Our promise
KEN's operational VPN session records do not contain full URLs, page paths, search terms, internet connections made through the tunnel, or non-DNS traffic content. For sessions routed through a KEN DNS resolver, separate DNS query logging described in section 2.5 applies.
We do record account-linked operational information needed to establish and manage a VPN session. This includes the KEN server used, connection start and end times, session duration, total bytes transferred, and technical tunnel identifiers. The sections below explain those records and keep them distinct from internet destination and traffic-content data.
01Who We Are
KEN VPN is operated by KEN Secure Ltd ("we", "us", "our"), company number 17186942. Our website is located at kensecure.com and our service is delivered through the KEN VPN mobile application ("the App"). This Privacy Policy explains how we collect, use, and protect information when you use our services.
02Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address. Required for account authentication and important service notifications.
- Display name. Optional, used to personalise your experience.
- Password. Stored as a securely hashed value (bcrypt). We never store or can view your plain text password.
- Authentication session data. We store a hashed refresh-token record with its account and device identifiers, the request IP address and user-agent, and creation, expiry and revocation information so we can manage signed-in sessions.
2.2 Subscription & Payment Information
If you subscribe in the Android app, the purchase is processed by Google Play. The App sends KEN the Google Play purchase token and product identifier so our server can verify the subscription with Google. We store that token, the product identifier, subscription state and expiry time against your KEN account so we can provide and update your plan access.
If you use a KEN card checkout, the purchase is processed by Stripe. When creating the checkout, we provide your account email address, display name, KEN account identifier and selected plan, and we store the resulting Stripe customer and subscription identifiers together with subscription status and expiry information. KEN does not collect or store your full card number or CVV; those payment details are entered with Stripe.
2.3 Device Information
When you register a device with KEN VPN, we store a device identifier, device name, platform type (currently Android), and a VPN-internal IP address. This is required for the WireGuard protocol to function.
2.4 Operational VPN Session & Bandwidth Information
For each VPN connection, we create an operational session record linked to your KEN account and, where available, your registered device. It contains a session identifier, the KEN VPN server used, connection start and end times, duration, total bytes sent and received, the VPN-internal address and WireGuard public key assigned to the tunnel, and a disconnect reason. For a multi-hop connection, it also identifies the KEN entry and exit servers. Authorised administrators can view recent session records together with account email, display name and plan tier, and can export recent session records.
We use these records to establish and close tunnels, account for bandwidth, show service statistics, monitor connection state, and manage server capacity. The session record itself does not contain full URLs or page paths, DNS queries, search terms, the destination IP addresses and ports actually contacted through the tunnel, or non-DNS traffic content.
2.5 DNS Resolver Query Log
For VPN sessions routed through a KEN DNS resolver, the resolver keeps per-query DNS log entries by default and associates them with the tunnel's VPN-internal IP address. KEN's backend reads the entries for the current internal address to calculate total and blocked-query counts for the Ad & tracker shield. The App provides a “Don't log my DNS queries” setting; when enabled, the resolver skips per-query logging and statistics for that internal address, so KEN cannot provide the “blocked this session” counter.
As checked on 5 September 2026, 47 active resolvers use a six-hour query-log rotation interval and one uses a 24-hour interval. The resolver normally retains the current and previous log files, so the rotation interval is not a deletion deadline. Older files, interrupted rotation and backup copies can retain information for longer. See section 7 for more about data retention and backups.
2.6 Wi-Fi Network Name (On-Device Only)
The KEN VPN app for Android asks for the location permission. This is not used to track where you are: Android requires that permission before any app may read the name (SSID) of the Wi-Fi network you are connected to. KEN uses the network name entirely on your device to power unsafe Wi-Fi alerts and your trusted-network Smart Rules. Your location and your Wi-Fi network names are never stored, never transmitted, and never leave your device. If you decline the permission, the VPN works normally and only the Wi-Fi safety features are unavailable.
2.7 Push Notifications
To deliver service alerts (for example security notices or important account messages), the app registers a push notification token with Google Firebase Cloud Messaging. This token identifies an app installation for notification delivery. Firebase also processes technical information as described in its privacy documentation. Account deletion follows the cleanup and backup process in section 7; it does not promise immediate removal of every copy held by a service provider.
2.8 Product Feedback
If you choose to send product feedback, we store the outcome you selected (such as "Loving it" or "Could be better"), any product area you selected, any optional written comment, whether you submitted it after a session or from Settings, your plan tier, Android app build and platform, submission time, and your KEN account identifier. Authorised administrators can view the feedback with the email address associated with that account. We use this information to triage feedback, understand which areas need attention, and record whether an item has been resolved.
The App asks you not to include passwords, payment details, or browsing activity in a feedback comment. Account-linked feedback is included in the scheduled account-deletion cleanup described below, rather than erased immediately when you request deletion.
03Traffic Data Boundaries
Subject to the DNS resolver query log described in section 2.5, KEN's operational VPN session records do not include:
04How We Use Your Information
We use the information we collect solely for:
- Providing the VPN service. Authenticating your account, managing your subscription tier, and assigning VPN configurations.
- Enforcing plan limits. Tracking aggregate bandwidth to ensure fair usage across tiers.
- Service communications. Sending essential emails such as welcome messages, password resets, and upgrade confirmations.
- Service operation and improvement. Using operational VPN session records and aggregate statistics to monitor connection state, understand server use, and manage capacity.
- Shield statistics. Reading DNS resolver query-log entries for your current VPN-internal address to calculate total and blocked-query counters, unless you enable “Don't log my DNS queries”.
- Product feedback. Reviewing the outcome, area, optional comment and app context that you choose to submit so we can triage reports and improve the product.
- Requested security tools. Checking submitted messages, looking up breach exposure and providing eligible scam, breach and Wi-Fi advice. The third-party processing involved is described in section 6.
05Data Storage & Security
KEN's account database is hosted on Hetzner, with a standby copy on OVHcloud for service recovery. The website and API use HTTPS, and database replication between these servers uses SSH. VPN tunnel traffic is encrypted using WireGuard's ChaCha20-Poly1305 cipher suite. Passwords are hashed with bcrypt before storage. Access to production systems is restricted to authorised personnel only.
06Data Sharing
We do not sell, rent, or trade your personal information to any third party. We share data only with:
- Google Play. For processing Android subscriptions and verifying their status using the purchase token and product identifier (see Google's privacy policy).
- Stripe. For KEN card checkout and subscription management. We provide the account details described in section 2.2 and Stripe handles the card details entered in its checkout (see their privacy policy).
- Google Firebase. For sign-in with Google or Apple (authentication) and for delivering push notifications (Cloud Messaging). Firebase processes your sign-in identity and push token on our behalf (see Google's privacy documentation).
- Resend. For transactional email delivery (see their privacy policy).
- Anthropic. Provides AI analysis for eligible Scam Check, breach-advice and Wi-Fi-advice requests. For Scam Check, KEN processes the request through your signed-in account and sends the submitted content and heuristic signals to Anthropic's API after masking matching long digit sequences. This is not complete anonymisation: names, email addresses, links and other identifying text may remain. Breach advice sends selected breach details, such as names, dates, affected data categories and exposure/password-status categories. Wi-Fi advice sends the reported network-security type, whether the VPN is connected, and available connectivity-test and threat-level results. The Wi-Fi-advice request does not include a dedicated field for your network name or location. These requests should not be assumed to be anonymous. Do not submit passwords, payment details or other unnecessary sensitive information. Provider retention depends on the applicable API terms, model and configuration; KEN does not promise zero retention by Anthropic. See Anthropic's API data-retention documentation.
- Website and infrastructure providers. Cloudflare serves this website. Hetzner hosts the primary account database and OVHcloud hosts its standby copy. KEN's active VPN fleet also uses Microsoft Azure, Hetzner, Linode/Akamai, Vultr, LightNode and MivoCloud. Hosting providers supply the infrastructure on which KEN processes tunnel configuration and connection information and, where applicable, resolver data. This does not mean KEN copies its account database to every VPN server. See section 5 for storage and section 7 for the verified recovery-copy arrangements.
- Public DNS providers. Some connection configurations use Cloudflare's or Google's public DNS service for resolution or fallback. When a request follows one of those paths, the selected resolver receives the DNS query and the source address visible on that route. This is separate from KEN's own resolver query logs; KEN's logging setting does not control a public provider's processing.
- Enzoic. Powers the Dark Web Monitor. When you run a scan or keep monitoring enabled, the email address you choose to monitor is checked against Enzoic's breach-exposure database. Only that email address is shared, and only for this lookup (see their privacy policy).
- Law enforcement. Only if required by valid legal process (such as a court order or warrant). KEN's operational VPN session records do not contain full URLs, page paths, search terms, destination connections, or non-DNS traffic content, but we may hold the account, subscription, device, feedback, authentication, operational VPN session, and DNS resolver information described in this policy.
International processing
KEN operates VPN infrastructure in multiple countries, including outside the UK and European Economic Area. The route depends on the connection configuration and server selected. Our account-database recovery arrangements are separate from this worldwide VPN fleet, and service providers may also process information in other countries.
The country shown for a VPN location identifies that server's location. It does not describe every country where account information or service-provider data may be processed.
07Data Retention
Account, authentication-session, and operational VPN-session records are retained in KEN systems while they are used to operate the service and your account. Requesting account deletion deactivates the account and starts the deletion workflow. A scheduled cleanup checks every 12 hours for inactive accounts whose deletion request is more than 30 days old. That cleanup includes the account record, refresh tokens, registered devices, current and legacy connection-session records, legacy MFA records, magic links, account-linked feedback, Google Play subscription-verification records, saved preferences, connection streaks, VPN location-visit summaries, server-switch state and generated account briefings held in KEN's database. Cleanup waits while a device still has outstanding network-peer removal records, and failed account cleanup is retried on a later run. This schedule is not a guarantee that every copy of personal data is erased at the 30-day mark.
Deleting a KEN account does not delete records independently held by Google Play or another payment provider, or cancel a Google Play subscription. Cancel your subscription through its original payment provider.
For recovery, KEN copies its account and mesh databases to its standby server on a 30-second schedule. The standby keeps the latest and previous successfully received snapshots, replacing them as new snapshots arrive. Outages or failover can interrupt replacement. Separate historical recovery copies also exist, so this rolling schedule is not a deadline for deleting all backup copies.
Hetzner's automatic disk backups are enabled for KEN's primary API server. The service retains up to seven backup copies, replacing the oldest as a new backup is created. Removing a record or recovery archive from the live server does not immediately remove it from existing disk backups. This is a rolling backup-count limit, not a guaranteed seven-day erasure deadline.
On 5 September 2026, OVHcloud's control panel showed that optional backup storage was not configured and its Backup Agent was not installed for KEN's standby server. This does not mean that the standby has no copies: the KEN-managed rolling database snapshots and historical archives described here still exist.
On KEN's primary and standby API servers, an hourly cleanup checks the identified pre-failback database copies and cold-standby recovery archives for expiry after 30 days. It uses the most recent file modification or metadata-change time and skips archives that are unsafe to remove or being handled during failback. This rule covers those historical recovery archives, not active databases or the rolling standby snapshots. Scheduling delays, archive changes or failed safety checks can delay removal; it is not an exact 30-day erasure guarantee.
The cleanup and backup schedules above apply to the records and copies described in each paragraph. They do not set an overall deletion deadline for historical account records, DNS logs or all backup copies, including copies used to restore the service.
08Your Rights
Depending on the circumstances and the legal basis for processing, UK GDPR and applicable data protection law give you rights to:
To exercise any of these rights, contact us at [email protected].
Where processing is based on consent, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. Some optional features may then be unavailable.
You can also complain to the UK's Information Commissioner's Office, or to your local data-protection authority where applicable. You do not have to contact us before exercising that right.
09Children's Privacy
KEN VPN is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notice. The "Last updated" date at the top of this page indicates the most recent revision.
12Contact Us
If you have questions or concerns about this Privacy Policy or our data practices:
- Company: KEN Secure Ltd, company number 17186942
- Registered office: 59 Lavender Way, Cramlington, England, NE23 8FN
- Email: [email protected]
- General support: [email protected]