Privacy Policy
LetsGo VPN is operated by PHERUS .CO -SMC LIMITED. We provide VPN proxy services through our apps and related services. This Privacy Policy explains what information we collect, how we use it, and the choices available to you.
Information We Collect
We collect limited information needed to operate the service:
- Account information, such as your email address, display name, sign-in provider identifier, and internal user identifier.
- Subscription information, including product, purchase or transaction identifiers, status, and expiration details supplied by Apple App Store, Google Play, or our self-hosted Bitcart service. For cryptocurrency orders, this can also include the quoted fiat and cryptocurrency amounts, currency and network, deposit address, public blockchain transaction status, payment timestamps, and invoice event identifiers. Bitcart does not receive your VPN traffic, node credentials, or LetsGo authentication token.
- Device information, including an installation identifier, platform, device model, app version, push token when enabled, and device status, used to enforce device limits and protect accounts.
- On Android, when mobile services are configured, Firebase may process a Firebase installation identifier, push token, notification-delivery information, App Check integrity signals, and remote-configuration requests to deliver notifications, protect the service, and control safe feature rollout.
- Support content you choose to send, including messages and attachments. If you turn on “Attach diagnostics,” the ticket may also include app, device, subscription, connection, selected-server, connectivity-test, and redacted recent-log details. Full VPN node credentials are not included. On iOS, direct network lookups, active-node probes, and third-party connectivity checks are excluded from attached diagnostics.
- On Android, optional Firebase analytics, crash, performance, and diagnostic information may be collected only when the applicable feature and privacy controls permit it. Collection is off by default for new installations. This may include app interactions, app version, device and operating-system information, performance measurements, stack traces, and a Firebase installation identifier. We do not set your email address or VPN account identifier as a Firebase Analytics or Crashlytics user identifier. Formal Android builds leave the Sentry endpoint unconfigured. The formal iOS build does not link the native Firebase, Google Sign-In, or Sentry SDKs.
- On Android and iOS, Google Mobile Ads, its consent platform, and an enabled mediation partner such as Mintegral (Mobvista) may process consent choices, device identifiers available without App Tracking Transparency permission, IP-derived approximate location, app interactions, ad impressions, performance, fraud-prevention, crash, and diagnostic signals for eligible free users. The app requests non-personalized ads and does not request App Tracking Transparency permission on iOS. Subscribers do not receive ads.
- Referral and payout information if you use those features, including referral activity, wallet records, and the payout destination you provide.
- Limited server security logs, such as request time, IP address, endpoint, response status, and abuse-control events, used to operate and secure the service.
VPN Traffic
We do not sell your personal information. We do not use VPN traffic for advertising and do not intentionally retain the content of your browsing activity, DNS query content, or the websites and apps you access through the VPN. VPN browsing content, traffic payloads, DNS query content, node links, node credentials, and premium configuration credentials are never sent to Firebase, Google Analytics, Crashlytics, Performance Monitoring, Remote Config, Google Mobile Ads, or Mintegral. Temporary network metadata may be processed by the VPN service as needed to route connections, prevent abuse, enforce service limits, and maintain security.
The production app does not accept arbitrary custom profiles or user-supplied subscription links. Paid node configuration is generated by the LetsGo backend for the registered device and paid nodes are managed by LetsGo. Free-tier configuration is delivered through the LetsGo backend in an encrypted envelope from an administrator-configured external subscription source; those free nodes may be operated by independent providers. A node operator necessarily processes network connection data needed to carry the VPN session and is outside our direct operational control.
How We Use Information
- Provide, maintain, and improve LetsGo VPN.
- Verify subscriptions, manage account access, and enforce device limits.
- Detect abuse, fraud, security incidents, and service misuse.
- Respond to support requests and product feedback.
- Process referral rewards and requested payouts.
- Comply with legal obligations where required.
Third-Party Services
On iOS, purchases use Apple App Store and account access may use Sign in with Apple or email. The formal iOS build does not link the native Firebase, Google Sign-In, or Sentry SDKs. Google Play builds use Google Play Billing; account access may use Google Sign-In or email. Android may use Firebase Cloud Messaging, Firebase App Check, Firebase Remote Config, and, only when the applicable feature and privacy controls permit it, Firebase Analytics, Crashlytics, and Performance Monitoring; formal Android builds leave the Sentry endpoint unconfigured. Eligible free users on either mobile platform may also use Google Mobile Ads, Google's consent platform, and Mintegral (Mobvista) when enabled as an AdMob mediation source. The website, direct desktop clients, and standard Android distribution may use our self-hosted Bitcart service to create and confirm cryptocurrency orders. We also use email delivery, hosting, network, and external free-node providers. Optional support diagnostics may query a network-information service to identify an approximate country and network provider. These providers process information under their own privacy policies and platform rules.
Advertising
The first 20 minutes after first launch are ad-free. After that period, eligible free users may see one restrained Google Mobile Ads banner at the bottom of the Settings Center, one 300x250 content banner inside the dedicated Free Benefits Center, an app-open ad when returning to the foreground, and a connection-complete interstitial after the current node and latency result are displayed on the home screen. AdMob may select an approved mediation source such as Mintegral (Mobvista). Users may also voluntarily choose a rewarded ad on either approved screen; completing it hides both banners for the current app launch. Active subscription tiers are ad-free and loaded ads are disposed when paid entitlement becomes active. Android and iOS request only non-personalized ads after Google's consent platform reports that ads may be requested. The iOS app does not request App Tracking Transparency permission or use IDFA. Advertising on either platform is never based on VPN browsing, traffic, DNS queries, selected nodes, node credentials, account identity, purchase identity, or the LetsGo installation identifier.
Subscriptions and Payments
App Store and Google Play subscription payments are processed by Apple or Google. We receive purchase identifiers and subscription status needed to provide service, restore purchases, and handle refunds or cancellations, but we do not receive full payment card numbers from app-store purchases.
Where cryptocurrency checkout is offered, our self-hosted Bitcart service creates a deposit address and sends invoice-status notifications to our backend. We do not trust a notification as payment proof; the backend re-queries Bitcart through its authenticated server API before updating entitlement. The blockchain ledger and participants in the applicable network process public transaction details independently of LetsGo. We retain the minimum order, address, amount, status, event digest, and entitlement records reasonably needed to activate service, prevent duplicate credits, reconcile payments, address refunds or disputes, meet accounting requirements, and investigate fraud. A cryptocurrency order is fixed-term and is not an authorization for automatic wallet debits.
Sharing and Tracking
We do not sell personal information. We never disclose VPN browsing content, traffic payloads, DNS query content, connection destinations, node credentials, account identity, purchase tokens, or backend authentication tokens to Google Mobile Ads or Mintegral. For eligible free users, the iOS and Android apps allow Google Mobile Ads and an enabled mediation source such as Mintegral to process the limited advertising, device, interaction, approximate-location, performance, fraud-prevention, crash, and diagnostic information described above after the consent platform permits an ad request. Account, entitlement, device-limit, configuration-delivery, support, and cryptocurrency-order data is sent to LetsGo-operated services over HTTPS. Public blockchain networks independently receive and publish transaction data, but not your VPN traffic, email address, node credentials, or LetsGo authentication token from us. VPN sessions are carried by the selected node: paid nodes are managed by LetsGo, while free nodes can come from an administrator-configured external source and may be operated by independent providers. Apple separately processes App Store purchases and Sign in with Apple under its relationship with you. The iOS app does not request App Tracking Transparency permission. We may also disclose information when you direct us to do so or when required by law.
Data Retention
We retain information only as long as needed for service operation, account management, support, security, accounting, dispute resolution, and legal compliance. Session and verification records are short-lived. Billing and wallet records may be retained where required for accounting or fraud prevention.
Your Choices
On Android, you can keep optional Firebase analytics, crash reporting, and performance monitoring disabled. On Android and iOS, you can revisit advertising privacy choices where Google's consent platform makes that control available. On every platform, you can decline optional notifications, leave support diagnostics off, remove registered devices, and delete your LetsGo account in the app or through our verified web deletion form. You can cancel recurring subscriptions through Apple App Store or Google Play. Cryptocurrency purchases do not auto-renew and therefore have no recurring authorization to cancel. Account deletion anonymizes identity data and removes active sessions, devices, support data, and node credentials; payment records required for accounting, dispute handling, or fraud prevention may be retained.
Security
We use encryption in transit, restricted administrative access, hashed session tokens, and operational safeguards designed to protect information. No system can guarantee absolute security.
Children
LetsGo VPN is intended only for adults aged 18 or older. We do not knowingly collect personal information from anyone under 18. If we learn that an underage person has provided personal information, we will take reasonable steps to delete it.
International Use
Your information may be processed in countries or regions where we or our service providers operate. Those locations may have different data-protection laws from your home jurisdiction.
Changes
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new effective date.
Contact
For privacy questions, contact us at [email protected].