Legal

Privacy Policy

Effective 17 August 2026 · Last updated 17 August 2026

The short version

You can read every page on this site without giving us anything. There is no account to create, no form to fill in, no newsletter, and no analytics or advertising script running in your browser. We set no cookies of our own.

Two things do happen, and we would rather write them down than let you assume otherwise. Our hosting provider produces aggregate statistics from server requests — how many times a page was opened, which sites people came from, which countries requests came from. And displaying a page loads a font, a stylesheet and an icon library from three outside services, each of which sees your IP address because your browser contacts them directly.

Nothing here identifies you. There is no identifier that follows you between visits, no profile, and nothing we could sell even if we wanted to. The rest of this page sets out the detail, the legal basis for each item, and what you can ask us to do.

1. Who we are and what this covers

This policy applies to the website at vpntruthlab.com and to the way that site handles information. VPN Truth Lab operates the site and decides what is collected through it. Where European or British data protection law applies to a reader, that makes us the data controller for the limited processing described below. Most of our readers are in the United States, so the California rules in section 6 will be the relevant ones more often.

You can reach us about anything in this policy at editorial@vpntruthlab.com.

This policy does not cover any VPN provider's website, application or service. Once you follow a link away from here, that company's own policy applies instead — and given what you came to this site to buy, it is worth actually reading.

2. What we do not do

Shorter and more useful than the alternative list. None of the following happens on this site:

3. What is actually processed

Four things, and only four. Each one is set out below with why it happens, what legal basis it rests on, and how long it lasts.

3.1 Server logs

Like every web host, ours records the requests its servers handle. A log line typically contains an IP address, the URL requested, a timestamp, the browser's user-agent string and the referring page.

Why: keeping the site online, diagnosing faults, and defending against abuse such as denial-of-service attempts.

Legal basis: legitimate interests (GDPR Article 6(1)(f)) — running a website securely. We do not use these logs to build any profile of a reader.

Retention: held by the host for a short rolling window under its own retention schedule, then deleted. We do not export, archive or analyse them.

3.2 Aggregate statistics

Our host produces visitor statistics from those same server requests, without placing anything in your browser. What we see are counts: how many times a page was opened, which sites people arrived from, and which country a request originated in.

The distinction that matters here is between counting and identifying. These figures tell us that a number of people from a given country opened a given page. They carry no identifier that follows anyone between visits, and there is no way for us to single out an individual reader or reconstruct what one person did.

Why: to see which comparisons people actually read, so we know what to update and expand.

Legal basis: legitimate interests (Article 6(1)(f)). Because this happens on the server and stores nothing on your device, it does not require cookie consent under the ePrivacy Directive.

Note: as this runs server-side rather than in your browser, ad blockers and Do Not Track settings have no effect on it — which is exactly why we would rather state it plainly here.

3.3 Third-party resources loaded by the page

Displaying a page here loads files from services we do not control. Your browser contacts them directly, so each receives your IP address, the page you are viewing and your user-agent string. We receive nothing back from any of them.

Service Purpose
Google FontsThe typeface used across the site
Tailwind CDNThe stylesheet engine that renders the layout
Cloudflare (cdnjs)The icon library used for interface icons
Our hosting providerServes the pages; produces the statistics in 3.2

Why: the site needs a font, a stylesheet and icons to display correctly.

Note: none of these are advertising services and none are configured by us to track you. We list them because “we don't track you” is not the same statement as “nobody sees your request”, and only one of those is true here.

3.4 If you email us

Writing to us means we hold your email address and whatever you put in the message. We use it to reply and for nothing else. It does not go on a mailing list, because there is no mailing list.

Legal basis: legitimate interests (Article 6(1)(f)) — answering someone who contacted us.

Retention: for as long as it takes to deal with the message, plus a record of any correction we made to the site as a result. Ask and we will delete the correspondence.

4. Affiliate links and the cookies others set

Some links on this site are commercial. If you follow one and subscribe, we receive a commission at no additional cost to you. This is how the site is funded, and it is stated on How We Test and About as well as here.

In privacy terms, here is what happens when you click one. Your browser passes through a tracking domain operated by the provider or its affiliate network, which typically sets a cookie on its own domain so a later signup can be attributed. That cookie is set by them, not by us, sits outside our control, and is governed by their privacy policy — which is why we cannot delete it for you and why nothing you do on this page will stop it.

Nothing is set until you click. Simply reading a page places no commercial cookie of any kind.

What reaches us from these programmes is commission reporting: that a signup occurred, and aggregate figures. We do not receive your name, email address, payment details or any other personal information about you, and we make no attempt to connect a commission report to a reader.

5. Who your data is shared with

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not transfer it to data brokers, advertisers or anyone else for their own purposes.

The only parties involved in processing are the service providers named in section 3 — our host and the three resource providers — each acting for the narrow technical purpose described there. Some are based outside the EEA and the UK, so where personal data such as an IP address reaches them, that transfer relies on the safeguards those providers maintain, typically Standard Contractual Clauses or an adequacy decision.

6. Your rights

Depending on where you live, you have rights over personal data relating to you. In our case the honest answer is usually that we hold nothing about you at all — unless you have emailed us, in which case we hold that correspondence and nothing more.

If you are in the EEA or the UK

Under the EU GDPR, and the UK GDPR for readers in the United Kingdom, you may request access to your data, correction of it, erasure, restriction of processing, portability, and you may object to processing carried out on the basis of legitimate interests.

You also have the right to complain to the data protection authority in your own country — each EEA state has one, and in the United Kingdom it is the Information Commissioner's Office.

If you are in California

Under the CCPA as amended by the CPRA you may request disclosure of the categories of personal information collected, deletion, and correction, and you may opt out of sale or sharing.

We do not sell or share personal information, so there is nothing to opt out of. Exercising any right will never result in worse treatment.

To exercise any of these, email editorial@vpntruthlab.com. We will respond within one month. Because we hold so little, the usual answer is that we have nothing on file — and we will say so plainly rather than ask you to prove who you are for no reason.

7. Do Not Track and Global Privacy Control

There is no tracking on this site for a Do Not Track or Global Privacy Control signal to switch off. We run no browser-side analytics, set no cookies and build no profiles, so honouring such a signal would change nothing about how the site behaves. The aggregate statistics in section 3.2 are produced server-side from requests and are not affected by browser signals — stated here so the position is unambiguous rather than implied.

8. Security

The site is served over HTTPS. It is a set of static files with no database, no user accounts and no login, which removes most of the ways a site of this kind leaks data — there is no store of personal information to breach because no such store exists. Email correspondence is held in a standard mailbox protected by access controls.

9. Children

This site is intended for adults evaluating consumer software. It is not directed at children, and since no personal information is collected from anyone through the site, none is knowingly collected from a child. If you believe a child has sent us information by email, write to us and we will delete it.

10. Changes to this policy

If we add anything that changes what is described here — an analytics package, a contact form, a newsletter, any component that stores something in your browser — this page will be updated before that component goes live, and the effective date at the top will change with it. A privacy policy that quietly stops matching the site is worse than none at all.

Questions about this policy

Email editorial@vpntruthlab.com. If something here is unclear, or looks inconsistent with how the site actually behaves, we would genuinely like to know — an inaccurate privacy policy is a problem for you and for us.