Privacy Policy

Last updated: 7 September 2026

At Fubble VPN, your internet traffic belongs to you. We do not sell your data, we do not show it to advertisers, and we do not use it to build profiles of what you do online. This Policy describes how LUNEXLAB OÜ (“we”, “us”, “our”) processes information when you use Fubble VPN applications, our website at fubblevpn.com, and related products and services (together, the “Services”).

This Policy is written to meet the transparency requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the ePrivacy rules on cookies and similar technologies, and comparable privacy laws. If you do not agree with this Policy, please do not use the Services.

Related documents: Website Privacy Notice, Cookies Policy, Terms and Conditions, and platform notices for Android, iOS, Mac, and Windows.

Summary

  • No-logs VPN. We do not store, monitor, or track the websites you visit, the content of your traffic, DNS queries, source IP paired with a VPN IP, connection timestamps, session duration, or bandwidth used on Fubble-operated VPN servers.
  • We do not sell personal data and we do not share VPN traffic with anyone.
  • The only analytics we use in the apps are Firebase and Google Analytics, for aggregated product statistics (crashes, feature use, stability). They are not used to reconstruct your browsing.
  • If a location has no Fubble-operated server yet, we may temporarily offer a publicly available open VPN endpoint while we roll out a dedicated server for you, typically within minutes. That fallback is optional and is not covered by our no-logs guarantee.
  • You can request access or deletion at [email protected].

1. Who we are (data controller)

The data controller is LUNEXLAB OÜ, an Estonian private limited company, registry code 17218832, registered office: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia.

Privacy and data-subject requests: [email protected]. We have not appointed a Data Protection Officer because our core activity is providing a no-logs VPN and we do not systematically monitor individuals on a large scale. This contact is the channel for all GDPR Article 13/14 queries.

Lead supervisory authority: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — www.aki.ee. You may also lodge a complaint with your local EU/EEA authority.

2. What we do not collect, store, or track

Fubble VPN is designed so that we cannot see how you use the internet through our VPN. On Fubble-operated VPN servers we do not collect, store, or share:

  • Browsing history, visited URLs, or page content
  • DNS queries or resolved domain names
  • The contents of your encrypted or decrypted traffic
  • Connection logs that would link your real IP address to a VPN exit IP, a timestamp, or a user account
  • Session duration, bytes transferred, or originating ISP
  • Precise device location, contacts, photos, files, or microphone/camera data
  • Advertising identifiers used to track you across other companies’ apps or websites for our own marketing
  • Payment card numbers (those stay with Apple, Google, or the store/payment provider you already use)

Because this data is not stored, we cannot produce it in response to a legal request. We can only disclose information we actually hold, as described below.

3. What limited data we may process

You can use much of the Service without telling us who you are. We process only what is needed to run the account, deliver the VPN, support you, and understand app health at an aggregate level.

3.1 Account and authentication

If you create an account or sign in (email, Apple, Google, or Telegram), we may process:

  • Email address and a hashed password (if you use email)
  • An authentication token or user identifier from Apple, Google, Firebase Authentication, or Telegram (we do not receive your third-party password)
  • Optional display name if the sign-in provider sends it
  • A random account/device identifier so we can enforce simultaneous device limits and restore your subscription

Legal basis: performance of a contract (GDPR Art. 6(1)(b)).

3.2 Subscription status

To know whether your app should unlock premium locations, we process a subscription/entitlement status (active, expired, product identifier, expiry date). Purchases are completed in the Apple App Store, Google Play, or another store you choose. We may use RevenueCat only to sync that entitlement with our backend. We do not receive your full card number, CVC, or bank details. RevenueCat does not receive VPN traffic.

Legal basis: contract (Art. 6(1)(b)) and legal obligation for accounting/tax records (Art. 6(1)(c)).

3.3 App statistics — Firebase and Google Analytics only

The mobile and desktop apps share limited technical events with Google Firebase and Google Analytics so we can see whether the app is stable and which screens or features are used. Typical events include app opens, anonymous screen names, crash/error codes, OS version, app version, coarse country (derived by Google from IP at collection time), and device model.

These tools are not used to log VPN destinations, DNS, or traffic. We do not sell this data. We do not combine it with browsing history, because we do not have browsing history.

Legal basis: consent where required by the ePrivacy rules (Art. 6(1)(a)), otherwise our legitimate interest in keeping the product working (Art. 6(1)(f)). You can refuse or reset analytics in OS settings (for example, iOS App Tracking Transparency / Analytics & Improvements, Android advertising ID reset) and, where the app offers it, in-app diagnostics toggles.

Google’s privacy information: Google Privacy Policy and Firebase Privacy and Security.

3.4 Push notifications

If you opt in to push notifications, we store a device push token (via Firebase Cloud Messaging / Apple Push Notification service) so we can send operational messages you requested. Tokens do not reveal your browsing. You can disable notifications in device settings at any time.

Legal basis: consent (Art. 6(1)(a)) and/or contract.

3.5 Support, contact forms, and email

If you email us or submit a contact form, we process the message, your email address, and any diagnostic files you attach. Do not send traffic logs or sensitive content unless you choose to. We may notify our support inbox via email and, internally, via Telegram so we can reply faster.

Legal basis: contract / pre-contractual steps (Art. 6(1)(b)) and legitimate interest in answering you (Art. 6(1)(f)). Marketing email is sent only with consent (Art. 6(1)(a)); you can unsubscribe in every marketing message.

3.6 Website (separate notice)

The website may process truncated server logs for security and, only after cookie consent, Google Analytics and similar measurement cookies. See the Website Privacy Notice and Cookies Policy.

3.7 VPN tools page

If you open /tools, we may see the IP address of the incoming request solely to show you that IP and a boolean whether it matches a Fubble exit node. We do not take a client-supplied IP, and we do not return a server inventory.

The DNS leak check runs in your browser against bash.ws. Your resolver IPs are sent to that third party, not through our origin. We do not log those resolver IPs on Fubble servers. WebRTC and IPv6 checks also run in the browser (including public STUN and IPv6 echo services).

Legal basis: legitimate interest in providing the tool you requested (Art. 6(1)(f)).

4. On-demand locations and public fallback endpoints

Our catalogue of countries and cities grows with demand. If you select a location where we do not yet operate a dedicated Fubble VPN server, we may:

  • Provision a new Fubble-operated server for that location, typically within minutes; and/or
  • Temporarily offer a connection to a publicly available open VPN endpoint so you can get online immediately while the dedicated server is being rolled out.

The public fallback is optional. You may decline it or disconnect at any time. A publicly available endpoint is not operated by LUNEXLAB OÜ, is not covered by this no-logs Policy, and may keep its own logs. We do not receive those logs. When the dedicated Fubble server is ready, you can switch to it in the app and enjoy the same no-logs treatment as our other Fubble-operated nodes.

Legal basis for using a Fubble-operated on-demand server: contract (Art. 6(1)(b)). Connecting to a third-party public endpoint is a service you choose; that operator is an independent controller of any data it processes.

5. Purposes and legal bases

Purpose Data Legal basis (GDPR Art. 6)
Provide the VPN tunnel on Fubble servers None retained (traffic is not logged) (b) contract
Create and manage your account / devices Email or sign-in ID, device label, app version (b) contract
Unlock paid features Entitlement / expiry from the store (b) contract; (c) legal duty (tax)
App statistics and stability Firebase / Google Analytics events (a) consent where required; else (f) legitimate interest
Push notifications you opted into Device push token (a) consent
Support and contact forms Email, message, optional diagnostics (b) contract; (f) legitimate interest
Security of the website/API Short-lived connection metadata (f) legitimate interest; (c) legal duty
Marketing email Email address (a) consent

Legitimate interests, where used, are: keeping the Service secure, measuring whether the app works, and answering support. They are balanced against your rights; you may object under Article 21.

Providing account or payment data is not a statutory requirement, but we cannot deliver a paid subscription without a way to verify entitlement. You are not required to accept analytics cookies or in-app analytics.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects (Art. 22). We do not profile your browsing.

6. Recipients — who we share with

We do not share VPN traffic. We do not sell personal information. Recipients are limited to:

  • Google Ireland Limited / Google LLC — Firebase and Google Analytics for app (and, with consent, website) statistics. Independent controller/processor depending on the product; processing is described in Google’s terms.
  • Apple and Google Play (and, where used, RevenueCat as an entitlement processor) — to complete and restore purchases you initiate. They are independent controllers of checkout data. They do not receive VPN traffic.
  • Email and, internally, Telegram — only to deliver support messages you sent us.
  • Professional advisers, hosting in the EEA, or a successor in a merger, under confidentiality.
  • Competent authorities, if we are legally compelled and only for data we actually hold (typically account/support records, never VPN traffic logs).

Processors act on our instructions and may not use the data for their own advertising.

7. International transfers

LUNEXLAB OÜ is established in Estonia (EU). Account records we control are hosted in the European Union (currently Germany / EU regions).

Firebase and Google Analytics may process data in the United States. Where a transfer outside the EEA/UK occurs, we rely on: (i) an adequacy decision if one applies (including the EU–US Data Privacy Framework for certified organisations); and/or (ii) the European Commission’s Standard Contractual Clauses, with supplementary measures where needed. You may request a copy of the relevant clauses at [email protected]. Adequacy list: European Commission.

8. Retention

  • VPN traffic and connection logs on Fubble servers: not stored (retention: none).
  • Account and device records: for the life of the account, then deleted or anonymised within 30 days of a verified deletion request, except backups that rotate out within 90 days.
  • Subscription/tax records: as required by Estonian accounting law (generally 7 years).
  • Support emails: up to 24 months after the last message, unless a longer period is needed for a dispute.
  • Firebase / Google Analytics: according to the retention configured in those products (typically 2–14 months of event data). Aggregated reports may remain without identifying you.
  • Push tokens: until you disable notifications or delete the account/device.
  • Website security logs: typically up to 30 days.

After the retention period ends, data is deleted or irreversibly anonymised. Rights of access, erasure, rectification, and portability cannot be exercised on data we no longer hold (including data we never logged).

9. Security

We use encryption in transit (TLS and modern VPN protocols such as WireGuard), access controls, least-privilege production access, and logical separation of account data from VPN forwarding. No internet transmission is perfectly secure. You are responsible for keeping your device and account credentials safe.

If a personal-data breach is likely to result in a high risk to your rights, we will notify the Estonian Data Protection Inspectorate without undue delay and, where required by GDPR Articles 33–34, affected users (by email and/or a notice on the Services).

10. Your rights

Subject to GDPR conditions, you may:

  • Access a copy of personal data we hold
  • Rectify inaccurate data
  • Erase data (“right to be forgotten”)
  • Restrict processing
  • Object to processing based on legitimate interests or to direct marketing
  • Port data you provided to us, in a machine-readable format
  • Withdraw consent at any time, without affecting prior lawful processing
  • Not be subject to Art. 22 automated decisions (we do not carry these out)
  • Lodge a complaint with AKI (Estonia) or your local authority; a list is published by the EDPB

How to exercise rights: email [email protected] with the subject “Data request”, stating whether you want a copy, correction, restriction, objection, or deletion, and the email/account you use. We will verify your identity. If you act for someone else, we need proof of authority. We respond within one month (extendable by two months for complex requests, with notice).

We cannot give you VPN traffic logs, because we do not have them. Deleting an account removes account, device, and support data we control; it does not affect records the app stores keep about your purchase.

11. Region-specific notices

EU/EEA and United Kingdom

The sections above are written for the GDPR and UK GDPR. Withdrawal of consent does not affect processing that already took place. You may contact the UK Information Commissioner’s Office at ico.org.uk if you are in the UK.

Canada (PIPEDA)

You may access and correct personal information, withdraw consent subject to legal limits, complain to the Privacy Commissioner of Canada, and be notified of a breach that creates a real risk of significant harm.

United States (including California and similar state laws)

We do not sell or share personal information for cross-context behavioural advertising. We do not use sensitive personal information to profile you. You may request to know, access, correct, or delete personal information we hold, and you will not be discriminated against for exercising those rights. Submit requests to [email protected]. California “Shine the Light”: we do not disclose personal information to third parties for their direct marketing. We do not currently honour browser DNT signals as a global standard; we do honour our cookie banner and in-app/OS analytics controls.

12. Children

The Services are not directed at children under 16 (or the higher digital-consent age in your country; 13 in Estonia for information-society consent). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.

13. Do Not Track, cookies, email, and links

Cookie use is described in the Cookies Policy. Marketing email is opt-in and includes unsubscribe. Transactional email (receipts, security) may still be sent. Third-party websites linked from the Services have their own policies; we are not responsible for them.

14. Changes

We may update this Policy when the law or the product changes. The “Last updated” date will change. Material changes that reduce your privacy rights will be announced by email (if we have it) and/or in the app or on the website. Continued use after the effective date means you acknowledge the updated Policy. We will not use personal data in a materially new way without a lawful basis (including fresh consent where required).

15. Contact

LUNEXLAB OÜ
Tornimäe tn 5, 10145 Tallinn, Estonia
Email: [email protected]
Website: fubblevpn.com

We will try to resolve complaints within the deadlines set by applicable data-protection law.