LEGAL
Privacy Policy
This policy explains exactly what StreamShield VPN records about you, what it deliberately does not record, why, and how to get your data removed. It is written to be accurate rather than flattering.
EFFECTIVE AUGUST 9, 2026
The short version
We do not log your activity. We do not record the sites you visit, the services you stream, the DNS names you look up, or the contents of your traffic. There is no record anywhere in our systems of where you went while connected.
We do keep a limited amount of connection metadata — when a session started and ended, which server it used, how many bytes moved, and the IP address your device connected from. We keep it because your plan limits how many devices can be connected at once, and enforcing that limit requires knowing which sessions are open. We are telling you this rather than claiming a blanket “zero logs” policy that our systems would not support.
| Data | Do we hold it? | Why / why not |
|---|---|---|
| Websites, apps and services you connect to | NO | Never recorded, inspected, or stored at any layer of the service. |
| DNS queries | NO | Not logged by us. See the DNS section below — resolution is handled by third-party resolvers, not by StreamShield. |
| Contents of your traffic | NO | Encrypted in transit and never inspected, decrypted, or stored. |
| Bandwidth totals per session | YES | Byte counters reported by the VPN server, used for capacity planning and abuse detection. |
| Source IP address of your connection | YES | Recorded when a session opens, so simultaneous-connection limits can be enforced and abuse can be investigated. |
| Session start and end times, and the server used | YES | Required to enforce your plan’s connection limit and to operate the network. |
| Payment card numbers | NO | Handled entirely by the payment processor. We never see or store card details. |
1. Who this policy covers
“StreamShield VPN”, “we”, and “us” means the operator of the StreamShield VPN service and the streamshieldvpn.net website and applications. “You” means anyone who uses the service, visits the site, or holds an account.
Questions about this policy, or about the data we hold on you, go to [email protected].
If you bought through a reseller. StreamShield is sold both directly and through independent resellers who operate under their own branding. If you got your account from a reseller, that reseller administers your account and holds your customer details independently of us. Their own privacy practices apply to the relationship between you and them, and we do not control them. We provide the underlying network and hold the account and connection data described below. See Section 12 of the Terms.
2. What we do not collect
We do not record, and therefore cannot disclose to anyone:
- The websites, servers, or services you connect to through the VPN.
- Your browsing, streaming, or download history.
- The contents of your traffic, messages, or files.
- DNS lookups made while you are connected.
- The IP addresses you were assigned inside the tunnel, mapped to the destinations you visited.
We do not sell personal information, and we do not share it with advertisers or data brokers.
3. What we do collect
Account information
- A username, and a password stored only as a cryptographic hash.
- An activation PIN, for accounts that sign in to the app with a PIN rather than a password.
- An email address, where you provide one. It is optional for end-user accounts, and is used for account notices, config delivery, receipts, and password resets. Verification links are stored only as hashes.
- Plan, expiry date, connection allowance, and last sign-in time.
- An avatar image, if you upload one.
Connection metadata
Each time a device connects to a VPN server, we record the server used, the certificate name of the device, the time the session opened and closed, the number of bytes sent and received, the IP address your device connected from, and — if the session was closed by us — the reason.
The reason is enforcement. Plans are sold with a fixed number of simultaneous connections, and that limit is enforced strictly: when you exceed it, the oldest open session is disconnected. That is not possible without a live record of which sessions are open and when they started. The same records are used to investigate abuse reports and to size the network.
This is metadata about the connection, not about what you did with it. It records that a device connected, not where it went.
Device records
The devices you register, the names you give them, when each was last seen, and the client certificates issued to them. Certificate private keys are encrypted at rest.
Payment information
Payments are processed by third-party payment providers. Card numbers, bank details, and equivalent payment credentials go directly to that provider and are never transmitted to or stored on our systems.
We store the order record: amount, currency, description, provider, the provider’s reference identifiers, and the times of payment or refund. Order records outlive account deletion because we need them for accounting, tax, refunds, and chargeback disputes.
Support tickets
When you open a support ticket we keep the subject, the messages, any files you attach, and the account they relate to. Do not put passwords or payment card details in a ticket.
Administrative audit logs
Actions taken in the management panel — account creation, plan changes, suspensions, billing changes, and similar — are recorded with the acting account, the action, the affected record, and the IP address the action came from. These logs exist so that changes to accounts and money are attributable, and they primarily concern administrators and resellers rather than end users.
Server-side operational logs
The VPN servers themselves keep standard OpenVPN operational logs and a status file covering connection and disconnection events, for diagnosing faults. These are connection-level records of the same kind described above; they do not contain browsing activity or traffic contents.
4. DNS
When you connect, our servers instruct your device to use public DNS resolvers operated by Cloudflare (1.1.1.1) and Google (8.8.8.8). We do not run our own resolver and we do not log your queries — but this does mean your DNS lookups are answered by those third parties, subject to their own privacy policies, rather than by StreamShield.
You can override the DNS servers your device uses if you would prefer a different resolver.
5. Why we hold this data
We use the data described above only to:
- Provide the service, issue configurations, and authenticate your devices.
- Enforce the simultaneous-connection limit attached to your plan.
- Take payment, issue receipts, process refunds, and prevent payment fraud.
- Answer your support requests.
- Investigate abuse of the network — such as attacks launched through it — and enforce our Acceptable Use Policy.
- Keep the network secure, available, and adequately provisioned.
- Meet legal and accounting obligations.
Where the GDPR or similar law applies, our legal bases are: performance of our contract with you (providing and billing for the service), our legitimate interests (network security, abuse prevention, and capacity planning), your consent (optional marketing email, where offered), and compliance with legal obligations (tax and accounting records).
7. Legal requests and law enforcement
We respond to valid legal process. We can only produce data that exists, and what exists is described in Section 3. We cannot produce browsing history, DNS records, traffic contents, or a record of what any user did while connected, because we do not have them.
Where we are legally permitted to do so, we will decline overbroad requests and will seek to notify affected account holders.
8. How long we keep it
- Account data is kept for as long as the account exists.
- Connection metadata and device records are kept for the life of the account and are deleted together with it. Deleting an account removes its session history.
- Support tickets, including their messages and attachments, are kept while the account exists and are deleted together with it.
- Order and payment records are kept after account deletion for as long as accounting, tax, and chargeback rules require — normally several years — with the account link removed.
- Revoked certificate records outlive the account. The serial number of every revoked certificate stays on our revocation list — that is what stops an old configuration file from working — and the certificate name contains the account username.
- Administrative audit logs are kept as a security record, so that changes to accounts and billing remain attributable. The acting account is unlinked when a user is deleted, but an entry may still name the account it concerned.
- Encrypted database backups are retained on a rolling schedule — daily backups for 14 days and monthly backups for 12 months — so deleted data can persist in backups until those expire.
9. Deleting your account and your data
You can ask us to delete your account at any time, and we will actually delete it. We do not satisfy a deletion request by suspending the account, disabling sign-in, or marking it inactive — the account record itself is removed.
How to ask
Use the form at streamshieldvpn.net/data-deletion, which works without signing in and without the app installed, or email [email protected] with the username on the account.
We verify that the account is yours before deleting anything — normally by replying to the address on the account, or by asking for a detail only the account holder would know. The request form is open to anyone, and deletion is irreversible, so this step is not optional. If we cannot verify the request, we will not act on it.
We aim to complete deletion within 30 days of receiving the request, and we will tell you when it is done.
What deletion removes
Your account record — username, email address, password hash, activation PIN, plan, expiry, and avatar — along with your entire connection and session history, your registered devices and their credentials, your support tickets and their attachments, and every sign-in, refresh, password-reset and email-verification token. Your VPN certificates are revoked, so configuration files already on your devices stop working, and any live subscription is cancelled so you are not charged afterwards.
What we keep, and why
A limited set of records survives deletion, kept only where the law requires it or where destroying it would create a security or fraud problem:
- Order and payment records, detached from your account, for accounting and tax compliance and to handle refunds and card chargebacks that can be raised long after a purchase.
- Revoked certificate serial numbers, so a configuration file copied off a device before deletion cannot be used again. These carry the account username. This is a security measure, and removing it would undo the deletion it accompanies.
- Administrative audit entries, so changes to accounts and money remain attributable and fraud can be investigated.
- Encrypted backups, until they expire on the rolling schedule in section 8. Deleted data is gone from the live system at once but persists in backups until those are destroyed.
- A record that you asked, so we can demonstrate the request was honoured.
We keep nothing beyond what those purposes require, and we do not use any of it to re-create your account or to market to you.
Accounts bought from a reseller. If a reseller sold you your subscription, they administer your account and hold their own customer records that we do not control. Send your request to us and we will delete what is in our systems and pass it to the reseller, but you should contact them directly as well.
10. How we protect it
- Traffic between you and our servers is encrypted by the VPN tunnel itself.
- Passwords are stored only as salted hashes, never in a recoverable form.
- Session, refresh, and email-verification tokens are stored as hashes, so a database disclosure does not hand over usable tokens.
- Certificate private keys are encrypted at rest with authenticated encryption.
- Database backups are encrypted and stored off-site.
- Administrative access is role-based, and privileged actions are recorded in the audit log.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any required regulator within the timeframes the law sets.
11. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent you previously gave.
To exercise any of these, email [email protected] from the address on your account, or open a support ticket from within your account. We will respond within the period required by applicable law, normally 30 days. We may need to verify your identity first, and we may keep records we are legally required to retain, such as payment history.
For deletion specifically there is a dedicated form at streamshieldvpn.net/data-deletion, which works even if you can no longer sign in. What it removes and what we keep is set out in section 9.
If your account was sold to you by a reseller, ask them as well — they hold their own customer records that we do not control.
California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.
EEA and UK residents: you also have the right to lodge a complaint with your local data protection authority.
12. International transfers
Our servers and service providers are located in a number of countries, and using a VPN necessarily means routing your connection through a server in the location you choose. Your data may therefore be processed outside the country you live in, including in countries whose data protection laws differ from your own. Where required, we rely on appropriate safeguards such as standard contractual clauses with our providers.
The analytics described in section 14 are processed by Google in the United States. This applies to visits to our public pages only.
13. Children
The service is not directed to children and is not for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact [email protected] and we will delete it.
15. Changes to this policy
We may update this policy as the service changes. The effective date at the top always reflects the current version. If a change materially reduces your privacy — for example, if we began collecting a new category of data — we will give notice by email to account holders who have provided an address, or by a notice in the panel, before it takes effect.
16. Contact
- Privacy questions, data requests, and general support: [email protected]
- Network abuse reports: [email protected]
- Copyright notices: [email protected] or [email protected]