BTO VPN — Privacy Policy

Last updated: 10 September 2026

BTO VPN is a virtual private network app. This policy describes exactly what the app and its servers do and do not record. It is written to match the app's actual behaviour, not to be reassuring: every statement below corresponds to something in the running code.

No account, no identity

You do not create an account. There is no sign-up, no email address, no password, no phone number and no social login. On first launch the app asks our server for a random identifier (for example d_1a2b3c…) and an access token. That random identifier is the only thing that links your device to a session. We cannot connect it to your name, your email or your real-world identity, because we never receive any of those.

What we store

DataWhyKept for
Random device identifierTo attach a session and free-time quota to a deviceUntil you uninstall or we prune inactive devices
A hash of your access tokenTo authenticate your device's requests. The token itself is never storedSame as above
Session start time, expiry, chosen serverTo enforce the 15-minute free session and the 60-minute rewardSession history, for abuse prevention
Your device's WireGuard public key and the private tunnel address we assign (e.g. 10.7.0.5)Technically required to route your tunnel at allRemoved from the server when the session ends
Total bytes sent and received in a sessionCapacity planning and abuse detectionSession history
Advertisement transaction identifiers issued by GoogleSo one rewarded ad grants exactly one hour and cannot be replayedSession history
Subscription purchase token, product and expiry (paying users only)To confirm with Google Play that your subscription is activeWhile the subscription is active

What we do not store

An honest limitation

While a tunnel is up, the operating-system kernel on the VPN server necessarily knows the network address your device is currently connecting from, because that is how packets get back to you. This is held in memory for the life of the connection and is not written to a log or a database by us. We would rather state this plainly than claim a technical impossibility.

Advertising

The free tier uses Google AdMob rewarded video. Watching one advertisement extends your session to one hour. AdMob is operated by Google and may collect data under Google's Privacy Policy, including an advertising identifier. We receive from Google only a signed confirmation that a specific advertisement was genuinely watched — we do not receive any profile about you. Advertisement requests are deliberately sent outside the VPN tunnel so that they are not attributed to our server addresses. The paid tier shows no advertisements.

Payments

Subscriptions are sold and processed by Google Play. We never see or store your card details. We receive only the purchase token that lets us ask Google whether your subscription is active.

Legal requests

We keep the small amount of data listed above and nothing more, so that is the most that could ever be produced in response to a lawful request. We do not have browsing history to hand over, because we do not create it. Our hosting providers are subject to the laws of their own jurisdictions and may be compelled independently of us.

Children

BTO VPN is not directed at children under 13 and we do not knowingly collect data from them.

Your choices

Uninstalling the app ends the relationship: your device stops being able to authenticate, and its sessions expire. To have a device's records deleted sooner, contact us with the device identifier shown in the app's settings screen.

Changes

If this policy changes materially we will update the date at the top and surface a notice in the app before the change takes effect.

Contact

Email: privacy@btov.uk