Legal

Privacy policy

Draft

This policy describes the service as built and has not yet been reviewed by a lawyer. The plain-language version is the privacy page; where the two differ, tell us, because one of them is wrong.

Last updated: 22 August 2026

This policy explains what Nemean Software, LLC (“we”) processes when you use Nemean VPN, why, for how long, and what you can do about it. It is written to match the system as built; if we change the system, we change this.

1. Who is responsible

Nemean Software, LLC is the data controller. Contact: [email protected].

2. What we process, and why

2.1 Your account

DataPurposeRetention
Email addressTo identify your account and let you recover it.Until the account is deleted.
Password (as an Argon2id hash)To authenticate you. We cannot recover the plaintext.Until changed or the account is deleted.
Session tokens (hashed)To keep you signed in to the portal and the app.30 days, or until you sign out.
Second-factor secret (encrypted) and recovery codes (hashed)To verify a second factor, if you enable one.Until disabled.
Device name and public keyTo let a device request credentials, and to let you revoke it.Until you revoke it or delete the account.
Subscription tier, status and periodTo know what you are entitled to.While the account exists.
Payment method summary (card brand, last four digits, expiry)To show you which card is on file.Until replaced.
Invoice referencesTo show you your invoices and to meet tax obligations.As long as tax law requires.

2.2 Payments

Payments are processed by our payment processor. The card form is served by them and the payment is confirmed between your browser and them; your card number does not pass through our servers. The processor holds your payment details and your email for the subscription under their own privacy policy.

2.3 Using the tunnel

When the app connects, it presents a gateway with a credential containing a validity window, a plan tier and a signature. The credential contains no account identifier. The gateway sees the network address your device connects from for the duration of the session, as any server you connect to does, and forwards your traffic to its destination. Gateways keep aggregate counters (packets, bytes, handshakes, failures, active session count) and do not record source addresses, destinations, DNS queries or session times.

When the app requests a credential, our sign-in systems record nothing about the request beyond the fact of it being served. It does not learn which gateway you connect to or what you do.

2.4 This website

This site is static. It sets no cookies and uses no third-party analytics. Your theme preference, if you change it, is stored in your own browser and never sent to us. Our web host may keep ordinary server logs (requesting address, path, time) for a short period for security and capacity; we do not use them to identify visitors.

3. What we do not process

  • A history of which account connected to which gateway, or when.
  • The destinations, DNS queries or contents of your traffic.
  • Bandwidth or usage per account.

Not because of a rule: there is no mechanism that produces these records.

4. Legal basis

We process account and billing data to perform our contract with you; invoice data to meet legal obligations; and the minimal server logs described above on the basis of our legitimate interest in keeping the service available and secure.

5. Sharing

We share data with our payment processor (to take payment), our hosting providers (who run the servers the service lives on), and nobody else in the ordinary course. If we receive a legal demand, we will comply to the extent we are required to, with what exists — which is the list in section 2 and nothing in section 3.

6. Your rights

You can see and change your email, devices, subscription and payment method in the portal. You can ask us to delete your account, export your data, or correct it by writing to [email protected]. Depending on where you live you may also have the right to complain to a supervisory authority.

7. Security

Passwords are hashed with Argon2id; session tokens are random and stored hashed; second-factor secrets are encrypted at rest; the portal session is an HttpOnly, Secure cookie. The security page describes the rest.

8. Changes

When this policy changes, the date at the top changes. Material changes are announced to account holders by email.