Skip to content
WORLD VPN

Privacy Policy

Applies to the World VPN App on every platform on which we offer it, including mobile and desktop.

Effective date: 18 September 2026 · Last updated: 18 September 2026

1. Who we are

Essa Studio MCHJ ("we", "us", "our") is the controller of the personal information described below.

Registered address: 2 Bodomzor Street, Shayx Shivli MFY, Tashkent, Uzbekistan

All privacy requests: support@captain.show

World VPN encrypts your device’s internet traffic and routes it through our servers. This Privacy Policy explains what we collect and, just as importantly, what we do not. Section 2 describes what happens to your online activity when you use the VPN; Section 3 describes the information the App itself collects.

2. Your online activity when you use the VPN

2.1 What our VPN servers DO NOT log

When you are connected to World VPN, your internet traffic passes through our VPN servers. Those servers DO NOT record:

  • Your browsing history, or the websites, apps or services you connect to, as an individual record — see Section 2.4 for the one aggregate statistic we do keep
  • The content of your traffic
  • Your individual DNS queries
  • Your originating IP address
  • The VPN IP address assigned to you
  • The time you connected or disconnected, or the duration of your session

The one exception to the list above is the aggregate statistic described in Section 2.4: a per-server count of how often each domain name was resolved. It is not linked to any user, device, account, IP address or session.

Data needed to maintain your connection is held in the server’s memory only while the session is active and is discarded when it ends. We measure the total load on each server in aggregate so that we can add capacity; this tells us nothing about any individual user.

Because we hold none of this information, we cannot match online activity to you, and we cannot provide it to anyone who asks for it — including government authorities — since we do not have it to provide.

2.2 What the App does record about your VPN use

The App records the product analytics events described in Section 3.3: when you tapped connect or disconnect, whether the connection succeeded, which server location and protocol you selected, and the result of any speed test. These are tied to a pseudonymous device identifier, or to your account if you have one. They contain nothing about what you did while connected, and are kept as described in Section 3.3.

2.3 Your IP address

The IP address referred to in Section 3.1 is the address from which your device contacts our own servers and providers — for example when the App launches, checks your subscription or sends an analytics event. We use it to derive your approximate location and to protect our systems from abuse. It is not recorded by our VPN servers and is never linked to your browsing activity. While you are connected, the websites and services you use see the address of the VPN server, not yours.

2.4 Aggregate DNS statistics

Our servers keep one category of aggregate statistic: for each server, a count of how often each domain name was resolved during each six-hour period. These counts are not linked to any user, device, account, IP address or session, and we cannot trace them back to you. We use them to monitor the health of our network and to detect abuse. They are the only record of DNS activity we hold; individual DNS queries are not stored. We keep these counts for no longer than 5 years and then delete them.

2.5 VPN permission

To provide the service, the App asks for permission to configure a VPN connection on your device — through a system prompt on iOS and Android, and through the operating system’s network settings on desktop, where administrator approval may be required. This permission allows the App to route your device’s internet traffic through our servers. We do not use it to read, alter or store the content of that traffic. You can remove the configuration at any time in your device or system settings, or by uninstalling the App.

2.6 Where our servers are

Our VPN servers are located in the countries shown in the App and are hosted in data centres operated by third-party infrastructure providers. Traffic through the tunnel is encrypted between your device and the server; the providers supply hardware and network connectivity and cannot read it. Because our servers do not store activity or connection logs, the location of the server you choose does not affect where your personal information is kept.

2.7 Our commitment about VPN data

We do not sell, use or disclose to any third party, for any purpose, any data about your use of the VPN service itself — your traffic, the destinations you connect to, your DNS queries, your originating or assigned IP address, and your connection and session records. We do not hold that data, and it forms no part of any analytics, attribution or advertising activity described anywhere else in this Privacy Policy.

Everything described in Sections 3 to 8 — including the analytics and advertising disclosures, and the "sale" and "share" described in Section 8.2 — concerns only information the App collects on your device about your use of the App: installs, screens viewed, features used, purchases and similar events. None of it is derived from, or contains, anything about your activity through the VPN.

3. What we collect, why, and how long we keep it

We collect information directly from you, automatically from your device when you use the App, and from Apple, Google and the providers listed in Section 5. We do not collect any information about what you do online while connected to the VPN — see Section 2.

3.1 Device and app identifiers

  • Includes: IDFV; advertising identifier (IDFA on iOS, Advertising ID on Android) where you have permitted it; Firebase installation ID; AppsFlyer ID; Mixpanel distinct ID; IP address; device model, operating system and version, language, time zone and carrier; app version; push notification token
  • Purpose: Operating the App, security and fraud prevention, analytics, advertising measurement
  • Legal basis (EEA/UK): Performance of a contract, for the identifiers needed to deliver the App to you; our legitimate interests in security and fraud prevention; your consent for advertising identifiers and for any other storing of, or access to, information on your device where the law requires it
  • Retention: Up to 5 years

3.2 Approximate location

  • Includes: Country and region derived from the IP address from which the App contacts our servers, and from the store country reported by Apple or Google. We do not collect precise or GPS location
  • Purpose: Regional pricing, analytics, fraud prevention, suggesting a nearby server location
  • Legal basis (EEA/UK): Performance of a contract; our legitimate interests
  • Retention: Up to 5 years

3.3 Usage events

  • Includes: App launches, sessions, screens viewed, features used, permissions granted or denied, paywalls shown, offers presented, buttons tapped, the A/B test variant assigned to your installation, notifications opened; VPN connect and disconnect actions, whether a connection attempt succeeded or failed and the type of error, the server location and protocol selected, and the results of any speed test you run. These events record that you used the VPN, not what you did while connected — see Section 2
  • Purpose: Operating and improving the App, running experiments
  • Legal basis (EEA/UK): Your consent, where the law requires it for storing or accessing information on your device; otherwise our legitimate interests in understanding how the App is used, improving it and testing changes
  • Retention: Up to 5 years

3.4 Subscription and purchase data

  • Includes: Product purchased, price, currency and billing period; trial started, converted, active, expired, cancelled or refunded; store transaction identifier; subscription identifier; country of purchase
  • Purpose: Providing and managing your subscription, customer support, accounting and tax
  • Legal basis (EEA/UK): Performance of a contract; legal obligation
  • Retention: For the duration of your subscription, then for as long as required for accounting, tax and the establishment or defence of legal claims

3.5 Attribution and advertising data

  • Includes: Campaign, ad network, ad set, creative and click data; store referrer data; aggregated conversion reports provided to us by Apple (SKAdNetwork / AdAttributionKit) and Google
  • Purpose: Measuring and targeting our advertising
  • Legal basis (EEA/UK): Your consent, where required, for advertising identifiers and for tracking across other companies’ apps and websites; our legitimate interests in measuring the effectiveness of our own advertising where consent is not required
  • Retention: Up to 5 years

3.6 Account data

  • Includes: Email address, first name and last name — provided by you, or received from Apple or Google if you sign in with your Apple or Google account, together with an identifier for your account with that provider. If you use Sign in with Apple and choose to hide your email, we receive a private relay address instead. We never receive your Apple or Google password. If you sign in by email, the one-time sign-in codes and links we send you, which expire shortly after they are issued
  • Purpose: Creating and securing your account, signing you in, restoring your purchases across devices, sending you account-related emails
  • Legal basis (EEA/UK): Performance of a contract
  • Retention: Until you delete your account. Sign-in codes and links are discarded once used or expired

3.7 Support correspondence

  • Includes: Your email address, the content of your message, and anything you choose to attach
  • Purpose: Answering you and fixing what you report
  • Legal basis (EEA/UK): Performance of a contract; our legitimate interests
  • Retention: Up to 3 years after the matter is closed

3.8 Diagnostics

  • Includes: Crash reports, error logs, stack traces, the technical state of the App at the time of an error, and diagnostic information about whether and how a VPN connection attempt failed
  • Purpose: Identifying and fixing crashes, errors and connection problems
  • Legal basis (EEA/UK): Our legitimate interests
  • Retention: Up to 5 years

3.9 Payments

We never receive or store your card number, CVV, bank details or billing address. Purchases made in the App are processed by Apple or Google, who act as independent controllers of the payment information you give them. If you purchased your subscription elsewhere — for example on our website — that purchase is governed by the privacy notice shown to you at the time of purchase.

3.10 What we do not collect

We do not collect precise location, biometric or health data, government identification numbers, financial account numbers, or any special-category data, and we do not record the content of other apps. We do not collect your browsing history, the websites or services you connect to, the content of your traffic or your individual DNS queries — see Section 2. Please do not send us such information.

3.11 Content that stays on your device

Your preferences — such as favourite server locations, the protocol you selected and the App’s settings — are stored locally on your device. We do not transmit them to our servers and we cannot see them. This content may be included in an iCloud or Google backup of your device if you have enabled one; those backups are governed by Apple’s and Google’s privacy policies, not by ours.

4. Advertising and tracking choices

  • iOS. We ask for your permission through Apple’s App Tracking Transparency prompt before accessing your advertising identifier or tracking you across other companies’ apps and websites. If you decline, we do not access it. You can change this at any time in Settings → Privacy & Security → Tracking.
  • Android. You can delete or reset your Advertising ID and opt out of personalised advertising in Settings → Privacy → Ads.
  • Meta. We use Meta’s SDK and Conversions API to measure our advertising and to build and exclude audiences. We send Meta events describing your interaction with the App — for example an install, a trial start or a purchase — together with device and advertising identifiers, and, where you have provided it, an irreversibly hashed version of your email address so that Meta can match the event to a Meta account. We never send Meta anything about your online activity through the VPN. Meta processes this both on our behalf and for its own purposes: https://www.facebook.com/privacy/policy. You can review and control what businesses share with Meta at https://www.facebook.com/off-facebook-activity
  • Push notifications. You can disable these in your device settings. You will still receive essential messages about your subscription.
  • Do Not Track. We do not respond to browser "Do Not Track" signals, as there is no accepted standard for them. We do honour the Global Privacy Control signal where the law requires it.

5. Who we share your information with

We do not sell your information for money. We do disclose it as set out below, and we do "share" it for cross-context behavioural advertising as that term is defined by certain US state laws — see Section 8. Nothing about your online activity through the VPN is disclosed to anyone, because we do not have it — see Section 2.7.

5.1 Service providers

Each of the following processes personal information on our behalf. We contractually require them to protect it to the standard set out in this Privacy Policy and to use it only on our instructions. This list reflects our principal recipients; we also use other providers in the same role, including for hosting and infrastructure.

  • RevenueCat, Inc. — processor. Subscription management, purchase validation, entitlements, offer configuration and subscription analytics. https://www.revenuecat.com/privacy
  • AppsFlyer Ltd. — processor. Marketing attribution and campaign measurement. https://www.appsflyer.com/legal/services-privacy-policy/
  • Mixpanel, Inc. — processor. Product analytics. https://mixpanel.com/legal/privacy-policy/
  • Google (Firebase Analytics, Crashlytics, Cloud Messaging) — processor. Analytics, crash reporting, push delivery and remote configuration. https://firebase.google.com/support/privacy
  • Functional Software, Inc. d/b/a Sentry — processor. Error monitoring. https://sentry.io/privacy/
  • Sinch Email (Mailgun) — processor. Delivery of sign-in codes and account emails. https://www.mailgun.com/legal/privacy-policy/

5.2 Independent controllers

  • Meta Platforms, Inc. and Meta Platforms Ireland Ltd. — joint controller with us for the collection of the event data described in Section 4 and its transmission to Meta, and an independent controller for everything Meta subsequently does with that data. Advertising measurement, audience building and targeting. In the EEA and the UK this arrangement is governed by Meta’s Controller Addendum. In essence: we are responsible for having a lawful basis for that collection and transmission and for telling you about it, and Meta is responsible for the processing that follows. You may exercise your rights against either of us, whatever that arrangement says between us. https://www.facebook.com/privacy/policy
  • Apple Inc. and Google LLC — independent controllers. Payment processing, store distribution and, if you use it, sign-in with your Apple or Google account. They provide us with subscription status, aggregated measurement data and the account details described in Section 3.6, and handle your payment and account information under their own privacy policies.

5.3 Other disclosures

  • Our professional advisers, where necessary
  • An acquirer, successor or assignee and its advisers, in connection with a merger, acquisition, financing, sale of assets or insolvency, including for the purpose of due diligence
  • Any party, where we believe in good faith that disclosure is necessary to comply with the law or an enforceable governmental request, to enforce our Terms of Service, or to detect, prevent or address fraud, security issues or harm to any person. We assess the authority of any body making such a request before responding. Where a request concerns your online activity or connection history, we are unable to provide it, because we do not hold it — see Section 2.1

6. International transfers

Our servers and most of our providers are located in the United States. Our VPN servers are located in the countries shown in the App; they hold no activity or connection logs, so connecting through a server in a given country does not result in your personal information being stored there.

If you are in the EEA, the UK or Switzerland, your information is therefore transferred outside your country. We rely on the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), on your explicit consent, or on another mechanism permitted by law. You can request a copy of the safeguards at support@captain.show

7. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you and obtain a copy of it
  • Correct information that is inaccurate or incomplete
  • Delete your personal information
  • Port it to another provider in a structured, commonly used, machine-readable format
  • Object to or restrict processing based on our legitimate interests
  • Withdraw consent at any time, without affecting processing carried out beforehand
  • Opt out of the sale or sharing of your personal information and of targeted advertising — see Section 8
  • Not be discriminated against for exercising any of these rights
  • Complain to a data protection supervisory authority. If you are in the EEA, the UK or Switzerland, you may lodge a complaint with the authority in the country where you live or work, or where you believe the law has been broken. We would rather resolve the matter first: please write to support@captain.show.

How to exercise them. Write to support@captain.show. You may use an authorised agent, whose authority we may ask to verify.

Verification. We will take reasonable steps to verify your identity first, which may mean asking you to submit the request from the email address associated with your account or purchase. Some information we hold is tied only to a pseudonymous device identifier and cannot be reliably linked to an individual; where we cannot verify that it relates to you, we will tell you and will not disclose it.

Timing. We respond within the period the law requires — generally one month in the EEA and the UK, and 45 days in the United States.

Providing information. You are not obliged to give us personal information, but some of it is necessary for the App to work, and without it some features will be unavailable.

8. Additional information for residents of the United States

This Section applies if you live in a state with a comprehensive consumer privacy law, including California, Colorado, Connecticut, Virginia, Texas, Oregon and others.

8.1 Categories we collect

  • Identifiers
  • Personal records (name, email address)
  • Commercial information
  • Internet or other similar network activity
  • Approximate geolocation data
  • Inferences

These are described in Section 3, collected for the purposes set out there, disclosed to the recipients listed in Section 5, and retained for the periods stated. "Internet or other similar network activity" here means your interaction with the App itself; we do not collect your browsing history, the contents of your communications or any other record of your activity through the VPN — see Section 2.

We do not collect sensitive personal information in order to infer characteristics about you. The only sensitive personal information we handle is the credential that lets you sign in to your account, and we use it solely to authenticate you and to keep your account secure — a purpose for which California law does not require us to offer the right to limit. We do not sell or share sensitive personal information, and we do not use or disclose it for any other purpose.

8.2 Sale and sharing

We do not sell your personal information for money. We do disclose identifiers, approximate location, usage data and subscription events to advertising platforms — principally Meta — in order to measure and target our advertising. This is data the App collects about your use of the App itself; nothing about your activity through the VPN is included, because we do not collect it — see Section 2.7. Under the California Consumer Privacy Act and similar state laws, this constitutes a "sale", a "share" for cross-context behavioural advertising, and targeted advertising.

We do not sell or share the personal information of anyone we know to be under 16 years of age.

8.3 How to opt out

Two methods are available. They do different things.

  • Device controls. Declining Apple’s App Tracking Transparency prompt on iOS, or resetting your Advertising ID and opting out of ads personalisation on Android, stops us accessing your advertising identifier and stops that identifier being included in anything we send to advertising platforms. It does not stop the events themselves: we also send Meta server-side events through its Conversions API — describing, for example, an install, a trial start or a purchase, together with an irreversibly hashed version of your email address where we have one — and those continue.
  • Full opt-out. To opt out of all sale, sharing and targeted advertising, including the server-side events described above, email support@captain.show with the subject line "Do Not Share My Personal Information".

8.4 Your rights

In addition to those listed in Section 7, you have the right to confirm whether we are processing your personal information, to know the categories and sources, and to obtain the specific pieces we hold. California residents may request access twice in any twelve-month period.

You also have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. We do not carry out such profiling — see Section 10.

8.5 Appeals

If we decline to act on your request we will tell you why. You may appeal by replying to our response, or by writing to support@captain.show with the subject line "Privacy Request Appeal". We will respond in writing within 45 days. If your appeal is denied, you may submit a complaint to your state Attorney General.

California "Shine the Light" (Civil Code § 1798.83). We disclose the information described in Section 8.2 to advertising platforms that may use it for their own marketing purposes. California residents may opt out of that disclosure free of charge at any time using the methods in Section 8.3, or may instead request once a year a list of the categories of personal information we disclosed in the preceding calendar year and the recipients, by writing to support@captain.show with the subject line "Shine the Light Request".

9. Deleting your data and your account

If you have an account. You can delete your account, and the personal information held against it, from inside the App: Settings → Account → Delete Account. You can also ask us to delete it by writing to support@captain.show from the email address registered to the account. Deletion is permanent and cannot be undone.

If you use the App without an account. To have the information associated with your installation deleted, open the App and go to Settings → Get Help, or write to support@captain.show. Because that information is held only against a pseudonymous device identifier, we may need you to send the request from the device concerned, or to give us that identifier, before we can locate the right records.

We delete the data from our production systems within 30 days and from our backups within 90 days, and we forward the request to the providers listed in Section 5 that hold data about you. There is no VPN activity or connection history to delete, because we never record it.

We may keep a limited amount of information where the law requires or permits it:

  • Records of your purchases, for accounting and tax purposes
  • Records needed to establish or defend legal claims
  • A minimal record of the deletion request itself, so that we can demonstrate we honoured it

Cancelling a subscription is not the same as deleting your data or your account. Subscriptions purchased through the App Store or Google Play are billed by Apple or Google and must be cancelled through your Apple or Google account settings; a subscription purchased elsewhere must be cancelled where you bought it. Deleting your account or your data does not cancel your subscription — you may continue to be charged until you cancel it — and cancelling your subscription does not delete your data.

Deleting your account or your data does not remove the VPN configuration from your device. You can remove it in your device or system settings, or by uninstalling the App.

10. A/B tests and personalised offers

We continuously test the App. Your installation may be assigned — usually at random — to a group that determines which version of a screen you see, which subscription offer or price is presented to you, and the wording used. We also analyse usage and subscription data in aggregate to decide which offers to make available.

We do not make decisions based solely on automated processing that produce legal effects concerning you or that similarly significantly affect you. Differences in the offers shown do not restrict your access to the App’s functionality.

11. Children

The App is intended for a general audience and is not directed to children. We do not knowingly collect personal information from anyone below the minimum age set out in our Terms of Use: 13, or the higher age required by the law of your country — in parts of the European Economic Area that age is 14, 15 or 16. If you are below that age, please do not use the App.

If you are a parent or guardian and believe your child has given us personal information, write to support@captain.show and we will delete it promptly.

12. Security

We maintain technical and organisational measures designed to protect personal information against loss, misuse and unauthorised access, including encryption in transit, access controls granted on a need-to-know basis, and the use of reputable infrastructure providers. Traffic between your device and our VPN servers is encrypted for the whole of its journey through our infrastructure. No system is completely secure, and we cannot guarantee the security of information transmitted over the internet.

You are responsible for keeping your account secure. Because you sign in with a code or link sent to your email address, or through your Apple or Google account, anyone with access to that mailbox or account can access your World VPN account; please keep them protected. Tell us immediately at support@captain.show if you believe your account has been compromised.

If we become aware of a breach likely to affect you, we will notify you and the relevant authorities where the law requires.

13. Changes, and how to contact us

We may update this Privacy Policy. When we do, we will change the effective date shown above. If the changes are material we will give additional notice — in the App or by email — before they take effect, where the law requires.

Essa Studio MCHJ

2 Bodomzor Street, Shayx Shivli MFY, Tashkent, Uzbekistan

Privacy requests: support@captain.show

WORLD VPN
Essa Studio MCHJ2 Bodomzor Street, Shayx Shivli MFYTashkent, Uzbekistan

Contact

support@captain.show

© 2026 World VPN. All rights reserved.

  • Privacy Policy
  • Terms of Use