Guru VPN No-Logs Policy
Effective date: 01.07.2026 | Version: 1.0
This No-Logs Policy explains how GURU NETWORK S.R.L. ("Company", "we", "us", "our") applies its no-logs commitment in connection with the Guru VPN service, including the website guruvpn.com, mobile applications, VPN infrastructure, and related services (collectively, the "Service").
This Policy supplements and should be read together with our Privacy Policy, Terms of Service, Fair Usage Policy, Acceptable Use Policy, Cookie Policy, and Refund Policy. If there is any inconsistency between this Policy and the Privacy Policy, the Privacy Policy governs the processing of Personal Data.
1. Our no-logs commitment
Guru VPN is designed to minimize the collection of data connected with users' VPN activity. We do not log traffic content, the content of communications, full URLs, page content, traffic payloads, or detailed browsing histories.
We do not store users' real source IP addresses in connection logs, and we do not associate source IP addresses with user accounts.
We do not keep DNS query records linked to a user account, registered device, or users' real source IP address. Where DNS logs are processed, they are handled as non-user-level technical logs, as described in Section 4 below and in our Privacy Policy.
We do not maintain user-level concurrent connection counts or parallel session logs. Plan limits are implemented through registered-device limits, not by tracking simultaneous connections at user level.
No-logs does not mean that we collect no data at all. We process limited account, subscription, billing, diagnostics, security, service metadata, user-linked connection logs, registered-device limit status, DNS technical logs, analytics/SDK data, cookies for the website, push notification data, and support data where necessary to provide, secure, troubleshoot, bill for, improve, and lawfully administer the Service, as described in this Policy and the Privacy Policy
2. Quick summary
The table below summarizes the main categories relevant to our no-logs position:
| Category | Do we log it? | Summary |
|---|---|---|
| Traffic content / payloads | No | We do not log the content of communications, traffic payloads, or message content. |
| Browsing history / full URLs / page content | No | We do not keep detailed browsing histories, full URLs, or page content. |
| Real user source IP in connection logs | No | Connection logs do not store users' real source IP addresses or associate source IPs with user accounts. |
| User-linked DNS logs | No | DNS logs are not associated with user accounts, registered devices, or real user source IP addresses. |
| User-linked connection logs / service metadata | Limited | May show that a user account or registered device connected to a particular VPN server, together with available connection timestamps and connection status indicators. These logs do not include users' real source IP addresses, traffic content, browsing history, full URLs, page content, user-linked DNS queries, or communications content. |
| Registered-device limit status | Limited | Plan limits are enforced by registered devices, currently up to four (4) devices unless the applicable plan states otherwise. |
| IDS/IPS security signals | Limited | An IDS/IPS system may analyze limited network-level signatures and patterns to detect suspected malicious or abusive activity. Alerts may include technical indicators and internal device identifiers where necessary for security, abuse-prevention, or lawful-request handling, but packets and traffic payloads are not retained as user activity logs. |
| Account, billing, support, diagnostics | Limited | These records are processed to operate the Service, manage subscriptions, provide support, improve reliability, and meet legal or accounting obligations, as described in the Privacy Policy. |
3. Data we do not collect or retain as VPN activity logs
We do not collect or retain the following as VPN activity logs:
- the content of communications or message content;
- traffic payloads or packet contents as user activity logs;
- full URLs, page content, or detailed browsing histories;
- records showing which websites or webpages a specific user visited;
- real user source IP addresses in connection logs;
- DNS query records tied to a user account, registered device, or real user source IP address;
- user-level concurrent connection counts or parallel session logs;
- routine profiling records intended to reconstruct an individual user's browsing behavior.
4. Limited data and technical signals we may process
To operate the Service responsibly, we may process the following limited categories of data and technical signals. These categories are not used to maintain browsing histories or traffic content logs.
4.1. Account and subscription data.
We process account information such as email address, account status, subscription status, authentication metadata, support communications, and related records needed to provide and administer the Service.
4.2. Payment and billing metadata.
We process limited payment and billing metadata such as transaction identifiers, receipts, subscription IDs, billing email/name where provided, and payment provider references. We do not store full card numbers on our servers.
4.3. User-linked connection logs / service metadata.
We may process limited user-linked connection logs stored in Guru VPN's database. These logs may show that a user account or registered device connected to a particular VPN server, together with connection timestamps available under the current architecture and connection status indicators, such as whether traffic was detected for connection-success and service-reliability metrics. We do not store users' real source IP addresses in connection logs and do not associate source IP addresses with user accounts. These logs are not used to maintain browsing histories, traffic content, full URLs, page content, user-linked DNS query logs, or communications content.
4.4. DNS technical logs.
DNS logs may consist of domain names resolved through the Service and timestamps. DNS logs are not associated with user accounts, registered devices, or users' real source IP addresses, and they are not intended to identify which user or device made a particular DNS request. We do not log full URLs, page content, traffic payloads, or message content.
4.5. Security and IDS/IPS signals.
We may use an IDS/IPS system to analyze limited network-level traffic signatures and patterns for indicators of suspicious activity, malware behavior, scanning, attacks, abuse, or other security threats. The system may generate security alerts or technical indicators based on predefined or configured signatures and patterns. Alerts may include internal device identifiers or other technical indicators that can allow account/device association where necessary for security, abuse-prevention, or lawful-request handling. This analysis is intended for signature- and pattern-based security detection, not for reviewing the substance of user communications or maintaining browsing histories. We do not retain traffic content, packets, or traffic payloads as user activity logs for routine Service operation, and signature-based detection is not guaranteed to detect all misuse or security threats.
4.6. Registered-device limits.
Each plan may limit the number of registered devices, currently up to four (4) devices unless the applicable plan states otherwise. We enforce plan limits through registered-device status rather than by maintaining user-level concurrent connection counts.
4.7. Approximate data volume and infrastructure metrics.
We may use approximate data volume, aggregate infrastructure performance signals, error rates, abuse reports, external complaints, and IDS/IPS alerts to protect network stability and enforce the Fair Usage Policy and Acceptable Use Policy. We rely only on metrics actually available under our technical architecture and do not claim to detect all possible misuse. These metrics do not include traffic content, browsing history, full URLs, page content, or communications content..
4.8. Crash, diagnostics, analytics, cookies, SDK identifiers, and push tokens.
We may process crash reports, diagnostic telemetry, analytics events, website cookies, mobile SDK identifiers, push notification tokens, attribution identifiers, and similar technical data as described in our Privacy Policy and Cookie Policy. Mobile apps may use SDK-based identifiers such as IDFA/GAID, Firebase IDs, RevenueCat IDs, attribution identifiers, and push tokens; these are not browser cookies.
5. Why limited data is processed
Limited data and technical signals may be processed for the following purposes:
- to provide, maintain, and troubleshoot the Service;
- to authenticate users, manage accounts, verify subscriptions, and support billing;
- to protect the Service against fraud, attacks, malware, spam, scraping, DDoS activity, unauthorized access, and other abuse;
- to enforce the Terms of Service, Fair Usage Policy, Acceptable Use Policy, and registered-device limits;
- to improve performance, reliability, security filtering, and user experience;
- to respond to support requests and data subject requests;
- to comply with applicable legal, accounting, tax, and lawful request obligations.
6. FUP and AUP enforcement
Enforcement of the Fair Usage Policy and Acceptable Use Policy may be based on limited service metadata, registered-device limit status, approximate data volume, aggregate infrastructure impact, IDS/IPS alerts, external abuse complaints, payment or account signals, user-linked connection logs within the retained period, and user communications with support, only to the extent these signals are actually available under Guru VPN's ordinary technical architecture.
We do not use source IP logs, user-level concurrent connection counts, or DNS logs linked to individual users or devices for FUP enforcement. We also do not inspect or log the content of communications or traffic payloads for FUP enforcement.
Because our detection is limited to available technical signals and external reports, we do not claim to identify every prohibited activity or every instance of misuse. Where practicable, we may provide notice and an opportunity to remedy before applying restrictions, unless immediate action is required to protect the Service, other users, third parties, or legal interests
7. Retention
We retain limited data only for as long as necessary for the purposes described in this Policy and the Privacy Policy, unless a longer period is required or permitted by law.
User-linked connection logs, where retained, are retained under the periods stated in the Privacy Policy and should be deleted, anonymised, or aggregated once user-level retention is no longer necessary for the documented purpose, unless longer retention is required by applicable law or for documented security, abuse-prevention, dispute, billing, lawful-request handling, or legal-claims purposes. DNS technical logs, where retained, are retained only for the limited periods stated in the Privacy Policy and are not associated with user accounts, registered devices, or users' real source IP addresses.
Account, billing, support, diagnostics, analytics, cookies, SDK identifiers, and processor-held data are retained as described in the Privacy Policy, Cookie Policy, provider terms, or applicable legal and accounting requirements.
Because we do not keep traffic content logs, detailed browsing history, full URLs, page content, source-IP-linked VPN activity logs, user-linked DNS query logs, or user-level concurrent connection records, we cannot retain or disclose records of those categories that we do not create or maintain.
8. Service providers and infrastructure
We use third-party processors and infrastructure providers to provide hosting, analytics, payments, crash reporting, push notifications, subscription management, security, and related services. These providers may process limited data on our behalf under contractual arrangements and safeguards described in the Privacy Policy.
Where data is transferred outside the EEA, we apply appropriate safeguards as described in the Privacy Policy. Third-party processors may retain data under their own retention policies, especially for billing, fraud prevention, diagnostics, or legal compliance.
9. Lawful requests and disclosures
We may disclose information where legally required, to comply with lawful requests, to protect rights, property, safety, the Service, or users, or to respond to legal process. Any disclosure is limited to data we have and can lawfully disclose.
We cannot provide traffic content, detailed browsing histories, full URLs, page content, source-IP-linked VPN activity logs, user-linked DNS query logs, or user-level concurrent connection records if we do not collect or retain those records. We may, however, be able to provide limited account, billing, support, registered-device status, user-linked connection logs, DNS technical logs, security/IDS/IPS alerts, analytics/SDK data, or other service metadata if such data exists and disclosure is legally required.
10. Account deletion and data subject rights
Users may exercise rights to access, rectify, erase, restrict, object to processing, request portability, or withdraw consent where applicable by contacting privacy@guruvpn.com or support@guruvpn.com.
Account deletion and third-party processor deletion are handled as described in the Privacy Policy. Some data may remain for a limited period in backups, exports, billing systems, security records, or third-party processor systems where technically or legally necessary.
11. Internal controls and review
We maintain internal technical and organizational controls intended to keep our no-logs commitments accurate and enforceable. These may include access controls, limited permissions, retention schedules, security reviews, internal audits, vendor reviews, and, where applicable, independent third-party assessments.
If our architecture or logging practices materially change, we will update this Policy and related public policies to reflect those changes.
12. Changes to this No-Logs Policy
We may update this No-Logs Policy from time to time. Material changes will be posted with a new effective date and, where appropriate, notified to users through the Service or other reasonable means.
13. Contact
For questions about this No-Logs Policy, privacy practices, data subject requests, or lawful request handling, contact:
-
Privacy: privacy@guruvpn.com
-
Support: support@guruvpn.com
-
Legal / law enforcement requests: support@guruvpn.com or privacy@guruvpn.com
Last updated: 01.07.2026