Meridian VPN Privacy Policy
Effective date: September 15, 2026.
1. General provisions
This Privacy Policy (the "Policy") governs the collection, use, and
protection of information a user provides while using the Meridian VPN
service (the "Service"): the Android app (package
org.meridianvpn.app), the iOS app, the router client and
control panel, and — in the future — desktop apps, along with the servers
associated with all of them.
By using the Service, the user confirms their agreement with the terms of the Policy. If the user does not agree with these terms, they must stop using the Service.
The general principles are the same across all platforms. Individual
points below describe technical details specific to a given platform (for
example, the ANDROID_ID identifier in section 2.1 only exists
in the Android app) — this does not mean the rules differ on other
platforms, they simply use their own equivalent of the same mechanism.
We aim to collect as little as possible. Below is everything that is collected — and, separately, what we do not do. In particular, Meridian VPN does not record or store: which sites you visit, which apps send traffic through the tunnel, the content of transmitted data, search queries, browsing history, or DNS requests. Traffic passes through our servers encrypted and is not saved.
2. Information we collect
The Service may collect the following types of data: device identifiers and the access key, technical information (IP address, device details), and connection details. The detailed breakdown for each item is below. The Service does not require passport data, documents, photos, or other personal information from the user beyond the minimum necessary for operation.
2.1 Device identifier
The app uses the Android device identifier (ANDROID_ID). If
the system does not provide one, the app generates its own random
identifier.
Why: a single access key works on a single device. The identifier lets us distinguish your device from someone else's and prevents a single paid key from being used on an unlimited number of phones.
It is also used to track the trial period, so the free trial days cannot be claimed again. For this purpose, the server stores not the identifier itself but an irreversible cryptographic transformation of it.
The identifier is not linked to your name, phone number, email, or Google account. It is not used for advertising and is not shared with third parties.
2.2 Access key
The access key is your connection password. It is stored on your device and sent to our servers when connecting and when checking your subscription.
2.3 Connection details
For every connection, our server logs:
- the IP address the connection was made from;
- the device identifier;
- the internal address assigned to you inside the tunnel;
- the session start and end time, and the amount of data transferred.
The access key itself is not logged — only a shortened representation of it, from which the key cannot be reconstructed.
This information is needed to operate the connection, fight abuse, and diagnose issues. It is not linked to the content of your traffic, since we do not store that content at all.
2.4 Subscription data
If a subscription is purchased through Google Play, the app sends our server the purchase token issued by Google — to confirm payment and issue the access key.
We do not receive your name, email address, payment details, or other personal data from Google. Payment processing is handled entirely by Google, in accordance with Google's Privacy Policy.
If the key was purchased through our Telegram bot, data processing there is governed by that messenger's own policy.
2.5 Data that stays on your device only
The following is stored locally and never transmitted:
- the app's event log (diagnostic connection records);
- video call links, if you added any;
- information about which connection method worked on your network;
- the list of apps selected for split tunneling;
- app settings.
You can send us the event log yourself by tapping "Share". This is a voluntary action; without it, the log never leaves your device. Before sending, we strip out any call links. The access key is never written to the log.
2.6 Google backup
If Google backup is enabled on your device, the backup includes the access key and the trial-period marker — so access is restored without re-entering anything after a reinstall or a move to a new phone.
The event log, call links, and other app data are not included in the backup.
Backups are stored on Google's servers and are governed by Google's policy. You can disable backup in your device settings.
3. How we use information
The Service may use the information it receives solely to: operate its functionality (connecting, checking subscriptions, fighting abuse, and diagnosing issues); communicate with the user (including notifications and support); and analyze and improve the Service. In doing so, the Service:
- Does not show ads and does not embed ad networks.
- Does not use analytics: the app has no behavior-tracking systems, visitor counters, or statistics-collection services.
- Does not request contacts, location, camera, microphone, files, or call/message history.
- Does not require registration: the app needs no name, email address, or phone number to work.
4. Sharing information with third parties
The Administration does not share collected data with third parties for marketing or similar purposes, except:
- when required by law;
- when necessary to fulfill obligations to the user (for example, when working with payment systems — see 2.4);
- when the user has given their own consent to it.
5. App permissions
Below are the permissions for the Android app. iOS, routers, and future desktop apps have their own permission models, dictated by their operating systems, but the purpose is the same: making the VPN work, and nothing beyond that.
| Permission | Why |
|---|---|
| VPN service | the core function — creating a secure connection |
| Network state access | detect a network change to restore the connection |
| Notifications | the mandatory notice that the VPN is running, and expiry reminders |
| Run on boot | restore scheduled reminders after a reboot |
| View installed apps | show the list for split tunneling |
The list of installed apps is used only to display the split-tunneling screen and is never transmitted anywhere.
6. Data storage and protection
Data is stored for as long as needed to achieve the purposes of processing (retention periods for each data type are below). The Administration takes reasonable measures to protect data but does not guarantee absolute security of information transmitted over the internet.
- Connection logs (connection address, session time, device identifier) — no more than 30 days.
- Web server logs (request address, time, requested file) — 14 days.
- Trial-period marker — 90 days after it ends.
- Key and its device binding — for as long as the subscription is active.
- Record of an expired key — 180 days. It contains only an irreversible fingerprint of the key, the expiry date, and the reason — not the key itself, the device, or any information about the person. The record is deleted after 180 days.
- Data on the device — until the app is uninstalled or the data is cleared manually.
Logs are kept only on our own servers and are not shared with external collection or analytics systems.
The working key database is backed up on the same server; the backups contain the same data as the database itself and are replaced as it is updated.
7. Disclaimer
The user understands and agrees that transmitting information over the internet always carries risk. The Administration is not liable for the loss, theft, or disclosure of data if it occurred through the fault of a third party (for example, a compromised user device) or of the user themselves (for example, sharing the access key with third parties).
8. Your rights
You may:
- delete your data — delete the app and write to us so we can delete the key and the records associated with it on the server;
- unbind a device — contact us, or use the Telegram bot if the key was purchased there;
- request information about what data is stored about you;
- opt out of backups — in your device settings.
9. Children
The app is not intended for children under 13 and does not knowingly collect data about them.
10. Changes to the Policy
The Administration may amend the terms of the Policy. For material changes, we will update the date at the top of the document. Continued use of the Service after changes are made constitutes the user's agreement with the new version.
11. Contact us
For privacy questions and data-deletion requests:
Email: support@meridianvpn.org