Legal

Privacy Policy

Last updated: 11 August 2026

This notice explains how Mslm Dev, trading as VPNDetection ("we", "us"), collects, uses and shares personal information when you visit vpndetection.io or use the VPNDetection API. Questions go to privacy@vpndetection.io.

1. What we collect

We collect the following from you directly:

  • Account details: your name, email address, and a hashed password. We never store your password in a form we can read.
  • Authentication data: if you sign in with Google or GitHub, the identifier and email that provider returns to us.
  • Billing details: handled by Paddle as merchant of record. We receive a record of the subscription and its status. We do not receive or store your full card number.
  • Support correspondence: whatever you choose to send us.

We collect the following automatically when you use the Service:

  • Session and security data: the IP address a request came from, the browser or client user agent, and timestamps. We use this to keep you signed in, to show you your own active sessions, and to detect abuse.
  • Usage data: which API endpoints your keys call and how often, so we can meter your plan and operate the Service.

We do not process special category or sensitive personal information, and we do not buy personal information from third parties.

2. IP addresses we classify are not personal information about you

This is worth stating plainly because it is the part people ask about. The IP addresses you submit for classification are processed to answer your query and are not used to build a profile of any individual. Our classification datasets describe network infrastructure, such as which ranges belong to VPN operators or hosting providers, and are derived from network measurement, published operator server lists and public internet registry records. They are not derived from the queries our customers make.

If you submit IP addresses that constitute personal data in your jurisdiction, you are the controller of that data and we process it as your processor for the purpose of answering your query.

3. How we use it

  • To create and operate your account, and to authenticate you.
  • To provide, meter and bill the Service.
  • To keep the Service secure, including preventing fraud and automated abuse.
  • To respond to your support requests.
  • To understand aggregate usage so we can improve the Service.
  • To comply with our legal obligations.

4. Legal bases (EEA and UK)

  • Contract: operating your account and providing the Service you subscribed to.
  • Legitimate interests: securing the Service, preventing abuse, and improving what we offer, where those interests are not overridden by your rights.
  • Legal obligation: retaining records we are required to keep, and responding to lawful requests.
  • Consent: optional cookies, and marketing email where we rely on consent. You can withdraw consent at any time.

5. Canada

Where PIPEDA applies, we rely on your express or implied consent, which you may withdraw at any time. In limited circumstances the law permits processing without consent, for example to investigate a breach of an agreement or to detect fraud.

6. Sharing

We share personal information only with:

  • Paddle, for payment and billing as merchant of record.
  • Cloudflare, whose Turnstile challenge protects sign-up from automated abuse.
  • Google and GitHub, if you choose to sign in with them.
  • Infrastructure providers that host the Service under contract with us.
  • Authorities, where we are legally required to.

We may transfer information in connection with a merger, acquisition or sale of assets. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

7. Cookies

We set strictly necessary cookies, and one optional functional cookie that is off until you agree to it. We set no analytics, advertising or cross-site tracking cookies. In full:

CookieSet byPurposeRetention
vd_sessionUsKeeps you signed in. Not readable by scripts.30 days
vpndetection_consentUsRecords your cookie choices so we do not ask again.180 days
Turnstile cookiesCloudflareDistinguishes people from bots on sign-up and sign-in.Set by Cloudflare
g_stateGoogleOptional, functional. Remembers that you closed the Google sign-in prompt so it does not reappear. Set only if you accept functional cookies.Set by Google

Signing in with Google or GitHub sends you to that provider, which sets its own cookies on its own domain under its own privacy policy. We do not set cookies on their behalf.

Everything above except the Google sign-in prompt is strictly necessary to provide a service you asked for, so it does not require your consent under the ePrivacy rules. The prompt is a convenience rather than a necessity, so it is off until you accept functional cookies, and nothing is loaded from Google until you do. You can change or withdraw that agreement at any time from the Cookie preferences link in the footer.

There is no single agreed standard for Do Not Track signals, so we do not currently respond to them.

8. Retention

We keep account information for as long as you have an account, and for a limited period afterwards where we need it to meet legal, tax or accounting obligations or to resolve disputes. Session and security logs are kept for a short period appropriate to detecting abuse. When we no longer need information, we delete or anonymise it.

9. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, hashed passwords, first-party session cookies that scripts cannot read, and optional multi-factor authentication. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Your rights

Depending on where you live, you may have the right to access your personal information, to correct it, to delete it, to restrict or object to processing, to portability, and to withdraw consent. We will act on requests in line with applicable law and will not treat you differently for exercising a right.

To exercise a right, email privacy@vpndetection.io. We will verify your identity before acting, usually by confirming control of the account email. Self-service export and deletion from your account settings is being built; until it ships, email is the route.

If you are in the EEA or UK and believe we are processing your information unlawfully, you may complain to your local supervisory authority. In Switzerland, that is the Federal Data Protection and Information Commissioner.

11. California

The categories of personal information we have collected in the past twelve months, using the CCPA's own categories:

CategoryExamplesCollected
A. IdentifiersName, email address, account name, IP addressYes
B. California Customer Records categoriesName, contact detailsYes
C. Protected classificationsAge, gender, raceNo
D. Commercial informationSubscription and billing recordsYes
E. Biometric informationFingerprints, voiceprintsNo
F. Internet or network activityAPI usage records, sign-in eventsYes
G. Geolocation dataPrecise device locationNo
H. Audio, visual or similarRecordingsNo
I. Professional or employment informationEmployment historyNo
J. Education informationStudent recordsNo
K. InferencesProfiles built from the aboveNo

We have not sold or shared personal information in the preceding twelve months, and we do not intend to. California residents may request access, deletion, or correction, and may use an authorised agent who provides proof of authorisation.

12. Children

The Service is for users aged 18 or over. We do not knowingly collect information from children. If you believe a child has provided us information, contact privacy@vpndetection.io and we will delete it.

13. Changes

We update this notice as our practices or the law change. The "Last updated" date above shows the current version, and we will notify account holders of material changes.

14. Contact

Mslm Dev
195-B Jasmine Block Sector C Bahria Town
Lahore, Punjab 53720, Pakistan
privacy@vpndetection.io

Mslm Dev, 195-B Jasmine Block Sector C Bahria Town, Lahore, Punjab 53720, Pakistan. support@vpndetection.io