Skip to content
4VPN
The appSupportDocuments
Русский

4VPN for Android

Privacy

Data processing in 4VPN for Android: connections, diagnostics, notifications and support.

2026-09-28

On this page

  • Data at a glance
  • Responsibility for data
  • Data needed to operate the app
  • Detailed diagnostics with your permission
  • Network availability checks
  • Notifications
  • How transmission is protected
  • Retention and deletion
  • Who receives data
  • Your requests and choices
  • This information website
App publisher
BRND LTD
Publisher address
42 Brooklands Lane, WEYBRIDGE, KT13 8UX, United Kingdom
Data controller
BRND LTD

Data at a glance

To activate your device and operate the connection, 4VPN sends the access server a device identifier, authorization information and operational connection events. Detailed diagnostic reports are sent only with your consent.

The sections below explain data types, recipients, purposes, retention and available controls. Declining a detailed report does not disable the VPN or necessary operational communication.

Responsibility for data

The company identified above as the data controller for your version publishes 4VPN and is responsible for processing it organizes to operate the app and support users. We determine the purposes of that processing, restrict access and handle requests to correct or delete data. Contact us at privacy@4vpn.app.

Where we engage processors for this work, they act on our documented instructions and contractual data-protection obligations. The purposes and recipients of transfers are described below. We do not sell data or use it for advertising profiling.

4VPN is a standalone VPN client. A compatible service provider supplies access to VPN servers. Processing that the provider independently carries out for its service is governed by its policy. A recipient’s label does not change its actual responsibilities.

Data needed for activation and connection operation is processed to perform the agreement for use of the app. Detailed reports and commercial notifications rely on separate consent. Abuse prevention, security and quality troubleshooting rely on legitimate interests subject to your rights; legally required records rely on the relevant legal obligation.

Data needed to operate the app

The access server receives a device identifier, its association with an existing account, authorization information and device proofs, platform, manufacturer, model, OS version, app version and build.

To configure, select and restore connections, the app sends attempt times and outcomes, network type, technical route, plan and event identifiers, failure classes and connection-check results. The access server stores the device binding, model and software versions, and connection events. These data are linked to your device and account and are not anonymous.

This is necessary operational communication. A detailed diagnostic report is separate and optional: declining it does not disable the VPN or operational communication. Purchases and payments outside the app are not part of the connection data described here.

Detailed diagnostics with your permission

At support’s request, 4VPN can send a detailed report to the access server to investigate a problem. Sending it requires your separate approval. You can decline or withdraw consent. The report includes connection and recovery events, errors, timing, CPU, memory and thermal measurements, aggregate byte and packet counters, app state and network type.

The size-limited journal itself is stored on your device and covers approximately the previous 24 hours. Keeping it locally does not mean sending a detailed report. After an approved upload, the report is stored on the server and linked to your device and account.

The diagnostic report does not contain browsing history, packet content, your DNS queries, raw IP addresses, carrier/SIM name, SSID/BSSID, IMEI/IMSI, advertising identifiers, passwords or access keys. The tunnel processes network addresses for routing; that does not mean recording browsing history in the diagnostic report.

Network availability checks

The app contacts Google and Cloudflare check endpoints to test connectivity. Direct checks over your current network expose that network’s IP address to the recipient; checks through the VPN expose the IP address of the tested exit.

The app does not attach account details, diagnostic reports or cookies to these check requests. Recipients still process ordinary network connection metadata.

Notifications

The Android version uses Google Firebase Messaging and Firebase Installations. Notification registration uses a Firebase Installation ID (FID); Google also processes data required for its SDK and delivery.

System notification permission and commercial-message consent are separate. Commercial messages are off by default and can be disabled independently of service messages.

A message may open a text card in the app. The card has no checkout link or purchase action.

Notification registration is removed when disabled, when the device is revoked or rebound, or when the token is recognised as invalid. Delivery history is not automatically erased by this operation.

How transmission is protected

Activation and diagnostic service requests use HTTPS. Traffic routed through the VPN tunnel is encrypted between your device and the VPN server. Routing rules determine which connections use the tunnel.

When accepting a detailed report, the server checks consent and the current device binding. Access to reports requires authorization and permission checks. Do not send passwords, one-time codes or access keys in support emails.

Retention and deletion

A detailed report is available for up to 7 days after upload completion. Access then ends and its contents are erased within the following 24 hours. Copies downloaded for support are subject to the same deadline.

A report request is valid for 24 hours. Incomplete parts are erased within the following 24 hours; the request record is removed within 8 days of creation. The size-limited local journal covers approximately the previous 24 hours.

Connection events, check results and notification delivery history are retained for up to 30 days from the event. Only irreversibly anonymized aggregates may remain afterwards if needed for quality analysis.

Device data is retained while its binding is needed. After unlinking, data is erased from working systems within 30 days and access credentials are revoked immediately. Push registration is removed once the server receives a disable, unlink or revocation command; delivery history has a separate retention period.

Minimal security and consent-decision logs are retained for up to 90 days from the event, without a copy of the detailed report. Support correspondence and attachments are retained for up to 180 days after case closure; unnecessary attachments are removed earlier.

Withdrawing consent stops further detailed-report uploads. Once the server receives the request, it deletes report contents and parts for the current device binding. If the device is offline, the request is saved locally and sent when connectivity returns. A minimal consent-decision record may remain within its separate retention period.

Residual backup copies of deleted data expire through rotation within 14 days of deletion from working systems and are not used for ordinary operations. On restoration, deletion requests are reapplied before the data returns to normal use.

We shorten retention when the purpose has been fulfilled earlier or a valid request requires deletion. Longer retention is limited to a specific legal obligation, purpose and period.

Who receives data

The access server is operated by a compatible service provider. It receives and stores device and connection information and detailed reports you authorize. These data are used for activation, connection operation and troubleshooting.

Google Firebase Messaging and Installations process data for notification registration and delivery on Android.

Google and Cloudflare receive technical connectivity-check requests and the IP address of the corresponding connection. The app does not attach account details, browsing history or a detailed report to these requests.

Zoho Mail EU processes messages to support@4vpn.app and privacy@4vpn.app: the sender address, message and attachments chosen by the sender. The app does not automatically attach a diagnostic report.

Processing may occur outside your country, including in the EEA, United Kingdom and United States. For transfers requiring safeguards, we use an applicable adequacy decision or standard contractual clauses with necessary supplementary measures; UK transfers use applicable UK safeguards. You can request details of a specific recipient and a copy of applicable safeguards at privacy@4vpn.app. Hosting email in the EU does not mean all operations are limited to the EU.

Your requests and choices

You can decline a detailed report, withdraw consent, disable commercial messages and manage system notification permission.

To access, correct or delete your data, email privacy@4vpn.app and specify iOS or Android. Where necessary, we will request sufficient information to verify that the data relates to you. Passwords and keys are not required.

We handle requests without undue delay and respond within one calendar month of receipt. If the law allows an extension or limits deletion, we explain the reason and next steps within that month.

When a request is granted, we delete data from working systems and ensure our processors carry out the request. Our usual operational target is within 7 days after necessary verification. Backups and records that must be retained by law are handled as described in the retention section.

You can also withdraw consent and request detailed-report deletion in the app. These actions do not delete your account with the access provider.

Where provided by law, you may also request restriction or portability and object to processing based on legitimate interests. Withdrawing consent does not affect the lawfulness of earlier processing. You may complain to the supervisory authority where you usually live, work or believe an infringement occurred.

The Android company’s supervisory authority is the Information Commissioner’s Office (ICO), United Kingdom; ico.org.uk.

This information website

This site is hosted on Cloudflare Pages. To deliver pages and protect its infrastructure, Cloudflare processes the IP address, request time, requested URL and technical browser headers. Our code sets no cookies and includes no analytics, advertising scripts or forms; fonts and images load from this site. We keep no separate visitor log. Cloudflare retains its own infrastructure records under its policies for as long as needed to operate and protect its service; see cloudflare.com/privacypolicy. The app diagnostic-report retention period does not apply to those records.

Related documentTerms
4VPN

App information, support and documents.

SupportPrivacyTerms

support@4vpn.app
privacy@4vpn.app