Privacy Policy
This policy is also available in German. Both versions describe the same processing.
This policy describes which personal data is processed when you use the website
autovpn.app and the macOS app AutoVPN, for which purpose, on which legal
basis, and for how long. It follows Articles 13 and 14 of the General Data
Protection Regulation (GDPR).
1. Controller
The controller within the meaning of the GDPR is:
Aaron Alexander Gladun · Sandstein Pixel
Grundstraße 4e, 01847 Lohmen, Germany
Email: info@sandstein-pixel.de
There is no statutory obligation to appoint a data protection officer.
2. The essentials up front
AutoVPN is a VPN client that you operate with your own WireGuard configuration and your own VPN server. This leads to the central point of this policy:
Your VPN traffic never passes through us at any point. We operate no VPN servers, see no connection destinations, log no traffic, and are technically unable to inspect it. The connection exists solely between your Mac and the VPN server you configured yourself.
The app contains no analytics, tracking or advertising components and no telemetry. No user account is required. Your WireGuard configuration, your network whitelist and your settings never leave your Mac.
Personal data therefore arises only at a few clearly defined points: when visiting the website, when making a purchase, when your licence key is delivered and activated, when checking for updates, and when you contact us. Each of these is described individually below.
3. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and a right to object to processing based on a legitimate interest (Art. 21). Where processing is based on your consent, you may withdraw it at any time with effect for the future; this does not affect the lawfulness of processing carried out beforehand.
An informal message to the address above is sufficient to exercise your rights. Please note section 9 regarding the deletion of licence data: your licence key remains technically valid even after your contact details have been deleted, which is why we must retain an anonymised revocation record.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Die Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17, 01067 Dresden, Germany
(Postfach 11 01 32, 01330 Dresden)
Part A — The website
4. Hosting and server log files
The website is a purely static site. It is served from a server that we administer ourselves and rent from ph24 / ProHosting24 (proprietor Nicolas Janzen, Hanauer Landstraße 328–330, 60314 Frankfurt am Main, Germany). The server is located in Germany. The provider supplies the data centre, hardware and network connectivity and, in that capacity, has theoretical access to the systems.
When the website is accessed, technically necessary access data is recorded in server log files:
- IP address of the requesting device
- date and time of access
- URL requested and volume of data transferred
- referrer URL (the previously visited page, where transmitted)
- browser type and operating system (user agent)
- HTTP status code
This data is technically unavoidable when operating a website. It serves to deliver the page, maintain stability and prevent abuse. It is not combined with other data sources, and we do not evaluate the log files for analytics purposes.
- Legal basis: Art. 6(1)(f) GDPR. The legitimate interest is the secure, stable and abuse-free provision of the website.
- Retention: Log files are deleted automatically after no more than 14 days. Excepted are entries required to investigate a specific incident of abuse or attack; these are retained until the matter is resolved.
5. Cloudflare (reverse proxy, DNS and TLS)
Cloudflare is placed in front of the website as a reverse proxy. Cloudflare
manages the autovpn.app domain (DNS), provides TLS encryption and protects the
site against bot and DDoS attacks. Every request to the website therefore passes
through Cloudflare first, which in doing so processes in particular your IP
address and the remaining connection data.
The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA.
- Legal basis: Art. 6(1)(f) GDPR. The legitimate interest is availability, attack mitigation and transport-encrypted delivery.
- Transfers to third countries: see section 15.
- Further information: Cloudflare’s privacy policy.
6. No cookies, no tracking, no external content
The website sets no cookies. There is no audience measurement, no web analytics and no tracking — no analytics service is embedded.
Likewise, no content is loaded from third-party servers. Fonts, graphics, scripts and stylesheets reside entirely on our own server; in particular, no external font services (such as Google Fonts), no third-party CDNs, and no embedded videos, maps or social media elements are used. Simply viewing the website therefore establishes no connection to any third-party provider.
7. Local storage in your browser
The website stores two values in your browser’s local storage (localStorage):
| Key | Content | Purpose |
|---|---|---|
theme | light or dark | remembers the appearance you selected |
lang | de or en | remembers the language you selected |
Both values are set only when you actively use the appearance or language switcher. They contain no identifier by which you could be recognised, are not transmitted to us or to third parties, and remain solely in your browser. You can delete them at any time via your browser settings.
Because this storage serves exclusively to provide a setting you explicitly requested, it is permitted without consent under § 25(2) no. 2 TDDDG (the German Telecommunications Digital Services Data Protection Act); no consent banner is required for it. Insofar as personal data is processed in this context, the processing is based on Art. 6(1)(f) GDPR (legitimate interest in presenting the site correctly).
8. No forms, no user account
The website has no contact or registration form, no newsletter and no customer area. No input is collected from you.
Part B — Purchase, licence and app
9. Purchase and payment processing (Stripe as merchant of record)
AutoVPN is sold through Stripe as merchant of record (MoR). Stripe acts as reseller and legal seller: Stripe processes the payment, issues your invoice and remits the applicable VAT. To that extent, the purchase contract for the software is concluded with Stripe.
Processing by Stripe. During checkout you enter your data directly with Stripe. Stripe processes in particular your name, email address, payment and billing details and billing address, and applies its own fraud-prevention measures. Stripe is the controller in its own right for this processing. Stripe’s privacy policy applies. Which Stripe entity is responsible in a given case depends on your place of residence; for customers in the European Economic Area this is generally the Irish Stripe entity.
What we receive. After a successful purchase we receive from Stripe only the details required to issue and administer your licence:
- your name and email address
- transaction identifiers (checkout session, payment intent, customer identifier, and whether the transaction was a test or a live one)
- your billing country as a two-letter country code
We never receive complete payment details — in particular no card numbers, bank details or security features.
- Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the licence) and Art. 6(1)(c) GDPR for compliance with tax and commercial law obligations.
- Transfers to third countries: see section 15.
10. Delivery of the licence key by email
After purchase, a service operated by us automatically generates your licence key and sends it to the email address you provided to Stripe. The service is triggered only by a cryptographically signed and verified notification from Stripe.
To send these transactional emails we use ZeptoMail from Zoho Corporation
B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands. Delivery runs over Zoho’s
EU infrastructure (api.zeptomail.eu). Your email address, your name and the
content and delivery status of the message are processed.
- Legal basis: Art. 6(1)(b) GDPR (delivery of the licence you purchased).
- Processing agreement: A data processing agreement pursuant to Art. 28 GDPR is in place with Zoho. Insofar as transfers to third countries take place within the Zoho group, these are safeguarded by the European Commission’s standard contractual clauses.
Note on the licence key: Your licence key is a cryptographically signed record that contains your name and email address. This is necessary so the key can be attributed to you and verified offline for authenticity. Please keep it like a personal document and do not pass it on.
11. Licence administration and device activation
A licence entitles you to use the software on one Mac. To enforce this, and to
be able to revoke lost, misused or refunded keys in support cases, we operate an
activation service at hook.autovpn.app.
11.1 What is transmitted
When you activate your licence, and when the app later renews its entitlement, the app transmits to this service:
- your licence key (which, as described in section 10, contains your name and email address)
- a pseudonymous device value — a SHA-256 hash computed from your Mac’s hardware identifier and a fixed, app-specific additional value. The hardware identifier itself is not transmitted and cannot be reconstructed from the hash.
- the app’s version number
For technical reasons the service is also aware of your IP address, since it is reachable via Cloudflare. From it we derive and store only the two-letter country code; we do not store the IP address itself.
Not transmitted: your WireGuard configuration, your VPN credentials, your network whitelist, Wi-Fi names, visited destinations, or any part of your traffic.
11.2 How often this happens
After successful activation the app receives a time-limited, signed confirmation (a “lease”) valid for 14 days, which it verifies offline. The app connects to the activation service only when this confirmation approaches expiry — in practice about once a week. If your Mac is offline at that moment, a grace period applies; the app does not lock itself immediately.
During the 14-day trial there is no contact with the activation service at all. Only an entered licence key triggers an activation.
11.3 What is stored
The data is held in a database (Cloudflare D1) that is explicitly pinned to the EU region. The following is stored:
-
for the licence: identifier, name, email address, country code, the Stripe transaction identifiers, date of issue, number of permitted devices, status (active/revoked) and, where applicable, a revocation reason and internal support notes
-
for the activation: the pseudonymous device value, its status, the app version, the time of activation, the last online contact and, where applicable, the time of release
-
for the history: events of the type purchase, activation, renewal, release or denial, each with a timestamp, country code and app version
-
Legal basis: Art. 6(1)(b) GDPR insofar as the processing serves performance of the licence agreement and support; additionally Art. 6(1)(f) GDPR with the legitimate interest of enforcing the agreed single-device use and preventing unauthorised sharing.
11.4 Changing devices and deletion
You can release the activation in the app at any time and thereby transfer your licence to another Mac. The previous device value is then marked as released.
On request we will anonymise your licence record: name and email address are irreversibly removed. For technical reasons, however, we cannot delete the record entirely — your licence key is signed offline and would otherwise remain activatable. An anonymised entry therefore remains which contains only the licence identifier and the revocation record and no longer relates to an identifiable person. Please note that anonymisation renders your licence permanently unusable.
12. The app on your Mac
Local storage. Your WireGuard configuration including its private key, your licence key, the activation confirmation and the start date of the trial are stored in the macOS keychain. Your network whitelist and all other settings remain local to your Mac. This data is not transmitted to us.
No logging of VPN traffic. As described in section 2, we process no connection or content data from your VPN tunnel whatsoever.
Network detection. To decide whether the VPN should be established, the app evaluates characteristics of the currently connected network (such as the Wi-Fi name). This evaluation takes place exclusively locally on your Mac; the characteristics are not transmitted.
Public IP address lookup. When you view the connection details in the app,
AutoVPN retrieves your public IP address via ipv4.icanhazip.com or
ipv6.icanhazip.com in order to display it to you. This service is operated by
Cloudflare; for technical reasons your IP address is transmitted to Cloudflare in
the process. We do not store the result.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a comprehensible display of the connection state). The lookup occurs only when you open the connection details.
No telemetry. The app contains no analytics, tracking or advertising components and transmits no usage statistics.
13. Automatic updates
By default AutoVPN checks once a day whether a new version is available. To do
so the app retrieves the file updates.autovpn.app/appcast.xml; the update itself
is then downloaded from github.com. Both are provided by GitHub, Inc. (a
Microsoft group company), 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107,
USA.
During this request your IP address and connection characteristics (such as the address requested and the time) are transmitted to GitHub for technical reasons. No user profile, identifier or information about your hardware is transmitted — the corresponding feature of the update framework used (Sparkle) is deliberately disabled. We ourselves receive no personal data from this process; only aggregated download counts are available to us.
You can disable the automatic update check in the app’s settings at any time.
- Legal basis: Art. 6(1)(f) GDPR. The legitimate interest is delivering security and bug fixes for software that intervenes closely in the system’s network configuration.
- Transfers to third countries: see section 15.
14. Contact and support
If you write to us by email — for example to [email protected] — we process your
details in order to handle your enquiry. Our email server is operated by us and
located in Germany; no external mail provider is involved in receiving it.
In connection with a support enquiry we may store an internal note on your licence record (see section 11.3) to keep the matter traceable.
- Legal basis: Art. 6(1)(b) GDPR where your enquiry serves the performance of the contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
- Retention: We delete the correspondence once it is no longer required and no statutory retention obligations apply.
Part C — General
15. Recipients and transfers to third countries
We disclose personal data only to the entities named below. We do not sell data, and no data is passed on for advertising purposes.
| Recipient | Role | Location of processing |
|---|---|---|
| ph24 / ProHosting24 | Data centre and server for website and email | Germany |
| Cloudflare, Inc. | Reverse proxy, DNS, TLS, licence database, IP lookup service | USA; licence database pinned to the EU region |
| Stripe | Merchant of record, payment processing, invoicing | EEA and USA |
| Zoho Corporation B.V. (ZeptoMail) | Sending transactional emails | Netherlands (EU infrastructure) |
| GitHub, Inc. (Microsoft) | Providing the update file and the program file | USA |
Transfers to the USA. Cloudflare, Stripe and GitHub/Microsoft are US companies; processing in the USA may therefore take place. Under the EU-U.S. Data Privacy Framework (DPF) the European Commission has determined that certified US companies provide an adequate level of data protection (adequacy decision of 10 July 2023). That determination is currently valid; the General Court of the European Union confirmed it in its judgment of 3 September 2025 (Case T-553/23, Latombe v Commission). An appeal against that judgment is pending before the Court of Justice of the European Union (C-703/25 P).
According to their own statements, the providers named hold a DPF certification and additionally rely on the European Commission’s standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Despite these safeguards, access to transmitted data by US authorities cannot be entirely ruled out.
16. Retention periods at a glance
| Data | Retention |
|---|---|
| Website server log files | 14 days |
Local browser settings (theme, lang) | until you delete them in your browser |
| Licence record (name, email, country) | for the duration of the licence — which is perpetual, so that your key remains activatable and we can reach you in support cases |
| Activations and event history | for the duration of the licence; anonymised thereafter |
| Support correspondence | until the matter is resolved, unless a retention obligation applies |
| Purchase-related records | where statutory retention obligations apply: eight years for accounting documents and invoices (§ 147(1) no. 4 AO, § 257(1) no. 4 HGB); such data is blocked from other uses |
You may request anonymisation of your licence record at any time; the details and the technical limitation are described in section 11.4.
17. No automated decision-making, no profiling
There is no automated decision-making within the meaning of Art. 22 GDPR. We do not create usage profiles and do not combine the data described above into a profile.
The only automated check is whether a licence is active and whether the permitted number of devices has already been reached (section 11). This check has no legal effect beyond whether the software starts on the device in question, and you can contact us at any time if the outcome does not match your expectations.
18. Obligation to provide data
Providing your name and email address is necessary for the purchase and delivery of the licence. Without these details we cannot issue and send you a licence key. Beyond that, you are under no statutory or contractual obligation to provide personal data; you can use the trial without providing any details at all.
19. Data security
All connections to the website and to our services are encrypted with TLS. Access to our licence administration is restricted to authorised persons and additionally secured by an upstream access control. We apply technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, alteration and unauthorised access, and adapt these on an ongoing basis to the state of the art.
20. Changes to this privacy policy
We update this policy when the processing described here or the legal situation
changes. The version currently published at autovpn.app applies.
Last updated: 24 August 2026