Legal

Privacy Policy

Effective 30 July 2026 Β· Applies to the Wombat VPN apps for Android and iOS and to wombatvpn.com

The short version. Wombat VPN has no accounts, so we never learn who you are. We store exactly three things: your device's WireGuard public key with the tunnel IP address assigned to it, an anonymous subscription status tied to a random identifier, and traffic totals counted per server. We do not store your browsing history, your DNS queries, your IP address, or any record of when a particular device connected. We do not sell or share your data with anyone.

1. Who we are

Wombat VPN (β€œWombat VPN”, β€œwe”, β€œus”) provides a consumer VPN service for Android and iOS built on the WireGuard protocol. For questions about this policy or about your data, write to privacy@wombatvpn.com. We operate from the European Union, and the EU General Data Protection Regulation (GDPR) applies to our service.

This policy explains what our apps and our servers do with data. It is written to be read, not to be survived β€” if any part of it is unclear, ask us and we will fix the wording.

2. There is no account, so there is no identity

Wombat VPN never asks you to sign up. There is no username, no password, no email address, no phone number and no social login. You do not tell us your name, and we have no way to ask.

Instead, your device identifies itself with a WireGuard key pair that the app generates on the device itself. The private key stays in the device's own storage and never leaves it β€” we could not retrieve it if we wanted to. Only the public key is sent to our servers, which is what a WireGuard server needs in order to accept an encrypted tunnel from your device.

A public key is not a name. It is a random-looking string that lets a server recognise a tunnel. We do not attach any personal detail to it, and we have no directory that maps keys to people.

3. What we store β€” the complete list

These are all the things our backend holds. There is no fourth category.

a. Provisioning state: your device's public key and tunnel IP

To bring a tunnel up, a server needs your device's WireGuard public key and an internal IP address inside the tunnel to route your packets to. We store that pair β€” public key and assigned tunnel IP β€” for as long as the device is configured on a server. It is the minimum a WireGuard network can function with. When you disconnect and revoke the key (see section 7), the record is removed.

b. Anonymous subscription status

If you subscribe, we need to know whether a device is entitled to premium service. Purchases are handled by the app stores through RevenueCat, our subscription infrastructure provider, which identifies the purchase with a randomly generated application user identifier. We store that random identifier and the entitlement state attached to it β€” active or not, and until when. The identifier is not derived from your name, email, device serial number or advertising ID, and it is not something you chose.

c. Per-server traffic counters

To know when a server is filling up and when to add another one, we count bytes transferred per server, in aggregate. A counter that says β€œthis server moved 4.1 TB this month” is not a record about you. We deliberately do not keep per-user or per-device counters, and the way our metering is structured means there is no per-device figure to recover afterwards.

4. What we never store

None of the following exists anywhere in our systems:

  • Your browsing history. No list of websites, domains, apps or services you reach through the tunnel.
  • DNS query logs. We do not record the names your device looks up.
  • Per-user or per-device connection records.No β€œthis device connected at 21:04 and disconnected at 23:11” entries, for any device.
  • Your IP address. The IP address your device connects from is never written to persistent storage. Access logging is disabled at the server level for both our API and our website, so it is not quietly collected in a log file either.
  • Any identifying detail. No name, email address, phone number, postal address, date of birth, advertising identifier or device fingerprint.
  • Payment details. No card numbers, no billing names, no addresses. See section 5.
  • Analytics or tracking of your activity. Neither this website nor the app carries advertising trackers or third-party analytics profiling you.

The reason we can state this so flatly is structural, not a promise about good behaviour: our database has no columns for this data. There is no retention period to argue about for records that were never created.

5. Payments and subscriptions

When paid plans are available, all purchases happen inside Google Play or the Apple App Store, and subscription state reaches us through RevenueCat. This means:

  • Your card details, billing name and billing address are handled by the app store and its payment processor. They never reach Wombat VPN, in any form.
  • What we receive is purchase state β€” an active or inactive entitlement β€” attached to the random identifier described in section 3b.
  • Google, Apple and RevenueCat process data under their own privacy policies for their own purposes; that part of the chain is outside our control, and worth reading if you care about the detail.

6. Our servers and where your traffic goes

Our VPN servers currently run in Europe, and more regions are being added. Your traffic is encrypted between your device and the server you choose; from there it exits to the internet in the usual way. A VPN moves the point at which your traffic joins the public internet β€” it does not make you invisible to the websites you log into, and it is not a substitute for good habits elsewhere.

7. Disconnecting, revoking and deleting

You are in control of the only record that ties to your device. From the app you can disconnect and revoke the device's key at any time. Revocation removes the public key from our servers within seconds, and with it the provisioning record described in section 3a. Uninstalling the app destroys the private key that lived on your device.

Subscription state, being tied to a random identifier held by the app stores and RevenueCat, is managed through your app store subscription settings.

8. Legal bases under the GDPR

  • Performance of a contract(Art. 6(1)(b)) β€” storing your device's public key and tunnel IP, and knowing whether a subscription is active, is necessary to provide the service you asked for.
  • Legitimate interests (Art. 6(1)(f)) β€” aggregate, per-server traffic counters, used to keep the service fast and to plan capacity. Because these figures are not attributable to any individual, the impact on you is nil.

9. Your rights β€” and an honest note about them

Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, and to data portability. You also have the right to complain to your national data protection authority.

Here is the honest part: we cannot link data to a person, so most of these requests are already satisfied by design rather than by procedure. If you write and ask us what we hold about you, we cannot look you up β€” there is no name, email or account to search. What we can do is explain exactly what the system stores (this document), and you can exercise erasure yourself by revoking your device key in the app, which deletes the only record connected to your device. We would rather tell you this plainly than pretend to run a lookup we are not capable of.

For anything else, write to privacy@wombatvpn.com.

10. Sharing, selling and legal requests

We do not sell your data. We do not share it with advertisers, brokers or analytics networks β€” there is no meaningful dataset to sell even if we wanted to. The only third parties involved in running the service are the app stores and RevenueCat for subscriptions, and the hosting and network providers that operate our servers.

If we receive a lawful request from an authority, we comply with the law that applies to us. What we can produce is limited by what exists: there are no activity logs, no browsing records, no IP addresses and no timestamps identifying a user, because we never created them.

11. This website

wombatvpn.com is a static site. It sets no tracking cookies, embeds no third-party fonts, scripts or analytics, and its access logging is disabled at the server level. Reading this page tells us nothing about you.

12. Children

Wombat VPN is not directed at children, and we do not knowingly collect personal data from them β€” or, as it happens, from anyone. Purchases are subject to the app stores' own age and parental-control rules.

13. Changes to this policy

If we change how the service handles data, we will update this page and change the effective date at the top. Material changes β€” anything that broadens what we store β€” will be announced in the app before they take effect, and we will keep the previous version available on request. We will never quietly widen this policy and hope you do not notice; if a change is significant enough to matter, you deserve to hear about it before it applies.

14. Contact

privacy@wombatvpn.com β€” for privacy questions, GDPR requests, or to tell us a sentence on this page is vague.

← Back to home