Privacy Policy
Effective: 30 July 2026 Last updated: 26 August 2026
This Privacy Policy explains how HARMANPLUS TECHNOLOGIES LTD (“HarmanPlus”, “we”, “us”) processes personal data when you use HarmanVPN, including the mobile application, website and related services.
1. About this Policy
Please read this Policy together with our Terms of Service and Acceptable Use Policy. If you do not agree, do not create an account or use the service.
We may update this Policy when our practices or legal requirements change. The effective date above will be updated when we publish a revised version.
2. Data Controller
HARMANPLUS TECHNOLOGIES LTD
United Kingdom
General and developer contact: developer@harmanplus.com
Privacy, data rights and support requests: support@harmanvpn.com
3. Scope
This Policy covers the HarmanVPN mobile application and supported platforms, the harmanvpn.com marketing site, authentication and account APIs, VPN node configuration APIs, and related admin operations.
It does not cover third-party websites or services you choose to visit while connected to the VPN.
4. Information We Collect
We collect only categories needed to operate accounts, secure the service, calculate HarmanVPN Free plan usage and apply active quota settings, deliver optional notifications, and (when advertising is enabled for HarmanVPN Free users) serve consent-gated ads. Categories are described below.
The harmanvpn.com marketing website uses Google Analytics 4 to measure website usage and performance. Google Analytics may process page views, page URLs and titles, referrer information, browser/device characteristics, approximate region derived from network information, and related technical interaction data.
5. Account Information
When you register we process: name, email address, password (stored only as a one-way hash — we do not store plaintext passwords), locale preference, and timestamps for terms/privacy acceptance.
We may store registration IP address and last login IP/time for security and abuse prevention.
Email verification and password-reset tokens are stored temporarily to complete those flows.
6. Device and Security Information
To manage sessions and devices we may process: device name, client-generated device identifier, platform, app version, OS/build metadata, approximate last-seen time, and last IP associated with the device record.
If you enable push notifications we process a Firebase Cloud Messaging registration token (stored encrypted at rest in our control plane) and related delivery status for campaigns you are eligible to receive.
We record login and security events (success/failure, IP, user-agent summary) for account security.
Admin panel access may use multi-factor authentication secrets and short-lived trusted-device cookies for administrators only.
7. VPN Service and Network Information
To establish a WireGuard tunnel we process technical VPN parameters such as your device’s WireGuard public key, the assigned tunnel address, selected node/region, and connection/disconnection state in our control plane.
WireGuard private keys are generated on your device. In the published Android app, the persistent private key is stored encrypted using Android Keystore-backed key material. We do not receive your private key.
VPN nodes keep the live peer public key and assigned address while a peer is active so the tunnel can operate. After disconnect/unbind the peer is removed from the node configuration; control-plane binding rows may retain disconnected status and timestamps.
8. VPN Traffic We Do Not Intentionally Record
We do not intentionally record: destination IP addresses of your VPN traffic, DNS query names, URLs, page content, or browsing history.
We do not intentionally enable packet-capture or destination-logging features in our maintained VPN node configuration for user traffic.
Separately, standard infrastructure access logs on servers (for example reverse-proxy logs for management/API endpoints) may temporarily include source IP addresses and request metadata for security and operations. Those logs are not used to rebuild a browsing history of sites you visit through the VPN tunnel.
9. Usage Quota and Aggregate Data
For Free accounts we measure aggregate bytes transferred (receive + transmit) on a UTC calendar-month basis to calculate the published monthly allowance (currently 1 GB unless changed in product settings). Active product settings determine whether access is restricted when that allowance is exhausted.
Counters are derived from WireGuard transfer totals reported by nodes. We store per-report deltas, monthly aggregates, and lifetime totals tied to your account. Premium accounts are treated as unlimited under current product rules.
These aggregates do not include destination hosts or DNS names.
10. Advertising and Consent
HarmanVPN Premium does not request or show ads.
HarmanVPN Free may show advertisements when our remote configuration enables advertising, you are authenticated, and applicable privacy/consent requirements are met. When advertising is enabled, HarmanVPN may use third-party advertising SDKs and services. Depending on the active application configuration, these may include providers such as Google and Unity.
The Google User Messaging Platform (UMP) / ConsentManager continues to gate whether ads may be requested. Ad SDK requests are not made when the app-level consent state prevents ad requests. Where consent frameworks apply, provider-specific consent signals (such as GDPR-related flags for a given SDK) are propagated only when ads may be requested. CCPA/PIPL flags and COPPA child-directed treatment are not automatically asserted by HarmanVPN. HarmanVPN is not presented as a child-directed app.
Current production-capable advertising is oriented to fullscreen interstitial placements around supported Free connect/disconnect interactions. Banner, rewarded, app-open, and native ad formats are not part of the current Unity production configuration. Existing Google Mobile Ads support may remain in the application architecture for future use. Advertising behaviour may depend on region, consent state, and app configuration.
When ads run, advertising providers may process data such as advertising or device identifiers, approximate location (for example, inferred from network signals), app/ad interaction events, diagnostic information, and other technical signals as described in those providers’ own disclosures. Personalisation and identifier use depend on consent and provider/account/device settings. HarmanVPN ad telemetry is designed to avoid transmitting PII, VPN credentials, access tokens, IP addresses, email addresses, and VPN configuration data.
The HarmanVPN mobile application does not include a general-purpose analytics or crash-reporting SDK. Firebase is used for Cloud Messaging, while advertising SDKs may process their own ad and diagnostic events when they are allowed to initialize. Separately, the harmanvpn.com marketing website loads the standard Google Analytics 4 web tag for website usage and performance measurement.
Advertising availability does not determine VPN availability. If an eligible ad cannot be initialised, loaded, shown, or times out—or if inventory is unavailable, the user is offline, or consent does not permit ad requests—the requested VPN action continues without a successful ad.
We do not sell personal data.
11. Local Storage and Secure Storage
The app stores its authentication token in platform secure storage. Non-secret preferences such as selected location and language, local ad-frequency counters, and notification permission flags are kept in app-local preference storage using the platform-specific implementation.
Google’s and other advertising/consent SDKs may store their own state on the device outside HarmanVPN-controlled keys.
Logging out clears the auth token and disconnects VPN sessions on a best-effort basis; it does not by itself erase WireGuard keys or all local preferences. Account deletion removes the server-side account and instructs the app to clear the local session.
12. How We Use Information
We use personal data to: create and secure accounts; authenticate API and VPN access; manage entitlements and Free quota settings; operate WireGuard peers; send transactional email (verification, password reset, security notices); deliver optional push notifications; prevent abuse; comply with law; improve reliability; and understand marketing website usage and performance.
13. Legal Bases
Depending on the context and applicable UK/EU data protection law, we rely on: performance of a contract (providing the VPN service you request); legitimate interests (security, fraud prevention, service integrity, limited operational logging); consent (where required for certain advertising/consent frameworks or optional notifications); and legal obligation where applicable.
You may withdraw consent where processing is consent-based, without affecting the lawfulness of processing before withdrawal.
14. Service Providers and International Transfers
We use processors/sub-processors such as: email delivery infrastructure (configured SMTP or equivalent), Google Firebase Cloud Messaging for push, Google Analytics 4 for marketing website usage and performance measurement, advertising SDK providers when Free ads are active (which may include Google and/or Unity depending on configuration), Google UMP for consent where required, and hosting/VPS providers that operate our control plane and VPN nodes.
Data may be processed in the United Kingdom, European Economic Area, and other countries where our providers or VPN nodes are located. Where required, we use appropriate transfer safeguards.
Android in-app purchases for Harman Premium are handled through Google Play. The iOS app is not published, so App Store billing is not offered to users at this time.
15. Data Retention
Account profile data is retained until you delete the account (or we close it for policy/legal reasons).
Password-reset and email-verification tokens expire automatically (typically within about 60 minutes).
Device records that are revoked or stale may be purged by scheduled jobs (inactive/stale windows are measured in tens of days as configured operationally).
VPN usage aggregates and peer-binding history associated with your user id are deleted when the account is hard-deleted.
Login/security events and support tickets may remain after account deletion with the user reference removed, for security, dispute, and abuse-prevention purposes. Automated purge schedules for those residual records are not fully published yet; we do not retain them to reconstruct VPN destinations or browsing content.
Operational backups and infrastructure logs are retained only as long as needed for resilience and security, then overwritten or deleted according to hosting practice.
16. Security
We use TLS for API traffic, hashed passwords, encrypted storage for certain secrets (such as FCM tokens and admin MFA material), short-lived VPN access tokens, and platform secure storage for on-device keys.
No method of transmission or storage is perfectly secure. Please protect your password and device.
17. User Rights
Subject to UK GDPR / applicable law, you may have rights to access, rectify, erase, restrict, object, and data portability, and the right to lodge a complaint with a supervisory authority (in the UK, the Information Commissioner’s Office).
To exercise rights, contact support@harmanvpn.com. We may need to verify your identity.
18. Account and Data Deletion
You can delete your account in the HarmanVPN app (My account → Delete my account) by re-entering your password and confirming. You can also open Settings → Delete account.
You can also request deletion on the web without installing the app: https://harmanvpn.com/account-deletion (also available under /tr/account-deletion and /en/account-deletion). Submitting the web form does not delete the account immediately; we send a time-limited confirmation link to the email address on the account. Responses are generic so we do not reveal whether an email is registered.
Deletion permanently removes the account and associated user data described above, subject to limited residual security records. Deactivation-only is not used as a substitute for deletion.
19. Children
HarmanVPN is not directed to children under 16 (or the higher digital-consent age in your country). We do not knowingly create accounts for children. If you believe a child has registered, contact support@harmanvpn.com and we will take appropriate steps.
20. Law Enforcement and Legal Requests
We may disclose information if required by law, regulation, court order, or to protect rights, safety, or integrity of the service. Because we do not intentionally retain VPN destination or DNS query logs, we typically cannot produce browsing histories that we do not have.
21. Changes to this Policy
We will publish updates on this page and adjust the last-updated date. Material changes may also be highlighted in the app or by email where appropriate.
22. Contact
HARMANPLUS TECHNOLOGIES LTD
United Kingdom
General and developer contact: developer@harmanplus.com
Privacy, data rights and support requests: support@harmanvpn.com