Last updated:
1. Scope
This Privacy Policy applies to colitu.com, docs.colitu.com, the Colitu apps (Windows, Android, iOS) and the Colitu VPN service (together, the "Service"). By using the Service you acknowledge the processing described here. For detailed processing records see the Data Processing Policy.
2. Our core principle: a VPN without activity logs
Colitu does not record the contents of your traffic through the VPN tunnel, the sites you visit, the contents of your DNS queries or the destination addresses you connect to. We process only the minimum data needed to run the Service, bill for it and prevent abuse. Colitu therefore does not promise complete anonymity: we keep limited data such as sign-in and IP history, connection time ranges and per-user traffic volume, for the periods listed in the tables below.
3. Data we process
| Category | Examples | Purpose |
|---|---|---|
| Account data | E-mail address, hashed password, language preference, account date | Creating and managing the account |
| Verification data | Hash of the one-time code, delivery records | Verifying the e-mail address |
| Device data | Device name, platform, OS and app version, irreversible hash of a hardware identifier | Enforcing device slots, preventing free plan and trial abuse |
| Sign-in and security data | Sign-in time, IP address, country derived from the IP, browser/app information | Account security, detecting suspicious sign-ins |
| Usage data | Volume of data (bytes) per user and server, connection time ranges | Traffic limits, fair use, capacity planning |
| Payment data | Order, amount, payment method type, payment provider transaction ID and status | Sales, accounting, refunds |
| Support data | Messages, files you attach, diagnostics the app adds automatically (device, version, recent errors, app logs) | Resolving support requests |
| Colitu Bot data | Conversations with the bot, "was this helpful" feedback | Answering and improving answers |
Card numbers, CVV codes, bank account details or crypto wallet keys never reach Colitu; payments are completed on the payment provider's secure page.
4. Legal basis
We process data to conclude and perform our contract with you (account, VPN access, billing), on the basis of our legitimate interests (security of the Service, preventing abuse and fraud, improving the Service), to meet legal obligations (accounting and tax records) and, where required, with your consent.
5. Retention
| Data | Period |
|---|---|
| Account data | Until the account is deleted |
| Device records | Until the device is removed or the account is deleted |
| Sign-in and IP history | 180 days |
| Per-user traffic records | 90 days; afterwards only period totals |
| Refused device and trial attempts | 180 days |
| Free plan and trial abuse hashes | Kept irreversibly to stop the free plan or a trial being claimed again |
| E-mail delivery records | 90 days |
| Colitu Bot conversations | 180 days |
| Closed support conversations | 2 years after closing |
| Payment records | For the legally required period |
Expired data is deleted by an automatic job.
6. Sharing
We do not sell your data or share it for advertising. We share it only as far as needed to provide the Service, with these providers:
- Payment provider (Platega): order amount and transaction details.
- E-mail provider (Resend): your e-mail address and the content of the message.
- AI provider (DeepSeek): questions you ask Colitu Bot and the related help articles. Your account details are not sent.
- Infrastructure providers: server hosting and DNS/CDN services (e.g. Cloudflare, for docs.colitu.com only).
When we receive a legally binding request we can only share data we hold and that is listed in this policy. Because we keep no tunnel traffic logs, we cannot provide such data.
7. International transfers
Our servers and providers may be located in different countries, and your data may be transferred there. Appropriate safeguards such as encryption and access restrictions apply.
8. Security
Passwords are stored irreversibly with Argon2id. All connections are encrypted with TLS. Secrets (e.g. API keys) are stored encrypted in the database. Administrator access is role-based, protected by two-step verification and written to audit logs.
9. Your rights
You have the right to access your personal data, to have it corrected or deleted, to object to processing and to receive a portable copy. Send requests from the Support section of the app or to support@colitu.com. To verify your identity we may ask you to send the request from your account's e-mail address. We answer within 30 days.
10. Children
The Service is not intended for people under 16. If we learn that we process data of someone under that age, we delete the account and the data.
11. Cookies
The website uses only cookies needed for sessions, security and your language choice; we use no advertising or tracking cookies. Details: Cookie Policy.
12. Changes
We may update this policy. We announce significant changes on the website or by e-mail before they take effect. The current version is always on this page.
13. Contact
Privacy questions: support@colitu.com
Questions? Write to support@colitu.com.