LEGAL · LAST UPDATED AUGUST 2026

Privacy Policy

We don't sell your data, and we don't log the sites you visit. Here's exactly what we do keep, who we share it with, and for how long.

Roamly is a privacy tool. We treat your data the same way we'd want ours treated: kept only when there's a real reason, encrypted in transit, deleted when no longer needed, and never sold.

The honest summary: No VPN with real servers can be "zero log." Every operator keeps some logs to run the service and respond to abuse. Anyone claiming otherwise is marketing, not engineering. We tell you exactly what we keep, why, and for how long. That's the deal.

Who we are

Roamly is operated by an independent vendor accessible at roamlyvpn.com. Contact: [email protected]. For legal/abuse matters: [email protected].

Data we collect

1. Account information

Roamly has no passwords. You sign in only with Sign in with Apple or Sign in with Google, so we never receive, store, or reset a password of yours. From that sign-in we keep:

  • Your email address, or the relay address Apple gives us if you chose "Hide My Email". If no address is provided at all, we generate an internal placeholder instead.
  • The provider account identifier (Apple or Google), so we can recognise you on your next sign-in
  • Your name, only if the provider sends it to us
  • Account creation date, last sign-in date, and the IP address used at sign-in

2. Connection logs (while you're using the VPN)

When you connect, we record session metadata to run the service, prevent abuse, and meet lawful disclosure obligations:

  • Connection start time, end time, and session duration
  • The server you connected to and the exit IP we assigned you
  • Your originating IP address at session start, and at disconnect
  • The country your connection came from, and the app version and device type that connected
  • The public half of your device's WireGuard key, which is what identifies your tunnel to the server

To be direct about one thing: we keep your originating IP in full for the retention period below. We do not shorten or mask it. Storing it is what lets us answer a lawful request or trace abuse back to a session, and pretending otherwise would be the kind of claim this page exists to avoid.

We do not keep a log of the websites or domains you visit. We record the connection metadata above, not your browsing. Our threat protection (below) blocks known-malicious domains at the DNS level without recording the sites you request. This data is recorded only at our WireGuard exit servers, and we use it for debugging connection issues, identifying abuse, and responding to lawful requests.

What we DO NOT collect:
  • URL paths, query strings, form submissions, or search terms
  • Page titles or page contents
  • Any browsing activity when the VPN is disconnected
  • Data from traffic that doesn't pass through the Roamly tunnel
The Roamly app does not read or report the URLs you visit — traffic is carried inside an encrypted WireGuard tunnel.

3. Built-in threat protection

While you are connected, DNS queries inside the tunnel are answered by a filtering resolver on the exit server. It blocks domains on our threat list, which is built from public threat intelligence feeds covering phishing and malware domains, plus anything we add manually after an abuse report. Queries that are not on the list are forwarded to Quad9 (9.9.9.9), a security-focused public resolver that blocks additional known-malicious domains on its own.

This filtering is always on and applies to every connected user. We do not record which domains you requested, or which ones were blocked. To be precise about what this feature is and is not: it blocks known-malicious destinations. It is not an ad blocker or a tracker blocker, and we do not advertise it as one.

4. Payment data

Purchases are made through Apple In-App Purchase. Apple processes the transaction and handles billing and receipts. We never see your card number or payment details. We receive Apple's purchase confirmation (transaction identifier, the product you bought, and the renewal or expiry date) so we can activate and maintain your plan, plus the IP address and device the purchase was made from as a fraud record.

5. Device information

To run sessions, provide support, and (if you allow notifications) send service alerts, the app registers your device with your account. This may include:

  • A random device identifier generated locally on your device. It contains nothing about you or your hardware, but it is stored in the iOS Keychain, which means it survives deleting and reinstalling the app. We keep it that way so that a device banned for abuse cannot return with a fresh install or a new account.
  • Device model, iOS version, and app version
  • Your device's language and region, used to decide which service notifications to send
  • A push notification token (only if you enable notifications)

This carries no browsing data. We use it to operate your account's sessions, support, optional notifications, and abuse enforcement.

Advertising measurement

We advertise Roamly, and we measure whether those ads work. This is the one place where data about you leaves us for a non-operational reason, so here it is in plain terms.

When you create an account, when you buy a subscription, and when a subscription renews, our server sends a single event to Meta (Facebook/Instagram) through their Conversions API. That event contains:

  • Your email address, hashed with SHA-256 before it leaves our server (we never send it in readable form). If your address is an Apple private relay address, it is still hashed and sent.
  • Your first and last name, if Apple or Google gave them to us at sign-in, each hashed the same way
  • Your country (the two-letter code only, hashed), taken from your device locale or connection
  • Your IP address and browser/app user agent at that moment, which Meta uses for matching
  • An account identifier of ours, also hashed
  • For purchases and renewals, the amount, currency, and which plan was bought

Meta uses this to tell us that an ad led to a signup or a sale, and to improve ad targeting on their platform. What is never sent: your VPN activity. No connection logs, no session times, no exit IPs, no DNS queries, no indication that you connected at all. The events fire on account creation, purchase, and renewal, nothing else.

There is no Meta, Google, or other advertising SDK inside the Roamly app. On the device we use Apple's SKAdNetwork, which reports install and purchase signals to ad networks anonymously through Apple, without an advertising identifier and without an App Tracking Transparency prompt.

Don't want this? Email us at [email protected] and we will exclude your account from advertising measurement and ask Meta to delete the events already associated with you. Your service is not affected either way.

Data we do not collect

  • The contents of your encrypted traffic (we can't, it's encrypted end-to-end with the destination)
  • Form submissions, message bodies, file uploads/downloads
  • Any browsing, connection, or domain data when the VPN is disconnected, no sites, IPs, or traffic are recorded while you're off.
  • Browsing activity on traffic that doesn't pass through the Roamly tunnel
  • Behavioural advertising profiles built from your VPN usage. Your connection history is never used for advertising, and is never sent to an advertising platform.
  • Your advertising identifier (IDFA). The app never asks for tracking permission and never reads it.

Third parties

This is the complete list of companies that receive any data from us, and exactly what each one gets:

  • Apple: handles Sign in with Apple, and processes In-App Purchases as the seller of record including billing, receipts, and tax. They see your payment details (we don't). They do not see your VPN activity.
  • Google: handles Sign in with Google if you choose it, and delivers push notifications through Firebase Cloud Messaging if you enable notifications. Firebase receives a push token for your device and the notification content, which is limited to service messages. It does not receive your VPN activity.
  • Meta: receives a hashed email address, IP address, and user agent when you create an account or buy a subscription, for advertising measurement. See Advertising measurement above for the full detail and how to opt out. Meta receives no VPN activity of any kind.
  • VPS / WireGuard server providers: operate the actual VPN exit servers. They see encrypted traffic, source and destination IPs, and bandwidth. They do not see your account identity.
  • Hosting provider: hosts our backend and database. Subject to their security and privacy practices.
  • Email delivery provider: delivers the transactional email we send (support replies, service notices). Receives your email address and the message content.

We do not sell your data, and we do not share it with data brokers. Beyond the advertising measurement described above, we do not share anything with advertising networks, and we do not run analytics on your VPN usage.

How long we keep data

  • Account data: until you delete your account. Deletion from the app is immediate and irreversible; backup copies age out within 30 days.
  • Connection logs (times, IPs, exit server): 24 months, then deleted automatically by a scheduled job. An open session is never deleted while it is still running.
  • Email logs (support replies, service notices): 12 months, then deleted automatically.
  • Diagnostic system logs: informational entries are deleted after 12 months. Error and warning entries are kept longer for security review.
  • Payment and audit records: kept for as long as accounting and lawful-disclosure obligations require, typically 5 to 7 years. These survive account deletion, but with your email address removed where the law allows.

Lawful disclosure

We comply with valid legal requests from courts of competent jurisdiction. We do not respond to informal requests, requests from non-governmental parties, or requests from jurisdictions where we have no legal nexus.

We will fight requests we believe are overbroad or fishing. We will publish (anonymized) annual transparency reports beginning in our second year of operation.

Your rights

You may, at any time:

  • Request a copy of all data we hold about you
  • Request deletion of your account and all associated data (subject to legal retention obligations on payments)
  • Correct inaccurate information
  • Object to advertising measurement. Ask us and we will flag your account so no further events are sent to Meta, and we will request deletion of the events already associated with you. Your subscription and service are unaffected.
  • Withdraw consent (which will close your account)
  • File a complaint with your local data protection authority

To exercise any of these: [email protected]. We respond within 14 days.

Security

All app-to-server traffic uses TLS 1.2 or higher. The VPN tunnel itself is WireGuard: your device generates its own private key, that key never leaves your device, and we only ever receive the public half.

There are no user passwords to steal, because sign-in is handled entirely by Apple and Google. Our database is not reachable from the public internet. Exit-server access is key-based SSH only, with password authentication disabled and a host firewall in place. Sensitive values we do store, such as server credentials, are encrypted at rest with AES-256-GCM.

If we discover a data breach, we will notify affected users within 72 hours of confirming it.

Children

Roamly is not directed at children under 16. We do not knowingly collect data from minors. If you believe a minor has registered, please email [email protected] and we will delete the account.

Changes

Material changes to this policy will be announced via email to all active accounts at least 14 days before taking effect. Minor clarifications may be made at any time and noted at the top of this page.

Questions?

Email [email protected]. Real human, usually responds in under 48 hours.