Privacy Policy
Effective May 14, 2026.
This document describes what personal data Personal Service (the “Service”) collects from its users, the purposes for which it is processed, and the third parties it is shared with. The Service is operated by an individual freelancer registered in the United Arab Emirates. The governing law is UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (the UAE PDPL). For users located in the European Union, the United Kingdom, or another jurisdiction with its own data protection regime, the relevant local law (GDPR / UK GDPR / etc.) applies in addition.
1. Personal data we collect
| Category | What exactly | Why |
|---|---|---|
| Identification | Email address, password (stored as a bcrypt hash only), interface language | Account creation and sign-in |
| Payment metadata | Stripe transaction id, amount, timestamp. We never receive or store card numbers — payment happens entirely on Stripe's side | Order accounting, UAE tax reporting, fraud detection |
| VPN usage | Traffic consumed, last-connect timestamp, key UUID | Quota enforcement, subscription renewal |
| Technical | IP address, user agent, log timestamps | Security (rate limiting, audit), incident diagnostics |
| Support | Content of your support-chat messages and any uploaded screenshots | Resolving your enquiry; translation of your message into Russian for the operator via OpenAI |
| Referrals | Who invited whom, credited bonuses | Operating the referral programme |
We do not collect: the contents of your VPN traffic, the websites you visit, DNS queries, banking details, ID documents.
2. Third-party processors
| Processor | Data shared | Jurisdiction |
|---|---|---|
| Stripe | Email, amount, transaction id | United States / European Union (Stripe Payments Europe) |
| OpenAI (gpt-5-nano) | Message content for translation and FAQ-grounded suggestions; your language code | United States |
| SMTP provider (Brevo) | Email address, transactional email subject and body | European Union (France) |
| Remnawave (VPN back-end) | Generated username, UUID, quota | Same data centre as the application |
| Hosting provider | All operational data (physical storage) | UAE / European Union |
| GitHub | Application source code only — no user data is hosted there | United States |
| Sentry (optional) | Error stack traces; no email or IP by default | United States |
| Google Analytics 4 (Firebase Analytics) | De-identified events: page views, "begin checkout" clicks, completed purchases, support events. IP is anonymised. Loads only after you accept cookies in the consent banner. | United States / EU (Google Ireland) |
| Meta Pixel (Facebook/Instagram, optional) | Used only when paid ad campaigns are active. Same set of de-identified events as GA4: page view, begin checkout, purchase. Loads only after you accept cookies. | United States / EU (Meta Platforms Ireland) |
3. Retention
- Active accounts — for as long as the subscription is active and you keep using the Service.
- Inactive accounts (no sign-in for 12 months and no active subscription) are automatically deleted. If paid orders exist in the account's history, we anonymise the profile instead of full deletion — email/password/last-login fields are replaced with opaque placeholders, while the financial trail is retained to satisfy UAE tax-reporting requirements.
- Payment records — 5 years from the transaction date (UAE tax retention).
- Security logs (sign-in audit, IP addresses) — 90 days.
- Database backups — 30 days.
4. Your rights
Under UAE PDPL and GDPR you have the right to:
- Obtain a copy of your personal data (right of access).
- Correct inaccurate data (right to rectification).
- Request deletion of your account (right to erasure / “right to be forgotten”). Where paid orders exist, we anonymise the profile instead of full deletion to comply with tax-retention rules.
- Object to processing and unsubscribe from emails.
- Receive your data in a machine-readable format (data portability).
- Lodge a complaint with the supervisory authority in your country (EU: your national DPA; UAE: the UAE Data Office).
To exercise any of these rights, write to [email protected] from the email address linked to your account. We respond within 30 days.
5. Cookies
We use the following cookies:
- Strictly necessary (always): session (sign-in), CSRF token, chosen UI language, theme.
- Analytics (only with your consent): Google Analytics 4 / Firebase Analytics. On your first visit we show a consent banner with "Accept" / "Decline". Until you explicitly accept, Google runs in Consent Mode v2 — no events are stored and no identifiers are written.
6. Security
All traffic is served over HTTPS with HSTS. Passwords are stored as bcrypt hashes. Database access is restricted by SSH keys. Admin actions are recorded in an audit log. Payment and Remnawave calls happen server-to-server — never via the user's browser.
7. Children
The Service is not intended for individuals under 18. By creating an account, you confirm that you are of legal age.
8. Changes to this policy
Material changes will be announced by email at least 14 days in advance. Minor edits are published on this page with the updated effective date.
9. Contact
All privacy enquiries and data-subject requests: [email protected].