1. Summary
The short version. Lunexis VPN has no user accounts — we never ask for your name, email address or phone number. We do not log, monitor or store your browsing history, DNS queries, or the contents of your network traffic. To enforce the free daily time allowance we store an anonymous, hashed device identifier together with the number of seconds of VPN time you have used. We use Google AdMob to show ads to free users and Firebase to detect crashes. Subscription payments are handled entirely by Google Play — we never see your card details.
2. Who we are
Lunexis ("Lunexis", "we", "us" or "our") develops and operates the Lunexis VPN mobile application for Android (the "App") and the website at lunexis.org (the "Site"). Together they are referred to as the "Service".
For any question about this policy or your data, contact us at support@lunexis.org. We act as the data controller for the limited personal data described below.
3. Data we collect
We deliberately keep collection to the minimum required for the Service to function.
3.1 Anonymous device identifier (HWID)
Because the App has no accounts, we need a way to know how much free time a given device has used today. The App generates a Hardware ID (HWID) by applying a one-way cryptographic hash to your Android ID combined with non-unique hardware metadata (device model and manufacturer).
- The HWID is a pseudonymous identifier. It is not linked to your name, email, phone number, advertising ID or any account.
- It cannot be reversed to recover your Android ID.
- Android ID changes when you factory reset your device or reinstall on a new user profile, which produces a new HWID.
3.2 Usage time (free tier enforcement)
While the VPN is connected on the free tier, the App periodically sends "usage deltas" — the number of seconds of connection time consumed — to our private backend API. Each delta is associated only with your HWID. This is the mechanism that enforces the 30-minute daily free allowance. We do not record which servers you connected to for profiling purposes, what you accessed, or how much data you transferred.
3.3 Installed application list (on-device only)
To provide the Per-App VPN (split tunneling) feature, the App reads the list of applications installed on your device so that you can choose which apps use the tunnel. This list stays on your device. It is never transmitted to us or to any third party.
3.4 Diagnostics and crash data
Firebase (Google) collects crash reports, stack traces, and basic stability and engagement metrics such as app opens, app version, OS version and general device model. This helps us find and fix bugs. This data is pseudonymous and is not used to identify you personally.
3.5 Purchase status
When you subscribe to Premium, Google Play provides the App with a purchase token and subscription status so the App can unlock premium features. We store only the subscription state necessary to keep your Premium access working. We never receive or store your credit card number, bank details or billing address.
3.6 Advertising data
Google AdMob may collect data — including your advertising identifier, coarse location derived from IP address, and ad interaction data — in order to serve and measure advertisements to free-tier users. This processing is governed by Google's own privacy policy and by the consent choices you make in the consent dialog (see section 8).
3.7 Website data
The Site is a static website hosted on Cloudflare Pages. It sets no tracking cookies and runs no third-party analytics. Cloudflare processes standard server request data (such as IP address and user agent) for security and abuse prevention, as described in Cloudflare's privacy policy.
4. Data we do not collect
We do not collect, log, store or sell any of the following:
- Your browsing history, visited websites or page contents
- DNS queries you make while connected
- The contents of your network traffic, messages or files
- Your name, email address, phone number or postal address
- Your precise GPS location
- Your contacts, photos, camera, microphone or SMS messages
- Payment card or bank account details
5. How we use data
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| HWID (hashed device ID) | Enforce the free daily time allowance and prevent abuse of the free tier | Legitimate interests / performance of a contract |
| Usage seconds | Calculate remaining free minutes | Performance of a contract |
| Crash & diagnostics | Detect, diagnose and fix defects; improve stability | Legitimate interests |
| Purchase status | Unlock and maintain Premium features | Performance of a contract |
| Advertising identifiers | Show and measure ads to free-tier users | Consent (where required) |
| Installed app list | Let you configure per-app split tunneling (on-device only) | Performance of a contract |
We do not sell your personal information, and we do not share it with data brokers.
6. Permissions we request
| Permission | Why it is needed |
|---|---|
BIND_VPN_SERVICE | Core function — creates the encrypted VPN tunnel. Android always asks you to approve this the first time. |
INTERNET / ACCESS_NETWORK_STATE | Connect to VPN servers and detect network changes. |
QUERY_ALL_PACKAGES | Used solely to display the list of your installed apps in the Per-App VPN (split tunneling) screen. The list never leaves your device. |
FOREGROUND_SERVICE | Keeps the VPN tunnel alive and shows the persistent notification while connected. |
POST_NOTIFICATIONS | Displays the connection status notification (Android 13+). |
RECEIVE_BOOT_COMPLETED | Optional — restores your connection after a reboot if you enable auto-connect. |
BILLING | Processes Premium subscriptions through Google Play. |
7. Third-party services
The App integrates the following third-party services. Each processes data under its own privacy policy:
- Google AdMob — serves advertisements to free-tier users. How Google uses data in advertising
- Firebase (Google) — crash reporting and basic analytics. Firebase privacy
- Google Play Billing — processes all subscription payments. Google Privacy Policy
- Google User Messaging Platform (UMP) — presents GDPR/CCPA consent dialogs to users in regulated regions.
- Cloudflare — hosts this website and protects it against abuse. Cloudflare privacy policy
Server configuration data used by the App is fetched from a remote configuration endpoint in encoded form; this request does not include any personal information about you beyond the technical metadata inherent to any HTTPS request.
8. Advertising and consent
Free-tier users see advertisements delivered by Google AdMob. If you are located in the European Economic Area, the United Kingdom, Switzerland, or a US state with applicable privacy legislation, the App uses the Google User Messaging Platform (UMP) to present a consent dialog before personalised ads are shown.
- You may choose non-personalised ads, which limits the data used for ad targeting.
- You can change your choice later from the App's settings ("Privacy options" / "Manage consent").
- You can reset or delete your advertising ID at any time in Android Settings → Google → Ads.
- Premium subscribers see no ads at all, and the advertising SDK does not request ads for them.
9. Sharing and disclosure
We share data only in these limited circumstances:
- Service providers — the processors listed in section 7, strictly for the purposes described.
- Legal requirement — if we receive a valid, binding legal order, we will disclose the data we hold. Because we do not keep traffic logs, browsing history or DNS records, such data does not exist and cannot be produced. The most we could ever produce is an anonymous HWID and a count of seconds used.
- Business transfer — if the Service is ever acquired, data may transfer to the acquirer under the terms of this policy; we will notify users of any material change.
10. Data retention
- HWID and usage counters — retained while the identifier remains active and deleted after 90 days of inactivity, or sooner upon request.
- Crash reports — retained according to Firebase Crashlytics defaults (typically up to 90 days).
- Subscription status — retained for the duration of the subscription plus any period required for tax, accounting or dispute-resolution purposes.
11. Security
All VPN traffic is encrypted using modern tunnelling protocols (VMess, VLESS, Trojan, Shadowsocks) provided by the Xray/V2Ray core. Communication between the App and our backend uses HTTPS/TLS. Device identifiers are stored in hashed form. Access to our backend is restricted to authorised administrators.
No system can be guaranteed to be perfectly secure. If we become aware of a breach affecting your data, we will notify affected users and the relevant supervisory authority where legally required.
12. Your rights
12.1 EEA / UK (GDPR)
You have the right to access, rectify, erase, restrict or object to processing of your personal data, and the right to data portability. You may withdraw advertising consent at any time. You also have the right to lodge a complaint with your local data protection authority.
12.2 California (CCPA/CPRA)
You have the right to know what personal information is collected, to request deletion, and to opt out of the "sale" or "sharing" of personal information. We do not sell your personal information. Advertising data sharing can be limited through the in-app consent options.
12.3 Exercising your rights
Email support@lunexis.org. Because we hold no account information, we may ask you to supply the HWID shown in the App's settings so we can locate the correct record. We will respond within 30 days.
13. Deleting your data
You can request deletion of all data associated with your device at any time. Full instructions are on our Data Deletion page. In short:
- Uninstalling the App removes all locally stored settings and preferences.
- Email support@lunexis.org with the subject "Data deletion request" and your HWID to have the server-side usage record erased.
14. Children
The Service is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
15. International transfers
Our processors (Google, Cloudflare) operate globally, so data may be processed outside your country, including in the United States. Where required, such transfers rely on Standard Contractual Clauses or equivalent safeguards implemented by those providers.
16. Changes to this policy
We may update this policy as the App evolves. The "Last updated" date at the top of the page always reflects the current version. Material changes will be announced in the App or on this Site before they take effect. Continued use of the Service after changes take effect constitutes acceptance.
17. Contact us
Questions, requests or complaints about privacy:
Email: support@lunexis.org
Website: lunexis.org
Response time: usually within 2 business days, and no later than 30 days.