Privacy Policy
Last updated 1 October 2026
Teal VPN is operated by Fxolio LLC, a Wyoming limited liability company (“we”, “us”). This policy explains exactly what we collect, what we deliberately do not collect, and why. It is written to be read, not to be survived.
The short version. We do not log the sites you visit, the addresses you connect to, or the contents of your traffic, and we do not store the IP address you connect from. We keep the minimum needed to run your account: the sign-in it belongs to (Google, Apple or an email address), your device’s public key, and how much data the account has used. We never sell, use or disclose any of it to anyone for any other purpose.
1. What we collect
Account information
- Your sign-in identifier and email address. You sign in with Google, with Apple, or with an email address and a one-time code. From Google or Apple we receive the identifier they issue for you and the email address on that account — for Sign in with Apple this may be the private relay address Apple creates for you, which we treat like any other address. We do not receive your name, photo, contacts or password. If you sign in with Apple, we also keep, encrypted, a token Apple issues, so that when you delete your account we can tell Apple to disconnect Teal VPN from your Apple Account. For email sign-in we keep the address you typed; the one-time code is scrambled at rest and expires in ten minutes.
- An account number. A reference we generate so support can find your account. It is not a password and cannot be used to sign in.
- Your plan and account status (Free or Pro, active or closed).
Device information
- Your device’s public key. The matching private key is generated on your device and never transmitted to us. We could not produce it if asked.
- A device label, platform and app version (for example “Android” or “iPhone”), so you can recognise and remove your own devices, and so we can retire versions with known problems. The label is the device model, never a name you gave the device.
- A scrambled device code — Free plan only. The Free plan is one per person and per phone. To enforce that, the app sends a one-way scrambled code derived from an identifier the phone gives to this app alone (on Android) or from a random value the app creates once and keeps to itself (on iPhone and iPad). We scramble it again with a secret key before storing it. We cannot turn it back into a device identifier, it is not an advertising identifier, and it is never used for tracking. The same code lets a phone that reinstalls the app keep its own device slot instead of using up a second one. Paying accounts are not recorded this way.
- On iPhone, iPad, and Mac: Apple DeviceCheck — Free plan only. When a Free plan starts on an iPhone, iPad, or Mac, we ask Apple to set one “Free plan already used” mark for that device, using Apple’s DeviceCheck service. Apple keeps this mark for our app only; it survives reinstalling the app and erasing the device. We receive only yes or no — no device identifier, and nothing that identifies you. We do not store the one-time token the device uses to ask Apple.
Usage figures
- Total bytes transferred per account and per device, to enforce plan limits. This is a number, not a record of what was transferred or where it went.
- When a device’s registration expires, so devices that are no longer used are removed automatically.
- A flag if an account appears to be shared beyond its device allowance.
- Which connection port worked on which kind of network. Some mobile networks block certain ports. When a connection succeeds, the app reports the port and the network type (Wi-Fi, or the code of the mobile operator) so other people on that network connect faster. This is kept as a counter only. It is not linked to your account or device.
Used for a moment, never stored
- Your IP address and the country it resolves to are used while a request is being handled — to limit abusive request rates and to apply the country restrictions in our Terms of Service. The address is held in memory for at most about a minute for rate limiting and is not written to our database or our logs. A daily counter of new sign-ups per network uses a scrambled value that cannot be turned back into an address and is discarded after a day.
Checking that the app is genuine
- The Android app may ask Google Play to confirm that it is the unmodified app, installed from Google Play, on a genuine device (the Play Integrity service). Google processes that request under its own privacy policy. We receive only the result, and we keep daily totals of results — nothing tied to your account.
- The iPhone and iPad app may ask Apple for the same confirmation (the App Attest service). We keep the public half of a key Apple certifies for that install and a counter; neither identifies you or your device to anyone else.
2. What we do not collect
- We do not log the websites, services or IP addresses you connect to through the tunnel.
- We do not store the IP address you connect from.
- We do not log DNS queries. Name lookups are answered by the VPN server itself and are not written to disk.
- We do not inspect, record or store the contents of your traffic. It is encrypted between your device and the exit server.
- We do not use advertising identifiers, analytics SDKs, trackers or fingerprinting in the app.
- We do not sell, rent or share personal information with data brokers or advertisers. Ever.
3. Payments
Teal Pro is bought through Google Play in the Android app and through the App Store in the iPhone and iPad app. Google and Apple handle your payment details under their own privacy policies; we receive a record that a purchase is valid (the product, its dates and a random tag we gave your account), so we can switch your plan on and off. We never receive or store your card number.
4. Why we are allowed to hold this
Where the GDPR or similar laws apply, we rely on: performance of a contract (running the account you created), and legitimate interests (preventing abuse and fraud, and keeping the service available to everyone). Where we rely on consent, you may withdraw it at any time.
5. How long we keep things
- Account and device records: for as long as the account exists. A device you stop using is removed automatically when its registration expires.
- When you delete your account (in the app, under Account → Delete account, or as described on our account deletion page): your account, devices and sign-in sessions are deleted immediately.
- One thing outlives deletion, briefly: if the account was on the Free plan, the scrambled device code keeps the amount of data used that day until the next daily reset, so that deleting and re-creating an account is not a way to refill the allowance. It carries no link to you, and it is deleted after that reset.
- On iPhone and iPad, Apple’s “Free plan already used” mark (see section 1) is kept by Apple, not by us, and is not removed when you delete your account: a device that has had a Free plan does not get a second one. It carries no link to you or your account.
- Purchase records we are legally required to retain, such as transaction records kept for tax purposes, are kept for the period the law requires. Deleting your account does not cancel a subscription: cancel it in Google Play or in your App Store settings first.
6. Who we share with
We use: hosting providers for our VPN servers (who necessarily carry the encrypted traffic, and cannot read it); Cloudflare, which carries requests to our website and account service; Google, for sign-in, for checking that the Android app is genuine, and for Google Play payments; Apple, for Sign in with Apple, for checking that the iPhone app is genuine, for the one-per-device Free plan mark (DeviceCheck), and for App Store payments; and Resend, which delivers the one-time code when you sign in by email and sees your address for that purpose only. We do not give any of them your browsing activity, because we do not have it.
Our commitment. We do not sell, use or disclose any data we hold about you to third parties for any purpose other than running the service as described on this page. Each provider named above receives only what its part of the service needs and may use it only for that, under terms at least as protective as this policy.
We will disclose information if compelled by a valid legal order binding on Fxolio LLC. We can only ever produce what we actually hold, which is described above. We cannot produce browsing history, traffic contents or connection IP addresses, because we do not have them.
7. Your rights
You may request a copy of your data, ask us to correct it, or delete your account and its data. Deleting is immediate from the app (Account → Delete account); if you cannot use the app, see our account deletion page. You can also withdraw the permission you gave Google or Apple for sign-in in your Google or Apple account settings; when Apple tells us you have, every session and device on the account is signed out at once. For anything else write to [email protected] from the email address on the account. Depending on where you live you may also have the right to complain to a data protection authority.
8. Children
Teal VPN is for adults. It is not directed at anyone under 18, and we do not knowingly collect their personal information. If you believe a minor has created an account, contact us and we will delete it.
9. International transfers
We are a United States company and our servers are located in several countries. Using the service necessarily involves your data being processed in the country whose server you select, and in the United States.
10. Changes
If we change this policy in a way that materially affects you, we will post the new version here with a new date and, where appropriate, tell you in the app before it takes effect.
11. Contact
Fxolio LLC
Privacy enquiries: [email protected]
Abuse and legal notices: [email protected]