Rotor is a VPN, so privacy is the product. This policy explains exactly what we store to run the service, how long we keep it — and everything we never store.
The short version
- We do not log what you do online: no traffic, no DNS queries, no browsing history, no record of which sites you visit.
- Our servers keep no access logs, and we don't store your IP address.
- We keep only what the service needs to work: your sign‑in identity, your subscription status and the list of devices you've signed in on.
- No advertising, no analytics, no tracking — in the app and on this website. We never sell or share your data.
- You can delete your account in the app at any time. Access ends at once; the remaining account records are erased within 90 days.
Who we are
Rotor VPN (“Rotor”, “we”) is operated by a company registered in Singapore, which is responsible for the personal data described in this policy.
Our Data Protection Officer can be reached at [email protected]. You can also use the contact form on our support page.
What we never collect
Rotor is built so that your online activity has nowhere to be stored. Our systems have no place to record it, so we cannot hand it over, lose it or sell it. We do not collect:
- the content of your traffic, or the websites and apps you use;
- DNS queries;
- your IP address or the IP addresses you connect to;
- connection times, session logs or bandwidth used;
- analytics, crash reports or advertising identifiers.
What we collect, and why
- Email address
- WhyOnly if you sign in with a one‑time email code: to send the code and let you recover access.Legal basisPerformance of our contract with you.KeptWhile your account exists, then up to 90 days after you delete it.
- Apple or Google sign‑in identifier
- WhyA pseudonymous identifier issued by Apple or Google, to sign you in. We never receive your password.Legal basisPerformance of our contract.KeptWhile your account exists, then up to 90 days after you delete it.
- Subscription information
- WhyThe App Store transaction identifier and subscription status, to know whether your plan is active. Payment is handled by Apple; we never see your card details.Legal basisPerformance of our contract; legal obligations.KeptWhile your account exists, then up to 90 days after you delete it, or longer only where accounting law requires it.
- Device information
- WhyFor each device you sign in on: the device model (for example “iPhone15,4”, not your phone's name), platform and app version, when it was added and when it last contacted our service — so you can manage your devices and we can apply the device limit.Legal basisPerformance of our contract.KeptUntil you sign out of that device or delete your account, then up to 90 days.
- Connection key
- WhyA public encryption key created on your device, so our servers can route your encrypted traffic back to you.Legal basisPerformance of our contract.KeptRemoved as soon as you sign out of that device or delete your account.
- One‑time sign‑in code
- WhyTo confirm it is you signing in by email.Legal basisPerformance of our contract.KeptExpires after 10 minutes; stored only as a one‑way hash.
- Sign‑in attempt counter
- WhyA counter tied to the requesting IP address, to stop automated abuse of sign‑in.Legal basisOur legitimate interest in protecting the service.KeptIn memory for up to one hour, then it expires. Never written to a log or database.
When you delete your account
You can delete your account in the app at any time. When you do:
- access to Rotor ends immediately, every signed‑in device is signed out and its connection key is removed;
- we revoke your Sign in with Apple authorisation;
- the remaining account records — email address or sign‑in identifier, subscription information and device list — are kept in a restricted state for up to 90 days, used only to respond to lawful requests and to investigate fraud or abuse, and then permanently erased.
Deleting your account doesn't cancel an App Store subscription — cancel it in your Apple ID settings.
Service providers
We use a small number of providers to run the service. Each one processes only what it needs for its task:
- Apple — the App Store, subscription payments and Sign in with Apple.
- Google — Sign in with Google, if you choose it.
- Postmark — delivers one‑time sign‑in codes by email.
- Infrastructure providers — the data centres that host our servers, and Cloudflare, which hosts this website and can carry encrypted connections between your device and our servers. They cannot read your encrypted traffic.
We do not sell or share your personal data with anyone for advertising or any other purpose.
International transfers
We are based in Singapore, and our providers may process data in other countries. When your data leaves the country where it was collected, we make sure it stays protected to the standard required by Singapore's Personal Data Protection Act and, for people in the European Economic Area and the United Kingdom, by the GDPR — for example through Standard Contractual Clauses.
Requests from authorities
We disclose data only when the law requires us to and the request is valid; we review every request and push back on requests that are not. By design, we have nothing to disclose about what you do online — no traffic, DNS, IP address or connection logs exist. At most, a valid order could reach the account records listed above.
If a law ever forced us to log our users' activity, we would move the affected service elsewhere or shut it down rather than comply, and we would tell you. We plan to publish a regular transparency report on the requests we receive.
Security
Traffic between your device and our servers is encrypted with ChaCha20‑Poly1305. Account data is encrypted in transit, access to it is restricted to the people who run the service, and we keep as little of it as possible. If a security incident ever affected your personal data, we would notify you and the relevant authorities without undue delay, as the law requires.
Your rights
Wherever you live, you can:
- see your devices and sign out of any of them in the app;
- delete your account in the app at any time;
- ask for a copy of your data, or for it to be corrected, exported or erased;
- object to or ask us to restrict processing, and withdraw consent where we rely on it;
- complain to your local data protection authority — in Singapore, the Personal Data Protection Commission.
To make a request, email [email protected] or use the contact form on our support page. We reply within 30 days and may ask you to confirm the request from your signed‑in app, so that nobody else can obtain your data.
California residents
We do not sell or share personal information, and we do not use it for targeted advertising. In the last 12 months we collected only the categories described above: identifiers (email address, sign‑in identifier, device model) and commercial information (subscription status). You have the right to know, correct and delete this information, and we will not treat you differently for using these rights.
Children
Rotor is for people aged 18 and over. We do not knowingly collect data from anyone younger; if we learn we have, we delete it.
This website
rotorvpn.com uses no cookies, no analytics and no third‑party scripts or fonts. Everything on it is served from our own domain.
Changes to this policy
If we change this policy, we will update the date at the top of this page. If a change is significant, we will also let you know in the app before it takes effect.
Contact
Questions about privacy, or a request about your data? Email our Data Protection Officer at [email protected].