Privacy Policy
How we protect your privacy with minimal data collection and a strict no-logs policy
Last updated: August 6, 2026
Our Core Promise
We never store any activity logs of any kind. LookerVPN was built from the ground up to collect as little data as possible. We use anonymous account numbers—no email, no password, no personal information required.
What We DON'T Collect
Unlike most online services, we intentionally avoid collecting common personal information:
- No email addresses - Your account is identified solely by a randomly generated 16-digit number
- No names or personal identifiers - We don't know who you are
- No browsing history - We do not log, monitor, or store websites you visit
- No connection timestamps - We don't record when you connect or disconnect
- No IP addresses - Neither your original IP nor assigned VPN IP is logged
This is about the VPN service. Requests to this website pass through edge security logging that does record an IP for a short period — see Server & Infrastructure Data below. - No bandwidth logs - We don't track data transfer amounts
- No DNS queries - Your DNS requests are not recorded
- No traffic content - We cannot see what you send or receive
What We DO Collect
We collect only the minimum data necessary to operate our service:
Account Data
| Data | Purpose | Retention |
|---|---|---|
| Account number (16 digits) | Account identification | Until account deletion |
| Account status & expiry date | Service access control | Until account deletion |
| WireGuard public keys | VPN connection authentication | Until device deletion |
| Device names (user-defined) | Device management | Until device deletion |
Payment Data
| Payment Method | What We Store | Retention |
|---|---|---|
| Credit Card (Stripe) | Payment token, amount, date (Stripe stores card details per their policy) | Transaction IDs deleted after 22 days |
| Bitcoin (BTC) | Amount, date, transaction ID | Transaction IDs deleted after 22 days |
| Monero (XMR) | Amount, date, transaction hash | Retained to prevent double-crediting (Monero's privacy features require this) |
Server & Infrastructure Data
| Data | Purpose | Retention |
|---|---|---|
| Aggregate connection counts | Server load monitoring | Real-time only, not stored |
| Server performance metrics | Infrastructure health | Aggregated, no user data |
| Web server access logs | Security & debugging | Maximum 5 minutes |
| Edge security logs (CloudFront/WAF, includes your IP address) | Abuse detection & edge banning | 7 days |
| Edge security aggregates (no IP address) | Attack pattern analysis | 90 days |
This applies to the lookervpn.com website, not to the VPN service. The edge security logs above record requests to this website — the same protection any site needs against scraping and attack. They have nothing to do with your VPN connection. We create no connection logs of any kind; see the No-Logs Policy below.
No-Logs Policy
We maintain a strict no-logs policy for VPN connections. This means:
- We do not log your VPN connection activity
- We do not monitor the content of your internet traffic
- We cannot identify what websites you visit or what data you transmit
- We cannot correlate any activity to any account number
- We have no data to provide to third parties—because that data doesn't exist
Technical Implementation: Our VPN servers are configured to write logs to /dev/null—literally discarding all connection information. Even our own engineers cannot access user activity data because it is never created.
Data Retention Summary
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion requested |
| Payment transaction IDs | 22 days (except Monero) |
| Support emails | 90 days |
| Web server logs | 5 minutes maximum |
| Edge security logs (website only, includes IP) | 7 days |
| Edge security aggregates (website only, no IP) | 90 days |
| VPN activity logs | Never created |
Website Analytics
Our website (not the VPN service) currently uses no third-party analytics service. We do not load any external analytics script, and we do not send your activity to any analytics vendor.
If we introduce website analytics in the future, it will be a privacy-respecting, cookieless solution under our own control that measures aggregate traffic only — never tracking individual visitors across sessions or other websites. We will update this policy before any such service goes live.
You can manage your cookie choices at any time through our Cookie Preferences page.
Third-Party Services
We use the following third-party services:
- Stripe - For credit card payment processing. Stripe stores card details per their privacy policy. We only receive payment confirmation.
- Cryptocurrency networks - Bitcoin and Monero transactions are processed on their respective public blockchains.
- Amazon Web Services (AWS) - For website hosting. Standard web server logs may be collected temporarily for security.
Law Enforcement Requests
If we receive a valid legal request from law enforcement, we can only provide the data we actually have:
- Whether an account number exists
- Account status and time balance
- Payment confirmations (no personal data for crypto payments)
We cannot provide:
- Browsing history or connection logs (we don't have them)
- IP addresses used (we don't log them)
- Bandwidth or data transfer information (we don't track it)
- Any activity correlation (it's technically impossible)
Data Security
We implement industry-standard security measures to protect the limited data we do collect:
- All data is encrypted in transit using TLS/SSL
- Our servers are secured and regularly updated
- Access to user data is strictly limited to essential personnel
- We use WireGuard protocol, providing state-of-the-art cryptographic security
Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal data:
- Right to access - Request information about what data we hold (which is very little)
- Right to deletion - Request that we delete your account and all associated data
- Right to portability - Request a copy of your data in a portable format
To exercise these rights, contact us at support@lookervpn.com.
Children's Privacy
Our Services are not intended for children under the age of 18. We do not knowingly collect personal information from children under 18.
International Data Transfers
Our servers are located in multiple countries to provide optimal VPN performance. Since we collect virtually no personal data, the privacy implications of these transfers are minimal.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced on our website at least 30 days before taking effect. Your continued use of our Services after changes take effect constitutes acceptance of the revised Privacy Policy.
Contact Us
The data controller responsible for your information under this Privacy Policy is Looker VPN Inc., the operator of LookerVPN. If you have any questions about this Privacy Policy or wish to exercise your rights, you can reach us at:
Looker VPN Inc.2 W Dry Creek Cir, Ste 100
Littleton, CO 80120-4479, USA
Email: support@lookervpn.com