful under the GDPR and UK GDPR.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we must have a lawful basis for each purpose. Ours are:
- Performance of a contract (Art. 6(1)(b)) — running your account, granting access to the network, enforcing plan limits, taking payment, and providing support. Without this data there is no service to provide.
- Legitimate interests (Art. 6(1)(f)) — securing accounts and the network, preventing fraud and abuse of the free allowance, and understanding aggregate product usage. Our interest is in operating a safe and reliable service; we have weighed it against your rights and limited what we collect accordingly.
- Consent (Art. 6(1)(a)) — analytics and marketing cookies, personalised advertising on the free mobile tier, and any optional marketing email. You give consent through the cookie banner, your device's advertising settings, or by opting in, and you can withdraw it at any time without affecting processing carried out before you did.
- Legal obligation (Art. 6(1)(c)) — retaining financial and tax records, and responding to valid legal process.
Google Tag Manager
How third-party tags are loaded, and how consent gates them.
We use Google Tag Manager (“GTM”), a tag management service provided by Google Ireland Limited, to load and control the measurement scripts that run on our public website. GTM is a container rather than a tracker: it sets no analytics or advertising cookies of its own and does not, by itself, collect personal data about you. What it does is decide which other tags load, and when.
Loading GTM involves a request to Google's servers, which necessarily discloses your IP address and browser details to Google as part of any web request. Google acts as a processor for the measurement data collected through our tags, under Google's data processing terms, and as an independent controller for its own operational purposes. Google's own practices are described in its Privacy Policy.
Consent comes first
Analytics and marketing tags stay switched off until you allow them. Your choice in our cookie banner is passed to Google using Google Consent Mode, which sets the analytics_storage, ad_storage, ad_user_data, and ad_personalization signals. Where a signal is denied, the corresponding tag either does not run or runs without storing or reading cookies.
What the analytics tag measures
Pages viewed and the order they were viewed in, approximate location derived from a truncated IP address, referring source, device and browser type, and rough session duration. It does not receive your name, your email address, your billing details, or anything at all about your VPN sessions.
Not in the apps
Tag Manager runs on our public marketing website. It is not loaded inside the UCN VPN applications, and no measurement tag has any visibility into a tunnel.
Blocking it entirely
You can block these tags at the browser level by rejecting third-party cookies, using a content blocker, or installing Google's Analytics opt-out add-on. Doing so has no effect on your ability to use UCN VPN.
Signing In With Google
What Google tells us, and what it does not.
You can create an account and sign in using Google. If you do, Google confirms your identity to us and passes us your email address and basic profile information. We use it to create or match your UCN VPN account and for nothing else.
We never receive your Google password, and signing in this way does not give us access to any other Google service. Google learns that you signed in to UCN VPN, in the same way it would for any site you use it on. You can disconnect UCN VPN in your Google account's security settings at any time; if you do, set a UCN VPN password first so you do not lock yourself out.
Payments
Card data goes to Stripe, not to us.
Payments are processed by Stripe, Inc. Your card details are entered into fields hosted by Stripe and transmitted directly to Stripe's PCI DSS Level 1 certified systems. We never see or store your full card number, expiry date, or security code.
What we receive back and store is a payment-method token, the card brand, the last four digits, and the outcome of each charge — enough to show you which card is on file, to charge it for your subscription, and to reconcile your invoices. Stripe processes your payment data as an independent controller for fraud prevention and its own legal obligations, under its Privacy Policy.
Note
Payment necessarily identifies you to your payment provider, and a subscription is linked to your account. If your threat model requires that no payment trail connect you to this service, pay with cryptocurrency rather than a card, or use the free tier.
International Transfers
Where your data is stored and processed.
UCNHUB LLC is established in the United States, and our infrastructure and service providers may process data in the United States and other countries. If you are in the EEA, the United Kingdom, or Switzerland, this means your personal data may be transferred outside the region in which you live, to countries whose data protection laws differ from your own.
Where such a transfer takes place, we rely on the European Commission's Standard Contractual Clauses, and the UK Addendum where applicable, together with the technical and organisational measures described in Security. You may request a copy of the relevant transfer safeguards by writing to us.
Connecting through a server in a particular country routes your traffic through that country, but does not move your account data there. Account and billing records live in our own systems regardless of which server you use.
How Long We Keep Things
Retention periods, category by category.
We keep personal data only for as long as we need it for the purpose it was collected for, or for as long as the law requires.
- Browsing, connection, and DNS records — never written, so there is nothing to retain or delete.
- Account records — for as long as your account is open, then deleted or anonymised within 90 days of closure, except where we must keep something longer.
- Billing and tax records — retained for the period required by applicable tax and accounting law, typically seven years, regardless of account closure.
- Free tier allowance counters — reset daily; no history of previous days is kept.
- Website and authentication logs — a rolling window sufficient to investigate incidents and detect abuse, after which they are deleted or aggregated.
- Support correspondence — retained while it remains useful for context and for the period in which a related dispute could arise.
- Crash and diagnostic reports — retained for a limited period while the fault is investigated.
- Analytics data — retained for the period configured in the analytics tool, and only ever in aggregate form.
Important
Closing your account is permanent. Because we hold no browsing or connection history, there is no usage record for us to export to you before you go — but your account, subscription, and billing history are removed on the schedule above.
Security
The measures protecting your account and your connection.
We apply technical and organisational measures appropriate to the risk of running a privacy service:
- ChaCha20-Poly1305 authenticated encryption on every packet in the tunnel, with Curve25519 key exchange.
- VPN servers running from RAM, with no persistent storage of operational data and full state loss on reboot.
- TLS encryption for connections to our website, dashboard, and API.
- Account passwords stored only as salted cryptographic hashes, never in a readable form.
- An automatic kill switch in the Apps, so traffic stops rather than leaking if the tunnel drops.
- DNS resolution confined to the tunnel, with leak protection, so lookups do not escape to your ISP.
- Least-privilege internal access controls, so staff can reach only the systems their role requires.
- Rate limiting and abuse detection on authentication endpoints.
Note
Security is shared work. Use a strong, unique password on your UCN VPN account, keep the Apps updated, and tell us straight away at contact@ucnvpn.com if you think an account has been compromised.
Important
No system is perfectly secure. A VPN protects traffic between your device and our exit server; beyond that point, protection depends on whether the destination uses HTTPS and on how it handles your data. A compromised device defeats a VPN entirely, because the traffic is captured before it ever enters the tunnel.
If Something Goes Wrong
How we handle a data breach.
If we become aware of a personal data breach that is likely to affect you, we will investigate it, contain it, and notify you without undue delay. Where the law requires it, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
Our notice will tell you what happened, what data was involved, what we have done about it, and what we recommend you do — in plain terms, not in a way designed to minimise it.
Your Rights
What you can ask us to do, and how.
Depending on where you live, you have some or all of the following rights over your personal data. We honour these requests for everyone, not only for people whose local law grants them.
- Access — ask what personal data we hold about you and receive a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete your account and its data, subject to records we are legally required to keep.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection — object to processing we carry out on the basis of legitimate interests, on grounds relating to your particular situation.
- Withdrawal of consent — change your cookie preferences, reset your device's advertising identifier, or unsubscribe from optional email at any time, without affecting processing that already took place.
- Freedom from discrimination — exercising any of these rights will never cost you service, price, or quality.
How to make a request
Write to contact@ucnvpn.com or use the contact form. We respond within 30 days, and will tell you if we need longer for a complex request. To protect your data we will verify that the request comes from the account holder before we act on it; we may ask you to confirm from the registered email address.
What an access request will return
Your account record, subscription and billing history, support correspondence, and any website or authentication logs still within their retention window. It will not contain browsing history, connection times, or destinations, because those are never recorded. A short response is a consequence of the design, not an incomplete answer.
Complaints
We would rather hear from you first, but you have the right to complain to your data protection supervisory authority — in the EEA, the authority in your country of residence or work; in the UK, the Information Commissioner's Office.
Government and Legal Requests
What happens when someone asks us for your data.
We review every request we receive for validity and scope. We require valid legal process, we refuse requests that are overbroad or defective, and we narrow what we produce to what the law actually compels.
What we are able to produce is limited to what exists: account details, subscription status, and billing records. We cannot produce browsing history, connection logs, DNS queries, timestamps, or the identity of the user behind a given exit IP address at a given moment, because none of it is recorded.
- Where we are legally permitted to notify you of a request before responding, we will, so that you have the opportunity to object
- We do not provide any authority with direct or unsupervised access to our servers
- We do not weaken, backdoor, or add logging to our infrastructure at the request of any third party
Note
UCNHUB LLC is a United States company and is subject to United States legal process. We are transparent about that rather than implying a jurisdiction places us beyond the reach of the law. Our protection is architectural: the records simply do not exist to be handed over.
United States Privacy Rights
California and other state privacy laws.
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information we collect and why, to access and delete it, to correct it, to limit the use of sensitive personal information, and to be free from discrimination for exercising those rights. Residents of other US states with comparable laws have equivalent rights, and we extend the same treatment to all of them.
The categories of personal information we collect, and the purposes we collect them for, are set out in Information We Collect and How We Use Information. The categories we disclose to service providers are set out in Sharing and Sub-processors.
Exercise these rights the same way as any other: write to contact@ucnvpn.com. You may use an authorised agent, in which case we will ask for proof of their authority.
Note
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have not done so in the preceding twelve months. Advertising on the free mobile tier is served in-app by our providers and is subject to your device's advertising controls.
Children
UCN VPN is not for children.
UCN VPN is intended for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 16, or under 13 in the United States.
If you believe a child has given us personal data, write to contact@ucnvpn.com and we will delete the account and its data.
Automated Decision-Making
Where machines decide, and where they do not.
We do not make decisions about you that produce legal or similarly significant effects using automated processing alone, and we do not carry out profiling of that kind.
Automated controls do exist: rate limits on sign-in attempts, fraud checks by our payment processor, abuse detection on shared exit addresses, and enforcement of the device and free-allowance limits. These act on requests and sessions rather than on your legal standing, and a person will review any decision that restricts your account if you ask us to.
Changes to This Policy
How we tell you when this page changes.
We may update this Privacy Policy as the service changes or the law does. When we do, we revise the “Last updated” date at the top of this page.
If a change materially affects how we handle your personal data — a new purpose, a new category of recipient, or a materially different retention period — we will tell you by email to your account address before it takes effect, so that you can review it and, if you disagree, close your account.
Contact Us
Privacy questions, requests, and complaints.
Write to us about anything in this policy, to exercise your rights, or to raise a concern. We read every message and we will tell you what we can and cannot do.
- Entity
- UCNHUB LLC
- Address
- 254 Chapman Rd, Suite 101-B
Newark, DE 19702, United States - contact@ucnvpn.com
- Support
- ucnvpn.com/contact-us
- Response time
- Within 30 days
Questions about this policy? We're happy to clarify anything.
Contact us