We rewrote this policy to remove claims we could not stand behind and to add disclosures that were missing. Specifically: we now disclose device identifiers, matching our Google Play Data safety declaration (Article III); we list every GDPR right individually instead of referring to a list that was not there (Article XI); we removed statements about RAM-only servers, routine third-party audits, and a bug bounty programme, because none of those exist yet (Article IX); we set out retention periods in a table (Article VIII); we aligned the minimum age with our terms of service (Article XII); we added an advertising article that sets the rules before any decision is made (Article XIV); and we filled in the governing law that was previously left blank (Article XVIII). Nothing was removed in order to give us more room — every change either narrows what we may do or adds something you can hold us to.
Article IWho we are and what this covers
Lumo Veil ("Lumo Veil", "we", "us", "our") is a virtual private network service published by QEDCS LLC OF MASSACHUSETTS, a limited liability company organised under the laws of the Commonwealth of Massachusetts, United States. For the purposes of the EU and UK General Data Protection Regulation, that company is the data controller for the personal data described in this policy.
This policy explains how we collect, use, store, and share personal data when you use the Lumo Veil Android application, our servers, and this website (together, the "Service"). It also explains the rights you have over that data and how to exercise them.
Our guiding principle is to collect only the minimum data required to operate a VPN service. We designed the Service so that we do not hold sensitive information about the people who use it. We cannot disclose, misuse, or abuse — even when compelled — data that we do not possess.
By using the Service, you agree to the collection and use of information in accordance with this policy. Read it together with our terms of service, which govern the rest of the relationship.
Article IIThe no-logs pledge
We operate a strict zero-logs policy for your activity and your connections. We do not collect, store, or monitor:
- your browsing history or the websites you visit;
- the content of your internet traffic;
- your DNS queries;
- your original IP address while you are connected to the Service;
- the outgoing VPN IP address assigned to you;
- connection timestamps;
- session duration;
- bandwidth usage attributed to an individual session.
We do not keep logs of your online activity while you are connected. We do not keep connection logs. We cannot and will not monitor, track, or log what you do online.
The one honest qualification
Routing a live connection requires a system to know, for the duration of that connection, where packets are meant to go. This is true of every network in existence, and it is not something a VPN can design away. That state exists only in memory, only while your session is running, is not written to any log, and does not survive the end of the session. No record of your online activity is retained afterwards.
We would rather state this plainly than publish an absolute that a competent engineer would know is impossible.
Article IIIInformation we collect
Even with a strict no-logs policy, some information is necessary to provide, maintain, secure, and improve the Service. This is the complete list.
3.1 Device and app identifiers
The Lumo Veil app may process device or other identifiers — for example an app instance identifier or an Android-provided device identifier. This is the data type declared in the Data safety section of our Google Play listing, and we disclose it here so that the two agree.
We use these identifiers to make the app function correctly on your device, to apply fair-use and anti-abuse limits, and to detect automated or fraudulent use of the Service. They are not linked to your browsing, because your browsing is not recorded. As of the effective date of this policy they are not used for advertising and are not shared with third parties; if that changes, Article XIV sets out exactly what changes and what stays the same.
3.2 Service usage information
To operate and size the Service, we may process aggregate bandwidth volumes (aggregated across the Service, not attributed to an individual session), your device model and operating system version, and your app version and language settings.
3.3 Diagnostic and performance data
To keep quality up we may collect aggregated performance metrics, anonymised crash reports from the app, and anonymised records of unsuccessful connection attempts. This data contains no unique identifier that could tie it back to you. If you report a problem and we need more device information to solve it, we will ask you for it separately and only use what you choose to send.
3.4 Customer support information
If you contact us, we process your email address and the content of your message. We use it to answer you and to understand recurring problems. Nothing else.
3.5 Account information — if and when accounts exist
Version 1.0.0 of the app does not require an account and does not offer one. This clause governs any account feature we introduce later: we would collect your email address (for account creation, verification, recovery, and important service notices) and a password, which would be stored only as a salted hash produced by a modern password-hashing function, never in a form we could read.
3.6 Payment information — if and when paid plans exist
Version 1.0.0 has no in-app purchases and no subscriptions. If paid plans are introduced, payments would be handled by third-party payment processors. We would receive confirmation of a transaction and the details needed for tax and accounting; we would not store full card numbers or complete payment credentials.
3.7 Website and cookies
This website uses no tracking cookies, no advertising pixels, and no third-party analytics. Should we later introduce features that require strictly necessary cookies — session management, security tokens, or remembering your language — they will be limited to that purpose and described here before they are used.
The website loads a web font from Google Fonts. Doing so involves your browser making a request to Google's servers, which discloses your IP address to Google under their own terms. If you would prefer that not to happen, a browser extension that blocks third-party font loading will stop it, and the site remains fully readable without it.
Article IVWhat we never collect
For absolute clarity, the following are never collected, never stored, and therefore never available to us, to a court, to a buyer, or to an attacker.
| Category | Examples |
|---|---|
| Browsing activity | Websites visited, pages viewed, searches conducted |
| Traffic content | Data payloads, files transferred, messages sent |
| Destination data | Destination IP addresses, domain names visited |
| DNS queries | Domain name resolution requests |
| IP addresses | Your original IP address or the VPN address assigned to you |
| Connection metadata | Timestamps, session duration, per-session server usage |
| Activity logs | Any record of what you do while connected |
We cannot disclose, misuse, or abuse data that we do not possess. That sentence is the whole design.
Article VHow we use information
We use the limited information described in Article III only to:
- provide, operate, and maintain the VPN Service;
- keep the Service secure — detecting abuse, automated misuse, and fraud;
- diagnose faults and improve performance and reliability;
- answer you when you contact support;
- send service notices that matter — security, availability, and changes to this policy or our terms;
- process payments and manage subscriptions, if and when paid plans exist;
- comply with legal obligations that apply to us.
We do not sell, rent, or trade personal information, and we do not share it with third parties for their own marketing purposes. We do not build advertising profiles from your use of the VPN, and no processing described here involves the content of your traffic, because that is never recorded. Advertising, if it is ever present in the app, is governed by Article XIV.
Article VILegal bases for processing
If you are in the European Economic Area, the United Kingdom, or Switzerland, we must have a lawful basis for each thing we do with your data. These are ours.
| Processing activity | Legal basis |
|---|---|
| Providing the VPN Service | Performance of a contract (Art. 6(1)(b)) |
| Device identifiers for anti-abuse and correct operation | Legitimate interest in keeping the Service usable and secure (Art. 6(1)(f)) |
| Aggregate diagnostics and crash reports | Legitimate interest in a working product (Art. 6(1)(f)) |
| Customer support | Performance of a contract, or legitimate interest in answering you (Art. 6(1)(b) / (f)) |
| Payment processing and record-keeping | Performance of a contract and legal obligation (Art. 6(1)(b) / (c)) |
| Responding to lawful legal process | Legal obligation (Art. 6(1)(c)) |
| Optional marketing email, if ever offered | Consent, withdrawable at any time (Art. 6(1)(a)) |
Where we rely on legitimate interest, we have weighed it against your rights and freedoms, and you may object at any time under Article XI.
Article VIIIHow long we keep things
We keep personal data only as long as it serves the purpose it was collected for, and then delete or anonymise it.
| Data | Retention |
|---|---|
| Browsing, DNS, traffic content, connection records | Never stored, so nothing to retain |
| In-memory session state | Deleted when the session ends |
| Device or other identifiers | No longer than 12 months, unless an active abuse investigation requires longer |
| Anonymised diagnostics and crash reports | Up to 24 months, in aggregated form |
| Support correspondence | Up to 24 months after your issue is resolved |
| Account information, if accounts exist | For the life of the account, then deleted within 90 days of closure |
| Payment and tax records, if paid plans exist | As long as tax, accounting, and audit law requires — typically 7 years |
Where we are required to retain something for legal compliance, we retain only that, and only for as long as the obligation lasts.
Article IXSecurity
We protect the Service with measures appropriate to its risk:
- Encryption in transit. The VPN tunnel between your device and our servers is protected with strong, standard cryptography — AES-256 in the data channel. Traffic between this website and your browser is served over HTTPS.
- Restricted access. Access to production systems is limited to the people who need it, and is authenticated and monitored.
- Hardened infrastructure. Servers are patched and hosted in data centres with physical and logical access controls.
- Minimisation as a control. The most effective security measure on this list is that browsing and connection records are never written. A breach cannot expose a database that does not exist.
- Responsible disclosure. We accept good-faith vulnerability reports at [email protected] and commit to the terms set out on our security page.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where the GDPR requires, and notify affected users without undue delay where the risk is high.
We have not commissioned an independent third-party security audit, and we do not operate a paid bug bounty programme. Earlier drafts of this policy said otherwise; that was wrong, and it has been removed. If either changes, this section will say so with a date.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and anyone who tells you they can is selling something.
Article XInternational transfers
Lumo Veil is operated from the United States, and a VPN by its nature routes traffic through servers in many countries. Your information may therefore be processed outside the country you live in, including in countries whose data protection laws differ from your own.
Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), data processing agreements with our providers, and adequacy decisions where one applies. You may request a copy of the safeguards we rely on by writing to us.
Article XIYour rights
Some of these rights are guaranteed by law where you live. We extend all of them to everyone who uses Lumo Veil, wherever they are, because a right that depends on your postcode is a weak one.
11.1 Rights we extend to every user
- Access. Ask what personal data we hold about you and get a copy.
- Rectification. Have inaccurate data corrected and incomplete data completed.
- Erasure. Ask us to delete personal data we hold about you.
- Restriction. Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability. Receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
- Objection. Object to processing we carry out on the basis of legitimate interest.
- Withdraw consent. Where processing is based on consent, withdraw it at any time, without affecting what was lawful before.
Set your expectations honestly: because we do not keep activity or connection records, an access request cannot return your browsing history — there is none to return. What we can produce is any support correspondence and confirmation of the categories described in Article III.
11.2 If you are in the EEA, the UK, or Switzerland
The rights above are yours under Articles 15 to 22 of the GDPR (and the UK GDPR). In addition:
- You have the right to lodge a complaint with a supervisory authority — your national data protection authority in the EEA, the Information Commissioner's Office in the UK, or the Federal Data Protection and Information Commissioner in Switzerland. We would appreciate the chance to resolve it first, but you do not have to come to us before you go to them.
- We do not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you, within the meaning of Article 22.
- We will respond to a request within one month, extendable by two further months for genuinely complex requests, in which case we will tell you why before the first month expires.
11.3 If you are a California resident
Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know what personal information we collect, use, and disclose; the right to delete it; the right to correct it; the right to opt out of its sale or sharing; and the right not to be discriminated against for exercising any of these.
We do not sell personal information, and we have not done so in the preceding twelve months. As of the effective date of this policy we also do not share personal information for cross-context behavioural advertising, and have not in the preceding twelve months, so there is presently no sale or sharing to opt out of. Should an advertising component be introduced that constitutes "sharing" under the CPRA, we will update this policy before it takes effect and provide a clear "Do Not Sell or Share My Personal Information" control — see Article XIV. We do not collect sensitive personal information for the purpose of inferring characteristics about you, so there is no right to limit its use to exercise.
The categories of personal information we collect are set out in Article III: identifiers (device identifiers and, if you write to us, your email address), internet or network activity information in aggregate and anonymised form only, and the contents of your communications with support. The business purposes for collecting each are in Article V, the categories of recipients in Article VII, and the retention periods in Article VIII.
You may use an authorised agent to make a request on your behalf; we will ask for proof of that authorisation.
11.4 How to exercise any of this
Email [email protected] with "Data request" in the subject line. Tell us what you want and which country or state you are in, so we apply the right law. We may need to verify your identity before we act, and we will ask for the least amount of information that will do it. Exercising a right is free; we may charge a reasonable fee only for requests that are manifestly unfounded or repetitive, and we will tell you before we do.
Practical guidance on making a request is on the support page.
Article XIIChildren
The Service is not directed at children. Under our terms of service you must be at least 18 years old, or the age of majority where you live, to use Lumo Veil.
We do not knowingly collect personal information from children under 13, or, in the European Economic Area and the United Kingdom, from children under 16. If you believe a child has provided us with personal information, write to us and we will delete it promptly.
Article XIIIDo Not Track and Global Privacy Control
This website does not track visitors across sites, so there is no cross-site tracking for a signal to switch off. We honour Global Privacy Control and Do Not Track signals as a matter of course, in that we do not perform the behaviour they are designed to prevent.
Article XIVAdvertising
Version 1.0.0 of the Lumo Veil app shows no advertising, and our Google Play listing declares none. Advertising is nonetheless a normal way for a free mobile app to fund itself, and this Article is published in advance so that the rules are set before the decision is made rather than after.
14.1 What would never change
- Advertising would never be based on your browsing history, your DNS queries, the content of your traffic, your original IP address, or your connection times. Those are not recorded, so they cannot be used for anything, including this.
- We would never sell, rent, or trade your personal information. That commitment in Article V is not conditional.
- No advertising would be placed inside the VPN tunnel or injected into the pages and apps you use. Any advertising would appear only in the Lumo Veil app's own interface.
14.2 What would change, and how you would know
An advertising component — for example the Google AdMob software development kit — typically processes the Android advertising identifier and basic device and app information, and shares it with the advertising provider so that ads can be delivered and measured. If we introduce one:
- we will update our Google Play Data safety declaration to state precisely what is collected and with whom it is shared, before the release ships;
- we will update this policy with a new effective date and a plain-language summary of the change, and give the 30 days' notice required by Article XVI;
- we will name the advertising provider here, and link to its own privacy policy;
- where consent is legally required — in the EEA and the UK, for personalised advertising — we will ask for it through a consent interface and honour a refusal, rather than treating use of the app as agreement;
- we will provide, and point you to, the controls that let you opt out of personalised advertising and reset or delete your advertising identifier in Android's own settings.
14.3 The file you may have found
This website publishes an app-ads.txt file, which is an industry standard that lets advertising systems verify which sellers are authorised to represent an app's inventory. Publishing it is a fraud-prevention measure and a prerequisite for advertising rather than advertising itself. We mention it because it is public, and finding it later without explanation would reasonably look like something being hidden.
Article XVOur Google Play declaration
Google requires every Android developer to declare their data practices in the Play Store's Data safety section. That declaration and this policy must agree; where an app's listing and its privacy policy contradict each other, at least one of them is wrong. Ours is reproduced here so you can check.
| Play Data safety statement | Where it is covered here |
|---|---|
| No data shared with third parties | Articles V and VII |
| This app may collect: Device or other IDs | Article 3.1 |
| Data is encrypted in transit | Article IX |
If you ever find a discrepancy between our Play listing and this policy, tell us. We will correct whichever one is wrong and say which it was.
Article XVIChanges to this policy
We may update this policy. When we do, we will post the new version here with an updated effective date and a plain-language summary of what changed, in the style of the note at the top of this document.
For changes that materially reduce your protections or materially expand what we collect, we will give notice at least 30 days before they take effect — by email to any address associated with an account, and by a notice in the app or on this website. Continuing to use the Service after a change takes effect means you accept it; if you do not, you can stop using the Service and ask us to delete what we hold.
Article XVIIContact and complaints
Questions, concerns, complaints, and data requests all go to the same place:
| Data controller | QEDCS LLC OF MASSACHUSETTS |
|---|---|
| [email protected] | |
| Subject line | "Data request", "Privacy", or "Complaint" |
| First response | Within 5 business days |
| Full response | Within 30 days |
If we have not resolved your complaint to your satisfaction, you may escalate it to your data protection supervisory authority as described in Article 11.2, or to the Attorney General of California if you are a California resident.
Article XVIIIGoverning law
This privacy policy is governed by and construed in accordance with the laws of the Commonwealth of Massachusetts, United States, without regard to its conflict of law provisions.
Nothing in this Article deprives you of the protection of mandatory data protection law in your own country. If you are in the EEA, the UK, or Switzerland, your statutory rights under the GDPR and equivalent legislation apply regardless of the governing law stated here.
Where this policy and our terms of service conflict on a privacy matter, this policy governs.