Privacy policy
Last updated 17 September 2026
What data Rocket VPN receives, why it is needed, how long it is kept and what may not be done with it. No fog: if something is collected, it is named here.
Contents
- 1. What data we collect
- 2. What is stored when you use the VPN
- 3. What we do NOT collect
- 4. No-Logs policy
- 5. Why the technical data is needed
- 6. Legal grounds for processing
- 7. Bot and account data
- 8. Payments
- 9. Support and correspondence
- 10. Where data is stored and who receives it
- 11. International transfers
- 12. How we protect information
- 13. Retention
- 14. Deleting and changing data
- 15. Transparency
- 16. Minors
- 17. Changes to this Policy
- 18. Contacts
This Policy governs how Rocket VPN (the “Service”) collects, uses, stores and protects user information. The Service is provided through the Telegram bot @Rock3tVPN_bot, the site tg-rocket.duckdns.org, the account area and related technical services. The operator is the Rocket VPN service administration. Support: @myrocketvpn_support, sup-rocket-vpn@proton.me
By using the Service you confirm your agreement with this Policy. If you do not agree with its terms, stop using the Service.
1. What data we collect
We try to collect only what is needed to run and support the Service. We do not ask for identity documents, phone numbers or home addresses.
The following data may be processed:
- Telegram User ID and username, where available — Telegram passes these itself. The User ID serves as the identifier of your account in the Service.
- Subscription details and its end date.
- Payment records needed to confirm a payment. Card details are not stored by the Service.
- Support requests.
- Email address — if you provide one yourself, for example to use several Telegram accounts or to recover access.
- Referral data: the fact a referral link was used and the identifier of the person who shared it — to credit the invitation and the reward.
- Sign-in records: which devices signed in and when, so that you can spot an unknown sign-in and revoke the session.
- Technical data required for the VPN to work — see section 2.
We do not seek to collect additional personal data that the Service does not need.
2. What is stored when you use the VPN
The Service keeps no logs of users' internet activity. For technical operation, diagnostics and security the following may be stored:
- the IP address the connection is made from;
- the total volume of transferred traffic;
- the time of the last activity or last connection.
The IP address is used during the VPN session and may be kept for a limited time after disconnection — to close the session correctly, for diagnostics and stable operation. After that it is deleted.
Web server technical logs may contain the IP address, request time, HTTP method and response code. The full request address is not written to the log.
A subscription link contains its identifier, which is in effect an access secret. For that reason the full address of such a link is not written to technical logs.
Web server logs exist to protect against brute force, automated attacks and other abuse, and are kept no longer than 14 days.
Keeping this technical data means the Service is not a tool of complete anonymity. We present Rocket VPN as a private VPN service, not as a means of absolute anonymity.
3. What we do NOT collect
This is one of the most important parts of the document. The Service does not collect or store:
- browsing history;
- the list of domains a user visited;
- the contents of internet traffic;
- DNS queries as a history of user actions;
- information about transferred files;
- logs of which site a particular user visited;
- a history of the user's actions on the internet;
- the contents of users' connections;
- payment credentials, including card numbers;
- location;
- the user's contacts;
- access to the device's camera, microphone or files.
The site uses no advertising or analytics cookies, and no third-party counters or analytics.
Only what the site cannot work without is used:
- the account session cookie. It appears only after you sign in to the account area, keeps you signed in between pages, is not accessible to page scripts, and is sent only over HTTPS and only to our site. It is removed when you sign out, and in any case after 30 days;
- your chosen language and theme. They are kept in the browser's storage (localStorage) and are not sent to the server.
Signing in is impossible without the session cookie, so the site does not ask for separate consent to it. If you prefer not to store it, do not sign in on the website — everything is also available in the Telegram bot. Stored data can be deleted at any time in your browser settings.
The presence of the technical data in section 2 does not amount to logging internet activity.
4. No-Logs policy
The Service follows a No-Logs policy with respect to users' internet activity. No-Logs in this Policy means that the content and history of a user's internet activity are not logged.
At the same time the Service does not use the term “Zero-Logs” and does not claim absolute anonymity, because limited technical data is kept for the Service to work: connection IP address, traffic volume and the time of the last activity. We consider this description more accurate and more transparent for users.
The VPN servers keep no access logs and no DNS query logs: nothing records which sites and resources a user opened or what they sent through them. That is why we are physically unable to provide a link between “a user → the sites visited, requests made or traffic content” — to anyone, including in response to an official request: we simply do not have such data.
5. Why the technical data is needed
The technical data that is kept may be used for:
- diagnosing faults;
- determining the last activity of a connection;
- preventing abuse of the Service;
- keeping the VPN infrastructure stable;
- technical support of users;
- securing accounts and sessions.
Access is unlimited within an active subscription, so traffic volume is not used to throttle or to bill. It remains technical statistics and holds no information about which sites or resources you visited.
6. Legal grounds for processing
For users in the European Union, personal data is processed on the grounds provided by Article 6 of the General Data Protection Regulation (GDPR), where the relevant ground applies. The main grounds are:
- Performance of a contract — providing and renewing the subscription, giving access to the VPN, confirming payment and restoring access. Without the data this requires, providing the service may be impossible.
- Legitimate interest — protecting the Service and its users, rate limiting, detecting brute force, attempts to enter someone else's account, abuse, and diagnosing faults. We seek to weigh that interest against users' rights and to process only what is necessary.
- Consent — for example, to process an email address the user provided themselves for that purpose. Such consent may be withdrawn at any time.
- Legal obligation — processing and keeping certain records, including payment data, where applicable law requires it.
The specific ground depends on the nature of the processing and the category of data concerned.
7. Bot and account data
Telegram User ID, username, subscription details and other data the bot needs are used to:
- identify the user;
- give access to the VPN;
- manage the subscription;
- restore access;
- handle support requests;
- prevent abuse;
- manage active sessions and devices.
Where necessary, a user may provide additional data to support themselves.
8. Payments
The Service neither receives nor stores card details. Payments are processed by the payment systems used, under their own rules and privacy policies.
The Service receives only what is needed to confirm payment, manage the subscription and settle possible disputes.
9. Support and correspondence
You can reach support through Telegram or email: @myrocketvpn_support, sup-rocket-vpn@proton.me
Support correspondence is kept no longer than 6 months from the last message in that ticket.
You may request that correspondence be deleted irreversibly. Once we receive the request it is deleted within 24 hours, unless keeping it is required by applicable law or to meet legal obligations. Deleted correspondence is not recoverable.
Correspondence is used only to:
- resolve the request;
- restore the context of an earlier request;
- diagnose technical problems;
- prevent abuse;
- improve the quality of support.
Do not send passwords or payment details to support, or any other information you do not want disclosed.
10. Where data is stored and who receives it
User data is hosted using the infrastructure of SERVA and other necessary infrastructure and hosting providers.
The Service does not sell or hand user data to third parties for advertising profiling, marketing or the interests of outside commercial organisations.
In the course of the Service's operation, data may be processed by the following categories of recipient:
- Telegram — the platform through which the user interacts with the Service;
- payment systems — when making and confirming payments;
- infrastructure and hosting providers — on whose servers the Service and the VPN nodes run. They may process technical data needed for the infrastructure to function and to carry network traffic.
The Service does not pass browsing history to such providers, because no such history is kept or stored.
Data may be disclosed to state authorities or others only in the cases provided by applicable law, for example on a proper legal request. The Service can disclose only the data it actually holds.
11. International transfers
The Service's VPN nodes are located in different countries — in the European Union, the United Kingdom, the United States and elsewhere. This is part of how a VPN works: by choosing a server, the user deliberately routes their network traffic through the chosen country.
What happens to data:
- Your traffic passes through the chosen VPN node while you are connected. It is not recorded or stored by the Service as a history of internet activity — see sections 2 and 3.
- Account data is processed in the infrastructure the Service uses, according to the purpose of that data and section 10 of this Policy.
- Node technical data — connection IP address, traffic volume and activity time — may be processed where the node is located, within the limits set out in section 2.
- The IP address used to sign in on the website is sent to the ipwho.is geolocation service so that the sign-in code email can show the country and city the sign-in came from. Only the IP address is sent, without the email or any other data.
Where data is transferred to or processed in countries outside the European Economic Area, the data protection mechanisms provided by law apply, including the contractual commitments of the relevant infrastructure providers where necessary.
The scope of such processing is limited to the technical data the Service needs. No history of internet activity is created or stored, so the Service holds no such history to transfer.
If you would rather your traffic did not pass through a particular country, do not choose that server in the app. The list of available countries is shown in the server list.
12. How we protect information
Technical and organisational security measures are used to protect user information. In particular:
- all traffic to the site and the bot goes over HTTPS;
- an account can be protected with two-factor authentication using an authenticator code and a cloud password;
- passwords are stored only as a cryptographic hash;
- authenticator secrets and backup keys are never returned through the Service's interface;
- a device that signed in recently cannot change the account's security settings for 12 hours — this gives the owner time to spot and revoke an unknown session;
- access to data is limited to the people and systems that need it for the Service to work.
No internet service can guarantee absolute security, so the Service does not claim that an incident is impossible. If an incident affects user data and requires notifying users, we will say so through the channels available, including the Telegram bot and the channel.
13. Retention
Retention depends on the type of data:
- Account data — while the account exists and for as long as the related obligations require.
- Active session and device data — for the period needed for session management to work and to keep the account secure.
- Connection IP address — for the limited time needed for the session, diagnostics and stability of the Service, after which it is deleted.
- Support correspondence — no more than 6 months from the last message.
- Payment records — for as long as needed to meet obligations, keep financial records and settle possible disputes.
- Web server logs — no longer than 14 days.
- The journal of administrative actions on accounts — indefinitely and anonymised.
The journal of administrative actions is kept so that an administrator's intervention in an account can be audited and cannot be hidden.
14. Deleting and changing data
A user may ask support:
- for a copy of the available user data;
- to correct inaccurate data;
- to delete data;
- to restrict processing;
- to withdraw consent, where processing is based on consent.
We aim to handle such requests within 30 days.
Deleting particular data may be limited by contractual obligations, financial record-keeping, abuse prevention or applicable law. Deleting the account ends the subscription.
15. Transparency
We aim to give users the clearest possible information about how the Service works. Users have access to:
- information about VPN servers and available configurations;
- the rules of use;
- this Privacy Policy;
- the FAQ and connection instructions;
- support information;
- information about prices and subscription terms.
We try not to present assumptions or marketing claims as technical guarantees. In particular, the Service does not claim absolute anonymity merely because a VPN is used, and does not use the wording “Zero-Logs” while technical data is kept.
16. Minors
The Service is not intended for anyone under 18: using a paid subscription means entering into a contract, and only a person with the necessary legal capacity can do so.
The Service does not knowingly collect children's data and does not verify users' age itself. If we learn that an account belongs to someone under 18, the relevant data may be deleted at the request of a parent or legal guardian, unless keeping it is required by applicable law.
17. Changes to this Policy
The Service may change this Privacy Policy. When it does, the last updated date at the top of the document changes accordingly and users are notified through the channels available, including the Telegram bot and the channel.
Continuing to use the Service after a new version is published means the user accepts its terms.
18. Contacts
For questions about privacy, data processing and how the Service works:
@myrocketvpn_support, sup-rocket-vpn@proton.me
Bot: @Rock3tVPN_bot
Site: tg-rocket.duckdns.org
We recommend contacting support if you have questions about what data is processed when you use Rocket VPN.