Privacy Policy
Last updated: October 2, 2026
This Privacy Policy explains how Esinti Yazılım Teknoloji ve Giyim Sanayi Ticaret Limited Şirketi ("Esinti", "we", "us" or "our") processes personal data when you use the Presto VPN app for iPhone and iPad (the "App"), the VPN service provided through it (the "Service") and our website prestovpn.app (the "Website").
We are the data controller under the Turkish Law on the Protection of Personal Data No. 6698 ("KVKK") and, where they apply to you, the EU General Data Protection Regulation ("GDPR") and the UK GDPR. Where these laws differ, we apply the stricter rule.
Summary
- No activity logs. We do not log the websites you visit, the IP addresses or services you connect to through the VPN, your DNS queries, or the content of your traffic.
- No sign-up. You do not give us your name, email address or phone number to use the App. The App creates an anonymous account that is linked to a device identifier.
- Connection records. We do keep records of your VPN connections: when a connection started and ended, which server and protocol you used, how much data was transferred, and the approximate country and network operator you connected from. We keep these records for 90 days. We also keep running totals for your account, such as the number of connections and the total data used, for as long as your account exists.
- App setup steps. For a new installation, once you accept the privacy screen, the App tells us which setup steps it went through and when (for example the intro screens, the subscription offer screen and your first connection), with your approximate country. This is linked to your anonymous account, contains no free text, and is kept for 90 days (Section 3.12).
- We do not store your IP address in our databases. We use it at the moment of each request to work out your approximate country and network operator, and then discard it.
- Service providers. We use third parties for analytics, crash reporting, advertising in the free version, install attribution, subscriptions, push notifications and hosting. They are listed in Section 5.
- Your choice on tracking. Ads are personalized, and your device's advertising identifier is used for attribution, only if you allow tracking in Apple's App Tracking Transparency prompt.
- We do not sell your personal data, and we never use or share data about your VPN connections for advertising.
1. Who we are
Esinti Yazılım Teknoloji ve Giyim Sanayi Ticaret Limited Şirketi
Address: Feriköy Mahallesi, Fırın Sokak No:69/2, Bomonti, Şişli, İstanbul, Türkiye
Email: info@prestovpn.app
For anything about your personal data, email us with the subject "Privacy request". Section 11 explains how.
2. What we never collect
The App, our servers and our VPN servers are designed so that we do not collect or keep:
- the websites, domains, apps, services or IP addresses you visit or connect to through the VPN;
- your DNS queries;
- the content of your internet traffic;
- any record that links your originating IP address to your online activity;
- your name, email address (unless you email us), phone number, contacts or photos;
- your precise (GPS) location. The App does not use location services;
- your payment card details. Payments are handled by Apple.
Because we do not have this information, we cannot provide it to anyone, including in response to a legal request.
3. Data we collect and why
3.1 Your anonymous account and device identifier
The first time you open the App, it creates an anonymous account on our servers. The account is linked to a device identifier that the App derives from Apple's identifier for vendor (IDFV). The App stores this identifier in your device's keychain, so it can remain on your device after you delete and reinstall the App, and your account, subscription and free-time allowance are recognized again.
With the account we store a randomly generated account name, a session token that expires after 24 hours, the subscription linked to the account, the technical keys needed to set up your VPN connection (such as your current WireGuard public key and the server it was set up on), and the dates the account was created and last updated.
We use this data to provide the Service, recognize your subscription and free-version allowance, and keep the Service secure.
3.2 App and device information
When the App signs in, it sends us its version and build number, the platform (iOS), your device language, the region set on your device and the country of your App Store account. We use this to provide the App in your language, show the right offers and servers, support older app versions, and understand our users by country, language and app version.
The App does not send our servers your device model, operating system version, mobile carrier or Wi-Fi network name. To reconnect faster, the App remembers on your device, and only on your device, which connection method worked on which type of network, using the carrier or Wi-Fi network name where iOS provides it.
3.3 IP address and approximate location
Our servers see your IP address whenever the App communicates with them. At that moment we use it to determine the country and the network operator (the autonomous system number and name of your internet provider) you are connecting from. We do this with a geolocation database that runs on our own servers (DB-IP), or with the country provided by our network provider, Cloudflare. We store the resulting country and network operator, not the IP address. We record the country you open the App from and the country you connect from, and we may compare them with your usual country, for example to notice that you are traveling. We use this to choose suitable servers, measure service quality by country and network, and detect and prevent abuse.
While you are connected, the VPN server you use needs your IP address to send traffic back to you. The server keeps it in memory only and does not write it to disk. To determine the country and network operator of a connection, the server sends our backend only a shortened form of your IP address (the first three blocks of an IPv4 address, or the first 48 bits of an IPv6 address). The backend discards it after the lookup. If the shortened address cannot be delivered, the VPN server deletes it after at most 72 hours.
Our network and hosting providers (Cloudflare and DigitalOcean) process IP addresses to deliver and protect traffic, and may keep short-lived technical logs. Our own application logs may briefly contain IP addresses where this is needed for rate limiting and abuse prevention.
3.4 VPN connection records
When you connect, disconnect or the App changes servers, we record:
- the times a connection was requested, started and ended, and how long it lasted;
- the server, server location and protocol used, and the servers and protocols tried;
- the amount of data uploaded and downloaded during the connection;
- the private address assigned to your device inside the VPN tunnel (an internal address, not your real IP address) and a short fingerprint of the connection key;
- the country and network operator you connected from (Section 3.3);
- the result of the connection, error codes, timings and the reason it ended;
- the app version and platform, whether you were on the free version or Premium at the time, and any speed limit applied;
- signals that may indicate abuse, such as the same connection being used from many networks at the same time.
We use these records to set up and troubleshoot connections, choose working servers and protocols, measure service quality, plan server capacity, apply free-version and subscription limits, and detect and prevent abuse such as subscription sharing or attacks. We keep them for 90 days, after which they are deleted automatically.
These records cannot show which websites or services you used, your DNS queries or the content of your traffic.
3.5 Usage totals
For each account we keep running totals and summary values: number of app opens and active days, first and last seen dates, numbers of connection attempts, successful connections and failures, number of VPN sessions, total connected time, total data transferred, a breakdown by protocol and result, the time of your last connection, your last known country, and your subscription state (such as your plan, trial and billing status and number of purchases).
We use them to operate the Service, help you when you contact support, understand how the App is used, and decide which messages to show you. We keep them for as long as your account exists.
3.6 Connection reports and diagnostics
When a connection attempt finishes, the App and its VPN extension send our servers a technical report: the steps taken, the servers and protocols tried, timings, results and error codes. Error details are checked to remove IP addresses before they are stored. We use these reports to find and fix connection problems, and keep them for 90 days.
3.7 Subscriptions and purchases
Purchases are made through Apple. We never receive your payment card details. We receive and store the product purchased, transaction identifiers, purchase and expiry dates, trial and introductory-offer status, auto-renewal and billing status, the App Store environment and, where available, price and currency. We check subscription status with Apple's App Store Server API, and Adapty also manages subscriptions for us (Section 5).
We use this data to give you access to Premium, restore purchases, answer support requests, prevent fraud and meet our legal obligations.
3.8 Push notifications
If you allow notifications, we store your device's push token (provided by Firebase Cloud Messaging) with your account. We use it to send you service messages and promotional messages, for example about offers, your subscription or new features.
Some messages are sent to groups of users selected by criteria such as plan, subscription status, App Store country, language, app version or usage (for example, users who have not connected for some time). Our team can also send a message to a single account, for example to follow up on a support issue.
When you open a notification, the App tells us. If the notification leads to a purchase, the App also sends the product and the transaction identifier, so that we can measure which messages are useful. We keep these records for 90 days. You can turn notifications off at any time in iOS Settings.
3.9 Ratings, problem reports and support
- Connection rating. After you disconnect, the App may ask you to rate the connection from 1 to 5 stars. We store your rating together with the context of that connection (protocol, server, server country, the country you connected from, connected time, free or Premium, app version). There is no free-text field. We keep ratings for 90 days. This rating is private and is not an App Store review.
- Problem reports. If you report a problem in the App, we store the category you chose with your account. There is no free-text field. We keep reports for as long as your account exists.
- Email support. If you email us, we process your email address, your message and anything you include in it. If you use the App's support link, the email subject contains your device identifier so that we can find your account. We keep support emails for as long as we need them to handle your request and any follow-up.
3.10 Speed test
If you use the speed test, the App downloads and uploads test data to our servers. We use your IP address only to prevent abuse of the test; it may briefly appear in our application logs (Section 3.3). We do not store speed test results.
3.11 Security logs
- To protect accounts and investigate problems, our servers keep a log of the requests made with your session token, including their content (for example, the server you selected or subscription data sent by the App). This log is deleted after 24 hours.
- Our application and hosting logs may contain your account or device identifier and subscription data for troubleshooting. They are kept for a short period.
- Whenever a member of our team views or changes an individual account in our internal tools, we record who did it and when (Section 6).
3.12 App setup steps
When the App is newly installed, it records on your device which setup steps it goes through in its first days, and when. After you accept the privacy screen, it sends these records to our servers. Nothing is sent before you accept; if you do not accept, nothing is sent. Steps that happened before you accepted (opening the App for the first time and seeing the privacy screen) are sent after you accept. The App does not collect these records when an existing installation is updated, and it stops collecting them 8 days after it was installed.
We store, linked to your anonymous account:
- which setup steps were reached and when: opening the App for the first time, the privacy screen, the intro screens, the subscription offer screen (whether it was shown, and whether you purchased, cancelled, the purchase failed or you closed it), reaching the home screen, tapping Connect, whether a connection attempt was stopped because your free time had ended or the servers were full, whether your first connection attempt worked, and whether you opened the App again about one day and about seven days after first opening it;
- your answers to the tracking (App Tracking Transparency), notification and VPN-permission prompts;
- how long each step took, counted only while the App was on screen;
- your approximate country, determined as described in Section 3.3 when the App first sends these records (never the country of a VPN server), or, if that is not possible, the country we already hold for your account; and the country of your App Store account;
- the app version and build, the platform, and a random installation identifier that the App creates when it is first opened and stores on your device. Deleting the App deletes this identifier, so a reinstalled App starts a new record, which we mark as a reinstallation.
These records contain no free text and no advertising identifier (IDFA). The installation identifier is not given to Firebase, AppsFlyer, Adapty or any other service provider, and we do not combine these records with attribution or advertising data about you. We use them to understand how new installations get through the App's setup and where people get stuck, so that we can improve it. Our internal tool shows them only as totals, for example by country, not per account. We keep them for 90 days, after which they are deleted automatically, and we delete them when we erase your connection history or your account. We do not sell them and we do not use them for advertising. You can object to this processing (Section 10).
4. Tracking, advertising and analytics choices
4.1 App Tracking Transparency
The App asks for permission to track you through Apple's App Tracking Transparency (ATT) prompt. If you allow it, Google AdMob, AppsFlyer, Adapty and Google Analytics for Firebase may access your device's advertising identifier (IDFA) to personalize ads and to measure which advertising campaigns bring users to the App. If you do not allow it, the IDFA is not available to the App or these services, ads are non-personalized, and attribution is limited. You can change your choice at any time in iOS Settings > Privacy & Security > Tracking. Your choice has no effect on the VPN.
The App does not send your IDFA to our servers, and we do not store it. When our team looks up your account, our internal tool displays the advertising identifier and tracking status that Adapty holds for your device.
4.2 Consent in the EEA, UK and Switzerland
Where the law requires it, the App asks for your consent for advertising-related processing through Google's User Messaging Platform before ads are personalized. You can review or change your choices at any time in the App under Settings > Privacy choices.
4.3 Ads in the free version
The free version shows banner, full-screen and rewarded ads (you can watch rewarded ads to get extra free time). Google AdMob may collect device information, your IP address and how you interact with ads in order to serve, limit and measure them. Ads are never based on your VPN traffic, which we do not log.
5. Service providers and third parties
We use the following providers. Each receives only the data it needs for its task.
| Provider | What it does for us | Data it processes |
|---|---|---|
| Google Firebase (Google LLC / Google Ireland Ltd.): Analytics, Crashlytics, Remote Config, Cloud Messaging, Installations | App usage analytics, crash reports, remote settings, push notifications | App events such as app opens, onboarding steps, paywall views and purchases (product, price, currency, App Store country and subscription identifiers derived from the App Store transaction), connection diagnostics (server, protocol, timings, results, error codes, Wi-Fi or cellular), rating and problem-report events; data Firebase collects automatically, such as an app instance identifier, device model, operating system version and approximate location; crash reports; push tokens. We do not give Firebase your account ID. |
| Google AdMob and Google User Messaging Platform | Ads in the free version; consent management | Device information, IP address, ad interactions, consent choices; IDFA if you allow tracking |
| AppsFlyer Ltd. | Install attribution and measuring marketing campaigns | IDFV, IDFA if you allow tracking, IP address, device information, install and in-app events (app opens; subscriptions with product, price and currency). AppsFlyer's identifier and attribution data are shared with Adapty. |
| Adapty Tech Inc. | Subscriptions, paywalls, purchase restores | Your device identifier (used as Adapty's customer ID), purchases and subscription status, paywall views, IDFV, IDFA if you allow tracking, IP address, device information, attribution data from AppsFlyer |
| Apple Inc. / Apple Distribution International Ltd. | App distribution, payments, subscription status, push delivery, promotional offers | Purchase and subscription data. When you redeem a promotional offer, your anonymous account ID is included in the offer signature. |
| Cloudflare, Inc. | Network delivery and protection for our servers and Website; public DNS resolver (1.1.1.1) | IP addresses and request data in transit; DNS queries that reach it from our VPN servers |
| Google Public DNS | DNS resolution for some VPN protocols | DNS queries that reach it from our VPN servers |
| DigitalOcean, LLC | Backend servers, databases and some VPN servers | All data we store (our backend application runs in Frankfurt, Germany); VPN traffic in transit |
| Hetzner Online GmbH | VPN servers | VPN traffic in transit |
| Amazon Web Services (Amazon Lightsail) | VPN servers | VPN traffic in transit; server performance metrics that contain no personal data |
| Lovable | Website hosting and website analytics | See Section 13 |
DNS. While you are connected, your DNS queries are resolved through public DNS resolvers, such as Cloudflare (1.1.1.1) and Google Public DNS (8.8.8.8), via our VPN servers. These resolvers see the queries coming from our VPN server, not from your IP address. We do not log DNS queries.
We require our service providers to protect personal data with the same or an equal level of protection as described in this Privacy Policy, through their terms of service and data processing agreements. Each provider's own privacy policy also applies: Firebase · Google · Google ads · AppsFlyer · Adapty · Apple · Cloudflare · DigitalOcean · Hetzner · AWS
6. Who can see your data and when we share it
6.1 Our team
A small number of authorized team members can access account data through an internal administration tool. It uses individual staff accounts and role-based permissions, and it records every time someone views or changes an individual account. Depending on their role, team members can see an account's device identifier, app and device information, approximate country information, subscription details, usage totals, connection records (including tunnel addresses, network operator and data volumes), ratings, problem reports, push notification history and the account's Adapty profile. Team members can also see statistics about the App's setup steps (Section 3.12), which our internal tool shows only as totals, not per account. They can send a notification to an account, apply or remove a speed limit, end an active VPN session and erase an account's connection history, which also erases its setup-step records. They use this access to provide support, run and protect the Service, and handle privacy requests.
6.2 Service providers
We share data with the providers in Section 5 only so that they can provide their services to us.
6.3 Legal requests
We disclose personal data to courts, law enforcement or other public authorities only when we are legally required to do so under applicable law, and only the data we actually hold at the time of the request. We cannot provide browsing history, DNS queries, traffic content or any record linking your IP address to your online activity, because we do not keep them. Data we do hold, such as connection records (for up to 90 days), usage totals and subscription data, may be disclosed when a valid and binding legal request requires it.
6.4 Business transfers
If we are involved in a merger, acquisition or sale of assets, personal data may be transferred to the buyer, who will remain bound by this Privacy Policy.
6.5 Our commitment on VPN data
We do not sell, rent or trade personal data. We do not sell, use or disclose to third parties any data collected through the VPN service for any purpose other than providing, securing and improving the Service as described in this Privacy Policy, or where we are legally required to do so. We never use data about your VPN connections for advertising.
7. Why we use your data and our legal bases
| Purpose | Main data | Legal basis |
|---|---|---|
| Providing the VPN, your account and your connections | Account and device identifier, app information, connection data, IP address (only at the moment of use) | Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Subscriptions, restores and purchase records | Purchase and subscription data | Performance of a contract; legal obligation for financial records (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)) |
| Security, fraud and abuse prevention, applying plan limits | Connection records, usage totals, security logs, staff access logs | Legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)); establishing, exercising or defending legal claims (KVKK Art. 5(2)(e)) |
| Service quality, troubleshooting and improving the App | Connection reports, diagnostics, ratings, problem reports, analytics, crash reports | Legitimate interests; consent where the law requires it |
| Understanding how new installations get through the App's setup steps, and improving them | App setup steps (Section 3.12) | Legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)); consent where the law requires it. You can object (Section 10) |
| Customer support | Support emails, account data | Performance of a contract; legitimate interests |
| Push notifications, including promotional ones | Push token, usage totals, notification records | Consent, which you give through the iOS notification permission (GDPR Art. 6(1)(a); KVKK Art. 5(1)) |
| Personalized ads and attribution with your IDFA | Advertising and attribution data | Consent through the ATT prompt and, where applicable, the consent form |
| Non-personalized ads, attribution without IDFA, analytics | Device, usage and ad data | Legitimate interests (keeping the free version available and measuring our marketing); consent where the law requires it |
| Complying with the law and responding to authorities | Data needed for the request | Legal obligation |
Where we rely on legitimate interests, we have balanced them against your rights. You can object (Section 10). Where we rely on consent, you can withdraw it at any time, without affecting processing that took place before.
8. International transfers
We are based in Türkiye. Our backend application runs in DigitalOcean's Frankfurt, Germany region. Our VPN servers are located in the countries shown in the App, and several of our service providers are located in, or process data in, the United States, the European Union, Israel and other countries.
When we transfer personal data abroad, we do so in line with Article 9 of KVKK, based on an adequacy decision, appropriate safeguards such as standard contracts, or the limited exceptions the law allows. Where GDPR applies, transfers to countries without an adequacy decision rely on safeguards such as the European Commission's Standard Contractual Clauses, or on certification under the EU–U.S. Data Privacy Framework where the recipient is certified.
9. How long we keep data
| Data | How long |
|---|---|
| Session token and request log | 24 hours |
| VPN connection records, connection reports and error records | 90 days |
| Connection ratings | 90 days |
| App setup steps | 90 days; the App deletes its copy on your device 8 days after it was installed |
| Notification open and purchase records | 90 days |
| Data on a VPN server while you are connected | In memory only, for the duration of the connection |
| Connection records waiting on a VPN server to be delivered to our backend | Until delivered, at most 7 days; the shortened IP address at most 72 hours |
| Account, device identifier, app and device information, approximate country, usage totals, problem reports, push token and the notifications sent to your account | As long as your account exists, or until you ask us to delete them |
| Subscription and purchase records | As long as your account exists and, where the law requires us to keep financial records, up to 10 years |
| Staff access records | As long as needed for security and accountability |
| Support emails | As long as needed to handle your request and any follow-up |
| Records of privacy requests | 3 years after the request is closed |
Data held by our service providers is kept according to their own retention settings and policies.
10. Your rights
Depending on where you live, you have some or all of the following rights:
- Under GDPR and UK GDPR: access, rectification, erasure, restriction of processing, data portability, objection (including to direct marketing and to processing based on legitimate interests), withdrawal of consent at any time, and lodging a complaint with your local data protection authority.
- Under KVKK (Article 11): to learn whether your personal data is processed; to request information about it; to learn the purpose of processing and whether data is used in line with that purpose; to know the third parties in Türkiye or abroad to whom data is transferred; to request correction of incomplete or inaccurate data; to request deletion or destruction under Article 7; to request that third parties to whom data was transferred be notified of such correction or deletion; to object to a result against you that arises from analysis exclusively by automated systems; and to claim compensation for damage caused by unlawful processing. You may also complain to the Personal Data Protection Board (kvkk.gov.tr).
- Other laws may give you similar rights. Contact us and we will respond in line with the law that applies to you.
11. How to exercise your rights or delete your data
- Contact us. In the App, open Settings > Support to email us. The email subject will include your device identifier, which we need to find your account. You can also write to info@prestovpn.app with the subject "Privacy request", or send a letter to the address in Section 1.
- Verification. Because your account is anonymous, we may ask for information that shows the account is yours, such as the device identifier from the App's support email or details of an App Store purchase.
- Response. We respond free of charge within 30 days. Where GDPR applies and the request is complex, we may extend this as the law allows and tell you why.
Deleting your data. When you ask us to delete your data, we delete your account and the data linked to it: device identifier, push token and notification history, app and device information, approximate country, usage totals, connection records, ratings, app setup steps and problem reports. We keep only what we must keep by law, such as financial records of purchases. We also ask Adapty and AppsFlyer to delete the data they hold for your device where their systems allow it. Firebase analytics data is not linked to your account, so we cannot locate it; Google deletes it according to its retention settings.
Deleting your data does not cancel your subscription. Cancel it in your Apple ID settings (Settings > [your name] > Subscriptions). Deleting the App from your device does not delete the data on our servers, and the device identifier stored in your keychain may connect a reinstalled App to the same account.
12. Automated decisions and profiling
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
We use automated rules to apply plan limits (for example, the free version's time limits and any speed limits), to choose servers and protocols for you, and to flag possible abuse. We also group users by criteria such as plan, subscription status, country, language, app version and usage to decide which in-app or push messages to show. If an automated check leads us to restrict your access, you can contact us and ask for a person to review it. You can object to the use of your data for promotional messages at any time.
13. Our Website
Our Website, prestovpn.app, is built and hosted with Lovable and delivered through Cloudflare.
- Website statistics. To understand how the Website is used, it records page views together with the page visited, the referring page, your browser's user agent, language and approximate country, and page performance measurements. These are linked to a random session identifier stored in a cookie (
session-id) that expires after 30 minutes. - Security and delivery. Cloudflare may set a cookie (
__cf_bm) to tell people from bots, and our hosting provider sets a technical cookie (__dpl) to serve the correct version of the site. - Fonts. The Website loads fonts from Google Fonts, which receives your IP address.
The Website has no advertising cookies, no sign-up and no forms. If you email us from the Website, Section 3.9 applies.
14. Security
We protect personal data with technical and organizational measures appropriate to the risk, including encrypted VPN tunnels, signed session tokens, access limited to authorized team members with individual accounts and role-based permissions, records of staff access, and short retention periods. No system is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs, we will notify the competent authorities and affected users as required by law.
15. Children
The App and the Service are intended only for people aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has used the App, contact us and we will delete the related data.
16. Changes to this Privacy Policy
We may update this Privacy Policy as the App and the Service change. We will post the new version on this page and change the "Last updated" date. If the changes are material, we will tell you in the App or by other appropriate means before they take effect.
17. Contact and complaints
Esinti Yazılım Teknoloji ve Giyim Sanayi Ticaret Limited Şirketi
Address: Feriköy Mahallesi, Fırın Sokak No:69/2, Bomonti, Şişli, İstanbul, Türkiye
Email: info@prestovpn.app
If you are not satisfied with our response, you can complain to the Personal Data Protection Board in Türkiye or, if you are in the EEA, the UK or Switzerland, to your local data protection authority. We would appreciate the chance to address your concern first.