Privacy Policy
Last updated January 27, 2026
1. Introduction
VoidPort ("Service"), operated by VoidMind ("we", "us", or "our"), is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR).
This policy covers the website and dashboard at voidport.app, the API at api.voidport.app, downloads from dl.voidport.app, and the relay servers that serve tunnel addresses under voidport.net.
2. Data Controller
VoidMind
Christian Romeni
Holzwasen 11
73087 Bad Boll, Germany
Email: privacy@voidport.app
3. Data We Collect
Account Information
- Email address (required for account creation)
- Password (stored as a secure hash)
- Payment information (processed by Stripe, not stored by us)
Usage Data
- Tunnel configurations (port, protocol, name)
- Bandwidth usage statistics
- Connection counts and timestamps
- IP addresses of relay connections
Technical Data
- Browser type and version
- Device information
- Log data (errors, access times)
4. How We Use Your Data
We use your data to:
- Provide and maintain the Service
- Process payments and manage subscriptions
- Monitor usage against plan limits
- Detect and prevent abuse or fraud
- Send service-related communications
- Improve and optimize the Service
- Comply with legal obligations
5. Legal Basis for Processing
We process your data based on:
- Contract: To provide the Service you requested
- Legitimate Interest: For security, fraud prevention, and service improvement
- Legal Obligation: To comply with applicable laws
- Consent: For optional communications (you may withdraw consent at any time)
6. Data Sharing
We may share your data with:
- Stripe: For payment processing
- Hetzner: For infrastructure hosting (servers in Germany)
- Cloudflare: For web hosting and CDN services
We do not sell your personal data to third parties. We may disclose data if required by law or to protect our rights.
7. Data Retention
- Account data: Until you delete your account
- Usage statistics (bandwidth, connections): 90 days rolling window
- Connection metadata (IP, timestamps): 14 days for abuse handling
- Payment records: As required by tax law (typically 7-10 years)
- Server logs: 30 days
8. What We Do NOT Collect
As a transport provider, we explicitly do NOT:
- Inspect or log the content/payload of your traffic
- Perform deep packet inspection (DPI)
- Analyze or profile your transmitted data
- Store any content passing through tunnels
- Sell or share data with advertisers
We only collect the minimum metadata necessary to operate the service and respond to abuse reports.
9. Your Rights (GDPR)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Delete your account and data
- Portability: Receive your data in a structured format
- Object: Object to certain processing
- Restrict: Limit how we use your data
- Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@voidport.app.
10. Data Security
We protect your data with:
- TLS 1.3 encryption for all connections
- Bcrypt password hashing
- Database encryption at rest
- Regular security audits
- Access controls and monitoring
11. International Transfers
Your data is primarily processed within the European Union (Germany). If data is transferred outside the EU, we ensure adequate safeguards are in place (e.g., Standard Contractual Clauses).
12. Cookies
We use essential cookies for authentication and session management. We do not use tracking or advertising cookies.
13. Children's Privacy
The Service is not intended for users under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us immediately.
14. Changes to This Policy
We may update this policy periodically. We will notify you of material changes via email or dashboard notice. Continued use of the Service after changes constitutes acceptance.
15. Contact & Complaints
For privacy inquiries: privacy@voidport.app
You have the right to lodge a complaint with your local data protection authority. In Baden-Württemberg, Germany, this is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg.