Document
Privacy Policy
Mayak Networks app. Version of 24 August 2026.
This Policy describes what data the Mayak Networks service (the “Service”, “we”) processes, for what purpose and how we protect it. By using the app and the website mayaknetworks.com you agree to this Policy. Personal data is processed in accordance with Russian Federal Law No. 152-FZ “On Personal Data”.
This is a translation of the Russian original for readers’ convenience. The Russian version is the legally binding one; in case of any discrepancy it prevails.
1. Operator and contacts
Personal data operator: Vladislav Demidov. For questions about processing, access or deletion: support@mayaknetworks.com.
2. What data we process
- Account data: account number and password; an email address — if you provided one at registration or linked it later (the password is stored only as a cryptographic hash, we never see it in plain text).
- Device data: device model, app version, device identifier and installation identifier — to bind the subscription to the device and to prevent abuse.
- Split-tunnelling sets: if you build a set of your own, the list of apps you picked is stored with your account — so the set comes back after a reinstall and on your other device. The ready-made sets we offer are not sent anywhere; we do not record which apps you use.
- Diagnostics (only when you ask for it): when you tap “Send log”, the app sends a technical connection log and the exit IP address — so that we can help with the problem. Diagnostic logs are encrypted and used solely for troubleshooting.
- Technical request data: IP address and time of requests to our servers — to operate the service and keep it secure (protection against attacks). When the app is downloaded from the website we additionally store browser details (User-Agent), the referring page and a channel tag — this record is kept for 30 days and deleted automatically.
- App analytics: roughly once a week the app automatically sends the app and
build version, device model, OS version, interface language, install source and aggregate usage
counters (total number of connections and number of days with a connection) — so that we know
which versions and devices are in use and can improve the product. This data does not include your
name, precise location, advertising identifier or the contents of your traffic; the account
identifier is determined on our server from your session and is not sent by the app.
In addition to this weekly report, the app keeps a short journal of its own actions: opening and backgrounding, Connect and Disconnect taps, country switches, the outcome of a connection, loss of connection, self-repair of the connection, an error shown to you and which screen was opened. The entries are technical — country, connection step, milliseconds, error code, screen name; they contain no site addresses, no names of other apps and no traffic content. The journal is linked to your account, the IP address of the request is stored alongside it, and all of it is kept for 90 days and then deleted automatically. We process this data ourselves: the app contains no third-party analytics. - Referral source: at registration we store the referring page (referrer) and campaign tags (UTM) — to measure how well acquisition channels work.
- Traffic volume: the daily number of bytes sent and received on your account — to watch server load, compliance with the plan and to detect abuse. These are volume counters only: no website addresses, no app names and no connection contents are stored.
How the connection works. The app uses Android’s VpnService — this is what asks your permission the first time you connect. It is required to route traffic from the apps you choose into our encrypted channel: without it a protected connection is not possible. Traffic is encrypted from your device to our server; we do not read or store its contents. You can withdraw the permission at any time — turn the connection off in the app, or revoke access in Android settings.
What we do NOT collect: we do not log the contents of your traffic, do not track the websites and apps you visit, do not sell data and do not use advertising trackers.
3. Purposes of processing
- providing and operating the secure network access service;
- authentication and account protection;
- diagnostics and quality improvement (at your request);
- analytics of app versions, devices and usage — to improve the product;
- accounting for server load and compliance with the plan (by traffic volume);
- infrastructure security and prevention of abuse;
- compliance with legal requirements.
4. Legal grounds
Processing is carried out on the basis of your consent (given at registration and when sending diagnostics), as well as to perform the service agreement and to comply with the law.
5. Storage and protection
- Data in transit is protected by encryption (HTTPS); diagnostic logs and passwords are stored encrypted/hashed.
- Retention: account data — while the account is active; diagnostic logs — 90 days; technical access logs — 90 days; the app action journal — 90 days; the app download log — 30 days; traffic volume counters — 180 days. Once the period expires, the data is deleted or anonymised.
One exception we state plainly. When a free trial is opened for you, we store a fingerprint of your email address and the date — so that the trial is not granted to the same address twice. It is not the address itself: the fingerprint is computed irreversibly, with a server-side secret key, and the email cannot be recovered from it. This record is kept even if you delete your account, and it is stored for 180 days, after which it is deleted automatically. It is used for nothing else — no mail, no advertising, no linking to your other data.
6. Disclosure to third parties
We do not disclose your personal data to third parties, except where expressly required by law (upon a lawful request from authorised bodies). We do not use third-party advertising or analytics SDKs.
The first technical exception — delivering notifications to your phone: it uses Google Firebase Cloud Messaging (Google Ireland Limited). It receives a technical device identifier (the token it issues itself) and the number of the message in your inbox. The contents of messages are not passed to Google — the headline and the text are fetched by the app from our server after it has been woken up. Notifications can be turned off in the app (“Settings” → “Notifications”) or in your account.
The second exception — resolving website addresses (DNS). Your connection settings name a DNS server: by default Cloudflare and Google, in the ad-blocking mode — AdGuard, or a server you specified yourself in your account. These queries travel through our node over the encrypted channel, so to the DNS server the request appears to come from our node, not your device. We do not store these queries and do not link them to an account. You can change the DNS server, or set your own, in your account under “Settings”.
7. Your rights
You have the right to request access to your data, its correction or deletion, and to withdraw your consent to processing. You can delete your account and the related data yourself (cabinet.mayaknetworks.com) or by request to support@mayaknetworks.com.
8. Children
The Service is not intended for persons under 13; we do not knowingly collect children’s data.
9. Changes to this Policy
We may update this Policy. The current version is always available at mayaknetworks.com/en/privacy.html (Russian original: mayaknetworks.com/privacy.html), with the version date stated.
10. Contacts
Questions about personal data processing: support@mayaknetworks.com.