The short version
BlackSwan is a no-logs VPN. We keep no record of what you do online — no browsing history, no destinations, no DNS lookups, no traffic contents. We cannot hand over activity we never recorded.
We are not zero-data. To run an account and a network we keep a small, defined set of metadata: aggregate byte counts per account, billing records, and your source IP address for a short window (24 to 72 hours) to handle abuse and enforce device limits. We state below exactly what that is and how long it lasts.
Last updated: July 18, 2026. This policy works alongside our Terms of Service, which includes our acceptable-use rules and refund policy.
Who we are (data controller and jurisdiction)
BlackSwan VPN is the operator of the service and the data controller for the limited personal data described here. The operating entity and governing jurisdiction are being finalized ahead of launch and will be stated here once confirmed; we are establishing the service in a privacy-friendly jurisdiction.
We are establishing the service in a privacy-friendly jurisdiction with no mandatory data-retention regime that would force us to log your activity. We separate our control plane (accounts, billing) from our exit-node hosting, so a node takedown never reaches billing or sign-in data.
For privacy questions, contact privacy@blackswan.vpn. General support is at support@blackswan.vpn.
What we do not log
A no-logs VPN is defined by what it refuses to keep. Our nodes and our control plane are configured so that none of the following is ever written to disk:
- Browsing history — the websites, apps, or services you reach through the tunnel.
- Traffic destinations — the IP addresses, hostnames, or domains you connect to.
- DNS queries or responses — the names your device looks up while connected.
- Packet or flow contents — any payload of your traffic.
- A mapping of you to the destinations you visit — we hold no record that could reconstruct your activity, because we store no destinations to map you to.
- Per-site, per-destination, or per-session bandwidth — usage is counted only as aggregate totals (see section 4).
What we do process, and how long we keep it
To sell subscriptions, run the network, and enforce fair use, we process a deliberately minimal set of data. Account identity and network metadata are kept apart and never joined into an activity profile. Each item below states its retention window.
- Source IP address: while you are connected, your originating IP is held in a connection-session record for abuse and fraud response and to enforce device/concurrency limits. It is automatically purged within 24 to 72 hours. It is never stored next to any destination, so it cannot reveal what you did. This is the only identifying network datum we retain, and it is short-lived by design.
- Aggregate byte counts: total upload and download per account, used to enforce free-tier data caps and to verify an active subscription. These are counts only — never broken down by site, destination, or session. Raw samples are rolled up and pruned within roughly 30 to 90 days; aggregate totals are kept while the account is active.
- Subscription identifiers: for in-app purchases, an anonymous app-instance identifier and an opaque receipt/subscription token from Apple or Google — no Apple ID, Google account, name, or email. Kept while the subscription is active and for a short period afterward to honor renewals, refunds, and tax/accounting obligations.
- Device enrollment: a device-bound subscription token and minimal device record, so your subscription works on your device and can be restored. Kept for the life of the account.
- Admin sign-in (staff): for BlackSwan staff signing in to the internal panel at /login, an email address used only for one-time-code (OTP) authentication. There are no passwords. OTP codes expire within 5 minutes; sessions expire after 8 hours idle or 24 hours absolute, or on logout. This applies to staff only — VPN customers never sign in here.
- Administrative-action records: a tamper-evident log of actions BlackSwan staff take in the internal panel (for example, suspending an account in response to an abuse report). This records staff activity for accountability — not your browsing — and is kept for the life of the account.
- Support correspondence: what you send us when you ask for help. Retained for a limited period after the issue is resolved.
Location (optional)
Location sharing is off by default and entirely optional. If, and only if, you turn it on, the app may attach an approximate (city-scale) location when you connect — never precise GPS, and never your continuous whereabouts. We use ACCESS_COARSE_LOCATION on Android and Apple's reduced-accuracy location on iOS; we never request background or always-on location.
We use these approximate points only to understand where the service is used so we can plan capacity and improve coverage. They are never used to identify you, never tied to your browsing or destinations, and never affect your subscription or access in any way.
You can disable location sharing at any time in the app's Settings. Turning it off stops new points immediately.
Payments — we never see your card
Subscriptions are sold through Apple's App Store or Google Play. Payment is handled entirely by those parties.
We never receive or store full card numbers, bank details, or billing addresses. From Apple and Google we receive only an opaque receipt or subscription token confirming a valid purchase and whether it is still active.
Apple and Google are independent controllers of the payment data they collect; their own terms apply to it. Refunds are described in the Refunds section of our Terms of Service.
Sub-processors and service providers
We keep our supplier list short and engage providers only for the narrow functions below. Each is bound by contract to protect the data it processes for us.
- App stores (Apple App Store, Google Play): subscription purchase, receipt validation, and in-app-purchase refunds.
- Infrastructure and hosting providers: the servers and data centers that run our VPN exit nodes and control plane.
- Transactional email provider: delivering one-time sign-in codes to BlackSwan staff.
- Push provider (Google Firebase Cloud Messaging / Apple Push Notification service): best-effort delivery of optional app notifications; never a channel for your traffic.
- No third-party analytics or crash-reporting SDK: the BlackSwan apps bundle neither. Aggregate usage analytics are computed by us in-house from byte counters; nothing about your activity is sent to a third-party analytics or crash vendor.
Lawful bases for processing
For users protected by GDPR-style or similar laws, we rely on the bases below. Each applies only to the minimal data described in section 4.
- Performance of a contract: verifying an active subscription and delivering the service you purchased.
- Legitimate interests: keeping the network secure, enforcing data caps and device limits, planning capacity from aggregate metrics, and responding to abuse (see the Acceptable Use section of our Terms of Service) — balanced against your privacy, which is why the source IP is short-lived and usage is aggregate.
- Legal obligation: complying with a valid legal request, strictly to the extent we hold responsive data — which, for activity, is none; and retaining minimal transaction records where tax or accounting law requires it.
- Consent: where required — for example, optional push notifications, which you can enable or decline in app settings and withdraw at any time.
Data retention summary
We keep data only as long as it serves its purpose, then delete or anonymize it. Because we create no activity logs, there is nothing to retain about your browsing, destinations, DNS lookups, or traffic contents — that data is never written at any point.
- Activity data (browsing, destinations, DNS, payloads): never recorded — zero retention.
- Source IP in connection-session records: 24 to 72 hours, then automatically purged.
- Aggregate byte counters: raw samples pruned within roughly 30 to 90 days; aggregates kept while the account is active.
- Subscription, billing, and entitlement records: account lifetime plus any legally required tax/accounting window, then deleted.
- Device enrollment: account lifetime.
- Staff email and sign-in sessions: account lifetime; OTP codes expire within 5 minutes; sessions expire after 8 hours idle or 24 hours absolute.
- Administrative-action log: tamper-evident, retained for accountability (records staff actions, not your activity).
- Support emails: a limited period after the issue is resolved.
International transfers
BlackSwan operates a global network, so the limited data above may be processed in countries other than your own, including at hosting and app-store providers in various regions.
Where data crosses borders, we rely on appropriate safeguards — such as standard contractual clauses or equivalent protections with our providers — and we minimize what is transferred in the first place. Our strongest safeguard remains design: there is no activity data to transfer.
Third-party exit servers
Most BlackSwan traffic exits through our own nodes under the no-logs configuration above. In some regions we may route traffic through rented upstream capacity. When that happens, a third party — not BlackSwan — operates the exit and can see traffic under its own logging, retention, and jurisdiction, which our no-logs invariant cannot bind. These options are off by default.
Where a server uses a third-party exit that exposes your IP and destinations directly to the upstream operator, we label it as third-party in the app so you can choose. We use only providers we consider credibly no-logs. Our no-logs promise is scoped to exclude traffic you route through a third-party exit.
Your rights
Depending on where you live, you may have GDPR-style rights (EU/EEA/UK), CCPA-style rights (California), or comparable rights elsewhere. We honor these for all users, to the extent the data exists.
Because we collect so little — and nothing about your activity — most requests resolve quickly: there is no activity record to access, port, or erase.
- Access: ask what personal data we hold about you.
- Erasure: ask us to delete your account. On a verified request we perform a full deletion of your records, except minimal transaction data we are legally required to retain.
- Portability: receive a copy of the limited account data we hold in a portable format.
- Rectification: correct inaccurate account data.
- Objection / restriction: object to or restrict certain processing, including optional diagnostics.
- No sale of data: we do not sell personal data and do not share it for cross-context behavioral advertising.
- Non-discrimination: exercising a right will not degrade your service.
- Complaint: you may lodge a complaint with your local data protection authority.
How to exercise your rights
Email privacy@blackswan.vpn with enough information for us to locate the relevant record. We may ask you to verify control of an account before acting, to protect you against fraudulent requests.
We aim to respond within 30 days. There is no charge for a reasonable request.
Children
BlackSwan is not intended for children. The service is for users aged 16 and over. We do not knowingly collect personal data from anyone under 16.
If you believe a child has provided us data, contact privacy@blackswan.vpn and we will delete it.
Security
Privacy is only as strong as the security behind it. We protect data with measures appropriate to its sensitivity.
- Strong, modern encryption protects your traffic in transit.
- Passwordless staff authentication via email one-time codes and HttpOnly, server-side sessions — there are no passwords to steal.
- Data minimization as a primary control: data we never collect cannot be breached, subpoenaed, or leaked.
- Hardened infrastructure, strict access controls, and least-privilege access for the small team that operates the network.
- No method of transmission or storage is perfectly secure; we work continuously to reduce risk.
Transparency
We state our logging posture plainly rather than asking you to take a slogan on faith: sections 3, 4, and 8 list exactly what we do and do not keep, and for how long. Our app-store privacy disclosures (Apple Privacy Labels and Google Data Safety) are kept consistent with this policy.
We do not currently publish a warrant canary or a periodic transparency report. We prefer to make our posture verifiable in what we engineer: nodes are deployed with access and connection logging suppressed, so there are no activity logs to produce. Where the law permits, we will notify affected users of a legal request that concerns their data.
Changes to this policy
We may update this policy as our service, providers, or legal obligations change. For a material change we will update the "Last updated" date and, where appropriate, notify you in the app or by email.
Continued use of BlackSwan after an update means you accept the revised policy. If you disagree with a change, you may stop using the service and request deletion of your data.
Contact
BlackSwan VPN — contact us using the addresses below.
- Privacy and data rights: privacy@blackswan.vpn
- General support: support@blackswan.vpn
- Abuse reports: abuse@blackswan.vpn
- Legal notices: legal@blackswan.vpn