Last updated: August 1, 2026
1. Who we are
HorseVPN is operated by Chita Technology LTD. This policy explains the limited information we process to authenticate accounts, provide the VPN service, manage subscriptions and devices, secure payment access, prevent abuse, and troubleshoot service failures.
2. Information we process
Account and authentication information
- Username, account identifier, password or password-derived authentication data.
- Account status, subscription start and expiration dates, permitted device count, and service-access status.
- On supported Apple devices, credentials may be stored locally using the operating system Keychain so the app can sign in securely.
Subscription and usage information
- Purchased plan, quota, used bytes, remaining bytes, validity period, and device limit.
- Connection/session identifiers, connection state, sent and received byte counters, and operational timestamps needed to provide and account for the service.
Device and security information
- Installation or device identifier, platform, device model, app version, browser information, user agent, screen and language settings, and session identifier.
- Security and anti-abuse signals such as device fingerprint, visitor identifier, IP address, failed payment attempts, and block-rule matches.
- We may derive an approximate country, province/state, or city from the public IP address to apply payment-access controls and prevent abuse. IP geolocation is approximate and may be wrong when a VPN, proxy, carrier network, or shared connection is used.
- When local IP-location data is incomplete or conflicts, the payment-security service may send the public IP address to a secondary IP intelligence provider solely to obtain another approximate country, province/state, or city result. Results are cached for a limited period to reduce repeated lookups. A conflict between providers is treated as ambiguous rather than as a precise physical location.
Payment information
- Buyer email, selected plan, payment-attempt identifier, amount, payment status, gateway reference, and fraud/security result.
- Full bank-card details are handled by the payment provider and are not entered into the HorseVPN app or website forms.
Support information
If you contact support, we process the information you choose to provide, together with relevant account or technical details needed to investigate the request.
3. How we use information
- Authenticate users and display account, quota, expiration, and device information.
- Operate the VPN tunnel, calculate service usage, and enforce subscription, quota, device, and concurrent-session limits.
- Register, display, revoke, and remove authorized devices and sessions.
- Process payment attempts, deliver purchased subscriptions, and prevent fraudulent or abusive payment access.
- Apply administrator-configured payment controls, including email, device, platform, IP, and approximate geographic restrictions.
- Maintain service reliability, investigate errors, and protect HorseVPN systems and users.
- Meet applicable legal, accounting, security, and compliance obligations.
4. VPN traffic and connection data
HorseVPN does not need the contents of your communications to authenticate your account or calculate your subscription usage. The service may process limited connection metadata that is technically necessary for tunnel operation, device/session control, security, usage accounting, and troubleshooting. We do not sell personal information.
5. Sharing and service providers
Information may be processed by infrastructure, hosting, payment, security, and support providers only as needed to provide the relevant service. Payment providers process bank-card information under their own privacy and security terms. We may disclose information when required by applicable law or when reasonably necessary to protect users, the service, or legal rights.
6. Retention
Account and subscription information is retained while needed to operate the account and satisfy legitimate legal, accounting, or security requirements. Device and session records are retained while needed to manage authorized access. Payment-attempt and anti-abuse records may be retained to reconcile transactions, investigate fraud, and enforce security rules. Technical connection metadata is retained only for the shortest period reasonably necessary for operation, accounting, security, and troubleshooting, after which it is deleted or aggregated where practical.
7. Security
We use technical and organizational safeguards intended to protect information, including encrypted transport, access controls, authentication, server-side enforcement of payment and device restrictions, and platform security facilities such as Apple Keychain where supported. No method of transmission or storage can be guaranteed to be completely secure.
8. Your choices and requests
You may contact support to request access, correction, or deletion of account-related information, subject to identity verification and any information we must retain for legal, accounting, fraud-prevention, or security reasons. Removing an authorized device or changing a password may revoke active sessions.
9. Children
HorseVPN is not directed to children under the minimum age required to consent to online services in their jurisdiction. We do not knowingly create accounts for children in violation of applicable law.
10. Changes to this policy
We may update this policy when the service, legal requirements, or data-processing practices change. The current version will remain available at this URL and will show its effective date.
11. Contact
Questions or privacy requests can be submitted through the HorseVPN support page.
The same policy covers the iOS/iPadOS App Store version, Android, Windows, the website, the account area, and payment-security processing. A separate iPhone-only or Android-only policy is not required for the current HorseVPN service.