Snapshot of the source text at fetch time, not a live mirror of the policy page.
Plain-English summary
Using Windscribe's website or service entails some data collection, though the company makes strong commitments to minimize user data and protect privacy. When visiting the website, browser and partial IP data are collected for analytics (data_use-1). If purchasing a premium account, payment transaction IDs are stored for 30 days for fraud prevention (data_use-2). Upon leaving the service, your username, password, and any provided email address will remain (data_use-3). There is no information regarding automatic renewals, cancellation, or refund policies in the provided text.
89% confidence
Ask Verbaterm
Follow up on findings with grounded answers from this review. Not legal advice.
Risk Flags
Critical issues that pose significant risks to individuals, such as weak data security, severe limitations on user rights, or potential for financial harm.
Not clearly stated: The policy effectively states that no historical logs are kept that could tie activity to a specific account due to shared IPs and minimal data storage. Therefore, we do not identify risk flags related to activity logging or identifying specific users from IP addresses.
Data Use
Practices related to the collection, processing, sharing, and retention of personal data.
Not clearly stated: The policy states that it does not use 3rd party tracking or analytics services other than self-hosted Piwik. Also, it explicitly lists what data is not stored, such as historical VPN sessions, source IP, or sites visited, and clarifies that anything not mentioned is not stored. This addresses potential concerns about extensive data collection or sharing.
low95% confidence
Website analytics collect browser and IP data
When you visit their website, a JavaScript code collects information such as your browser user-agent, language, screen resolution, referring website, and a subset of your IP address (first 3 octets) for analytics.
Why it matters: Your browser and a partial IP address are collected for website analytics when you visit the website.
When your web browser loads a page on our site, a small snippet of JavaScript code is executed within your browser which submits information such as your browser user-agent, language, screen resolution, referring website, and a subset of your IP address (first 3 octets).
When You Visit Our Website, paragraph 1 · Citation strength: strong
low90% confidence
Payment transaction IDs stored for fraud prevention
When you pay for a premium account, the transaction ID of your payment is stored for a period of 30 days for fraud prevention purposes.
Why it matters: Your payment transaction ID is kept for 30 days when you pay for a premium account.
We use 3rd party payment processors. When you pay for a premium account, we store the transaction ID of your payment for a period of 30 days for fraud prevention purposes.
When You Sign Up, paragraph 1 · Citation strength: strong
low90% confidence
Account data retained after account deletion
If you stop using the service, your username, password, and email address (if provided) will remain.
Why it matters: Even after you stop using the service, certain account details like your username, password, and potentially your email address will be retained.
If for some strange reason you decide not to use our service anymore, the only piece of information that will remain is your username, password and email address (if you provided it).
When You Leave, paragraph 1 · Citation strength: strong
Cancellation and Renewal
Terms related to how users can cancel their service, manage renewals, and any associated refund policies.
Not clearly stated: The policy does not address automatic renewal terms, cancellation policies, or refund options for paid services. There is no information provided about how or if subscriptions automatically renew or what steps are required to cancel them.
Gotchas
Less obvious clauses that might have surprising implications for users.
Not clearly stated: The policy includes a hypothetical scenario about drastic policy changes due to "giant spiders." This appears to be a lighthearted way of communicating that changes would only occur under extreme circumstances, making it difficult to classify as a typical "gotcha" with concrete user impact.
Protections
User-friendly clauses and beneficial practices that enhance user rights, privacy, and control.
Not clearly stated: The policy generally provides strong protections against data logging and third-party tracking, making positive commitments explicit.
Protection95% confidence
No 3rd party tracking or analytics (except self-hosted)
They do not use any 3rd party tracking or analytics services, ensuring that your activity on their website stays with them and your ISP, using only open-source Piwik web analytics hosted on their servers for aggregated usage data.
Why it helps: This commitment means your browsing data on their website is not broadly shared with external advertising or tracking companies, limiting the scope of behavioral profiling.
We do not use any 3rd party tracking or analytics services, so your activity on this website stays with us (and your ISP). We use open source Piwik web analytics platform to measure usage on our website, which is hosted on our servers. Piwik is used to analyze in aggregate information about our website visitors.
When You Visit Our Website, paragraph 1 · Citation strength: strong
Protection90% confidence
Minimal registration data collected
They only require a username and password to sign up for their service; providing an email is optional, intended for password recovery and service updates.
Why it helps: This reduces the amount of personal information you must provide to create an account, enhancing your privacy at registration.
We only require a username and password when you signup to our service. Email can be provided if you wish to be able to recover your password in case you forget it, as well as receive periodic service updates.
When You Sign Up, paragraph 1 · Citation strength: strong
Protection95% confidence
No storage of historical VPN sessions or browsing history
The policy explicitly states that historical records of VPN sessions, source IP addresses, and sites visited are not stored.
Why it helps: This commitment helps protect user anonymity by ensuring that past browsing activities or specific IP addresses are not linked to your account over time.
* Historical record of VPN sessions * Source IP * Sites you visited
When You Use Our Service, paragraph 4 · Citation strength: strong
Protection90% confidence
Temporary storage of connection data within server memory
Data such as your OpenVPN/IKEv2 username and time of connection are stored only in the server's memory for the duration of your connection and are immediately discarded upon disconnection.
Why it helps: This practice minimizes the retention of real-time connection data, ensuring that ephemeral details are not permanently logged or associated with your account.
For the duration of your connection the following is stored in **server’s memory**. This data is immediately discarded when you disconnect:
When You Are Actively Connected to a Server, paragraph 1 · Citation strength: strong
Protection90% confidence
Ability to delete your account
You have the option to delete your account at any time through the "My Account" section.
Why it helps: This provides users with practical control over their account and the ability to exit the service and its data retention policies when desired.
You can delete your account at any time in the "My Account" section.
When You Leave, paragraph 1 · Citation strength: strong
Protection90% confidence
Minimal data storage makes user data requests yield 'nothing of value'
Due to storing only the bare minimum data and not keeping historical logs of IP addresses or connecting activity to specific accounts, any request for user data is stated to yield "nothing of value."
Why it helps: This statement suggests a strong commitment to data minimization, which can protect users by making it difficult for third parties to obtain meaningful personal data even with a legal request.
Since we store the bare minimum for a customer to actually use our service, any request for user data would yield nothing of value. As we do not store any historical logs on who used which IP address, and since IPs are shared by dozens/hundreds of people at any given moment, so we cannot tie any activity to a specific account.
User Data Requests, paragraph 1 · Citation strength: strong
Report an issue
Flag a citation problem, stale policy text, or incorrect company match.
Verbaterm boundaries
This public review is informational only and is not legal advice. Verbaterm shows only findings tied to the cited source snapshot above.