Effective date: January 1, 2025 · Last updated: June 5, 2026
Dombay VPN does not record your VPN traffic, the sites you visit, your DNS queries, connection timestamps, or bandwidth usage. Because we retain none of it, there is nothing historical to hand over. In the rare event of a valid, binding legal order targeting a specific account, we may be compelled to enable narrow, forward-only monitoring of that one account — never the wider community. We publish a warrant canary.
1. Who We Are
Dombay VPN is a censorship-resistant VPN service operated by Kyo.ai Corporation. Our infrastructure is hosted in the European Union, giving all users the protections of the General Data Protection Regulation (GDPR).
Operating company: Kyo.ai Corporation (Kyo.ai KK), established in Japan on 19 September 2019 (share capital ¥15,000,000; principal business: information technology). Registered office: 405 Yamato Building, 1-6-16 Kanda Izumi-cho, Chiyoda-ku, Tokyo 101-0024, Japan. GDPR and privacy contact: inquire@dombayvpn.com.
For privacy inquiries, contact us at: inquire@dombayvpn.com
2. Data We Collect
We collect the minimum data required to provide the service:
- Email address — used for account authentication and subscription management. Collected only if you register with email.
- Phone number — used as an alternative authentication method (OTP). Collected only if you choose phone-based login.
- Payment information — processed by Stripe (for card payments) or handled by our payment partners for crypto/Telegram payments. We do not store full card numbers. Stripe's privacy policy governs their data handling.
- Device identifiers — an anonymous device ID used to link your subscription to your devices. This is not tied to your identity unless you log in.
- Session tokens — authentication tokens stored on your device, used to keep you logged in. Tokens expire after 90 days and are then deleted.
3. What We Do NOT Collect
- VPN traffic content or metadata
- Websites you visit while connected
- DNS queries made while connected
- Connection timestamps or session durations
- Your IP address while using the VPN
- Bandwidth consumed per session
By default our VPN nodes keep no activity logs — no traffic, destinations, DNS, or timestamps — so there is nothing historical to produce. Where a valid legal order compels it, any monitoring is limited to a single named account and takes effect only going forward; it is time-boxed and access-audited. See our warrant canary.
4. How We Use Your Data
- To authenticate your account and validate your subscription
- To process payments and issue activation codes
- To deliver service announcements (critical security notices only — not marketing)
- To respond to support requests you initiate
We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. EU Hosting and GDPR
All Dombay VPN servers are hosted in the European Union (Frankfurt, Germany; Netherlands; Helsinki, Finland). Your data is processed under the General Data Protection Regulation (GDPR).
As an EU-resident user, you have the right to access, correct, or delete your personal data at any time. See Section 8 for how to exercise these rights.
We do not transfer personal data outside the EU/EEA except where required for payment processing (Stripe operates globally under Standard Contractual Clauses).
6. Data Retention
- Session tokens: Active for up to 90 days, then automatically deleted.
- Account data (email/phone): Retained for the duration of your account. Deleted within 30 days of account deletion request.
- Payment records: Retained for 7 years as required by EU financial regulations. Payment details are held by Stripe — not us.
- Support tickets: Retained for 2 years, then deleted.
7. Cookies and Tracking
Our website uses a single first-party cookie to remember your language preference. We do not use advertising trackers, analytics pixels, or third-party tracking scripts on this website.
The Dombay VPN app does not use any analytics SDK, advertising identifier, or tracking library.
8. Your Rights — Right to Deletion
You have the right to request deletion of all personal data we hold about you. To exercise this right:
- Email inquire@dombayvpn.com with subject line "Data Deletion Request"
- Include the email address or phone number associated with your account
- We will confirm deletion within 30 days
You also have the right to access, correct, or port your data. Contact us at the same address.
9. Third-Party Services
- Stripe — payment processing. Stripe's privacy policy: stripe.com/privacy
- Telegram — optional bot-based authentication and payment. Telegram's privacy policy governs your Telegram account data.
- Google Play / App Store — if you install via these platforms, their respective privacy policies apply to the installation process.
10. Children
Dombay VPN is not directed at children under 16. We do not knowingly collect data from anyone under 16 years of age. If you believe we have inadvertently collected such data, please contact us for immediate deletion.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email (if we have your address) and by posting an updated version on this page with a new effective date. Continued use of the service after changes constitutes acceptance.
12. Contact
For all privacy-related questions and data requests: inquire@dombayvpn.com
We aim to respond to all privacy requests within 5 business days.