Veil VPN Privacy Policy
Effective date: 21 September 2026
Last updated: 21 September 2026
This policy covers the Veil VPN app only. Veil's other products have their own policies. It is written from what the Veil VPN app and its servers actually do today, and it says plainly what we have not yet verified.
The short version
Veil VPN links a random Veil ID and your device to the server you connect through, and records when you connect, how the connection is performing, and how much data you use each month. It does not record the sites you visit, your DNS lookups or page content. We have not yet independently verified how long our server and infrastructure logs are kept.
1. Who we are
Veil VPN is made by Veil Technologies Limited, a company registered in England and Wales.
- Company number: 17342128
- Registered office: 64 Kingsway, Coventry, CV2 4FE, United Kingdom
- ICO registration number: ZC206131
- Contact for privacy questions: support@veilsuperapp.com
Veil Technologies Limited is the "data controller" for the personal data described in this policy.
2. What Veil VPN collects
You do not create an account
There is no sign-up, email address, phone number, username or password. On first use the app creates a random Veil ID on your device and keeps it in your device's Keychain. Veil does not require you to provide your real-world identity. A Veil ID is generated randomly and is not, by itself, a real-world identifier.
What the VPN records
- Who and where: your Veil ID and device identifier, the server region you were assigned, the internal tunnel address assigned to your device, and when you were last connected.
- Your device's public key. The matching private key is created and kept only on your device and is never sent to Veil.
- Connection health: whether the tunnel is working, how recently it exchanged data, how long connecting took, and any error code.
- Data usage: the total data sent and received each month, counted against your device's key.
- Connection requests: each time the app asks to connect, it sends a random connection-request identifier. When a request is made or refused, Veil's provisioning service writes the request's identifiers to its logs: your Veil ID, your device identifier, the server chosen (and any server that previously failed), and the connection-request identifier.
- Invitation check: access is currently by invitation. Your Veil ID is checked against an invitation list, or against a time-limited open-access window that we open and close ourselves. During a time-limited window we may also record the device's User-Agent text.
What the VPN does not record
In Veil's VPN database we do not record the websites you visit, the services you connect to, your DNS lookups, the content of pages, or any history of your traffic. Your traffic is encrypted between your device and the VPN server using the WireGuard protocol. The server has to decrypt it to pass it on to the internet, so, as with any VPN, the server can technically see where your traffic is going while it is connected; we do not record that in our VPN database.
What we have not yet verified
- How long our infrastructure and server logs are kept, and whether the VPN servers themselves write connection logs. We have not independently audited this, so we do not claim either way.
- As with any VPN, the server you connect through can see the network address your connection comes from while you are connected.
Why we're allowed to: necessary to provide the VPN service you have chosen to use (UK GDPR Article 6(1)(b), contract).
3. What we never do
- We do not use advertising, ad trackers or third-party analytics SDKs in Veil VPN.
- We do not sell, rent or trade personal data.
- We do not build profiles of you or make automated decisions about you.
- We do not ask for access to your contacts, photos, location or microphone. The only permission the app needs is iOS's own VPN configuration prompt, and local network access as part of establishing the connection.
4. Who we share data with
- Infrastructure providers. Our VPN servers run on Vultr and our provisioning service runs on Cloudflare. They host the data described above on our behalf. Vultr's data processing addendum with Veil Technologies Limited was signed on 18 August 2026, and Cloudflare's standing data processing addendum applies to our use of its platform.
- Apple. The app is distributed through Apple's TestFlight and App Store, under Apple's own privacy terms.
Nobody else. If we receive a legally binding order from a court or authority with jurisdiction over us, we can only hand over what we actually hold, which is the records listed in section 2.
5. How long we keep data
We keep the records in section 2 while your device registration exists. We do not currently delete them automatically, and we have not yet verified how long infrastructure and server logs are kept (see above). You can ask us to delete the records tied to your Veil ID at any time by emailing support@veilsuperapp.com. When our retention practice is verified or changed, this section will say so before the change takes effect.
6. Your rights
Under UK GDPR you have the right to access, correct or delete your data, to restrict or object to processing, and to data portability. To exercise any of these, email support@veilsuperapp.com. We will respond within one month and will not charge you. Because we hold no name or email address for you, we may ask you to confirm your Veil ID from within the app. You may also complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).
7. Children
Veil VPN is not intended for children under 16.
8. Changes to this policy
If we change this policy we will update the date at the top and, for meaningful changes, tell you in the app before they take effect.
9. Contact
Questions, concerns, requests: support@veilsuperapp.com
Post: Veil Technologies Limited, 64 Kingsway, Coventry, CV2 4FE, United Kingdom