Overview
StekVPN is a VPN app for iOS and Android, operated by De Nieuwe Stek B.V. (Amsterdam, the Netherlands). De Nieuwe Stek B.V. is the controller of the personal data described here. This policy says what the app, our servers and this website keep, where, for how long, and why. It describes the service as it runs on the date at the top of this page.
StekVPN is not a no-logs VPN. Each server keeps a short connection log, so that an abuse complaint about one of our addresses can be traced to a single session. Section 02 says exactly what that log holds.
For 14 days, each server keeps which session used which tunnel address, and from which IP address it connected. We do not record which websites you visit or what your traffic contains. You need no account, and we sell nothing to anyone.
What we keep, where, and for how long
This table lists everything we keep about the use of StekVPN. Each row is a separate record with its own period, and nothing is kept longer than its row says.
| What it holds | Where | How long | Why, and on what legal basis | |
|---|---|---|---|---|
| Connection log | Every IP address a session connects from (without the port), the tunnel address the session was given, the session's public key, and the time (UTC) whenever one of these changes. | Only on the server of the location you chose. Logs are never copied between servers or combined. | 14 days. Each day's file is deleted automatically, on the server itself, once it is 14 days old. | To trace an abuse complaint (one of our addresses, a port and a time) to one session, so we can end that session and answer the complaint. Our legitimate interest in keeping the service from being used for abuse (GDPR Art. 6(1)(f)). |
| Abuse complaints | A complaint about one of our addresses, sent by a network or host (the address, a port, a time and what was reported), and what we did about it: which session it concerned and whether we ended it. This comes from the complainant, not from you. | Our mailbox for abuse reports, abuse@denieuwestek.nl, hosted by Strato in Germany. | 12 months after the complaint was handled, or longer while a complaint or a legal claim depends on it. | To answer the complaint and show that it was acted on (Art. 6(1)(f)). |
| Session on the server | The session's public key and pre-shared key, its tunnel addresses, a peer number, and WireGuard's traffic counters and last-seen time for that key. Never your private key, which stays on your device. | The server of the location you chose. | Until the session ends. The app removes it when you disconnect. If the app cannot, the server removes it 24 hours after it last heard from your device, or after 15 minutes if the session never connected. Its counters go with it. | To provide the VPN connection you asked for (Art. 6(1)(b), performance of a contract). |
| Server operation logs | Technical logs of the servers' own services: peer numbers, times and counts. They contain no IP address of yours and no key. | Each server. | No fixed period. They are rotated by size, a few megabytes per service, so older lines are overwritten. | To keep the servers running and find faults (Art. 6(1)(f)). |
| Registration service | When the app starts a session, it asks our registration service for one. Your IP address is used as a rate-limit key, and a fingerprint of the puzzle the app solved is kept so that it cannot be used twice. The chosen location and the session's public key are passed on to that server and not stored. The app also downloads the list of servers from Cloudflare, which sees your IP address when it does. | Cloudflare's network. | The rate-limit key: 60 seconds. The puzzle fingerprint: about 3 minutes. We keep no request logs, for registration or for the server list. | To stop automated mass registration (Art. 6(1)(f)). |
| Support email | What you write to us and your email address. | Our mailbox, hosted by Strato in Germany. | Deleted once your question has been dealt with, and no later than 12 months after our last exchange. | To answer you (Art. 6(1)(b) where it concerns the service, otherwise Art. 6(1)(f)). |
| Contact-form messages | The name, email address and message you enter in the contact form on this website. | Netlify, which hosts this website and forwards each message to our mailbox. | Deleted from Netlify once forwarded and handled. From then on it is kept as support email. | As for support email. |
| Visits to this website | Your IP address and the pages you request, as any web server receives them. | Netlify. | Kept by Netlify, as our processor, for less than 30 days, for delivery and security, then deleted. We do not receive or keep these logs. The site uses no analytics and sets no cookies. | To deliver the site and keep it secure (Art. 6(1)(f)). |
The session record is needed to provide the service: the app cannot connect without it. The connection log is a condition of offering the service (Section 07 explains what that means for an objection). Everything else, such as emailing us, is up to you.
Your traffic itself passes through the server of the location you chose on its way to its destination. The server handles it only in transit, to deliver it (Art. 6(1)(b)), and keeps none of it.
What stays on your device
The app keeps a few things on your phone only. We cannot see them:
- The VPN configuration, including the session's private key. A new key is made for every session.
- Your settings (sounds, haptics, reduce motion), that you accepted the terms, and a cached list of servers.
- A short list of sessions still to be removed from a server, so that a removal that failed can be tried again: at most 8, each dropped after 48 hours.
- The traffic totals under the dial (received, sent and session time). They are counted on your device for the current session only, and are neither stored nor sent to us.
The app contains no analytics, advertising or crash-reporting software. If you back up your phone, Apple's or Google's backup may include the app's settings, under their own privacy policies.
What we don't collect
To be clear about the negative space:
- We do not log the destinations of your traffic: no domains, no URLs, no DNS queries.
- We do not inspect, store or analyse the contents of your traffic.
- We do not require an account, a name, an email address or a phone number to use the app.
- We do not embed advertising or analytics software in the app or on this website.
- We do not sell, rent or trade any data to data brokers, advertisers or anyone else.
Inside the tunnel, DNS queries are resolved by Cloudflare's public resolver, 1.1.1.1. Cloudflare sees the address of our server, not yours, and handles the queries under its own resolver privacy policy. We do not log them.
What the records can and cannot show
The connection log identifies a session and a source IP address, not a named person. There are no accounts, names or payment details for it to be linked to.
An IP address can still identify you to whoever can match it to a subscriber, usually your internet or mobile provider. If you connect from a fixed home connection, the address in our log may point to your household.
Complaints about abuse go to abuse@denieuwestek.nl. When we receive one, we use the log of the server concerned to find the session that used the reported address and port at that time. We may end that session and tell the complainant that we acted on it. We give a source address only to an authority that is entitled to it by law.
If a Dutch authority sends a valid, legally binding request, we comply. We can only provide what the log of the server concerned holds for the last 14 days. Because each log is kept in the country of the location you chose, authorities there, or with power over the company that runs that server, may also be able to obtain it, including without our involvement. We have no traffic content and no browsing history for anyone to obtain.
Who processes it, and where
These companies process personal data on our behalf:
| Company | What it does for us | Transfer safeguard |
|---|---|---|
| Vultr (United States) | Runs our servers, except the one in Indonesia. | Standard Contractual Clauses |
| Hostinger International Ltd. | Runs our server in Indonesia. | Standard Contractual Clauses |
| Cloudflare, Inc. (United States) | Runs the registration service and the server list, and carries the registration service's requests to our servers. | EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| Netlify, Inc. (United States) | Hosts this website and its contact form. | EU-U.S. Data Privacy Framework and Standard Contractual Clauses |
| Strato AG (Germany) | Hosts our email. | Within the EU |
The connection log and the session record for a session are kept in the country of the location you chose. These are our locations today, from the same list the app shows:
- Indonesia, no EU adequacy decision
- Germany, in the EEA
- Mexico, no EU adequacy decision
- South Africa, no EU adequacy decision
- United States, EU adequacy decision for some organisations only
- India, no EU adequacy decision
- Netherlands, in the EEA
- Australia, no EU adequacy decision
For a location outside the EEA, the list says whether the European Commission has decided that the country protects personal data adequately. Where it has not, or only for some organisations, the transfer relies on the safeguard named above for the company that runs that server. A copy of these safeguards is available on request.
Apple and Google distribute the app through their stores and provide the phone's VPN and backup features. They do so as independent controllers under their own privacy policies, not on our behalf.
Your rights
You can object at any time to the processing we base on our legitimate interests, the connection log included. What an objection to the log means in practice is explained below.
Because we operate from the Netherlands, the EU General Data Protection Regulation applies to every user, wherever you live. You have the right to:
- Access the personal data we hold about you.
- Correct anything that is wrong.
- Delete it.
- Restrict our use of it while a question about it is being settled, for example while we consider an objection.
- Receive it in a machine-readable form.
- Object to processing based on our legitimate interests.
- Lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch data-protection authority.
Not every right applies to every record. The connection log is a record of what the server observed, so there is nothing in it to correct. The right to receive your data in a machine-readable form applies only to data processed to provide the service to you, not to the connection log.
How access and deletion work here
Because there are no accounts, we usually cannot tell which records are yours. Under GDPR Article 11 we do not have to collect more information about you just to find them. What we can promise without knowing who you are: the connection log deletes itself after 14 days, and a session record is removed when its session ends.
If you can tell us a session's public key, we can find that session's lines on the server concerned and delete them. The app does not show session keys today, so in most cases the 14-day expiry is the answer. We never act on a tunnel address (10.8.0.x): each one is used by different people one after another, and deleting by it would delete other people's records.
Records that an abuse complaint under investigation depends on may be kept until that investigation ends (GDPR Article 17(3)(e)).
The connection log is a condition of offering StekVPN: without it we could not answer abuse complaints, and hosts would not let us run servers. If you object to it, we will consider your objection, but in practice the only way not to be in the log is not to use the service.
To exercise any of these rights, email info@denieuwestek.nl or use the contact form. Requests are free of charge. We answer within one month. For a complex request we may extend this by up to two further months, and if we do, we tell you why within the first month. We do not use automated decision-making or profiling.
If a personal data breach is likely to put your rights and freedoms at risk, we notify the Autoriteit Persoonsgegevens within 72 hours. If the risk to you is high, we also tell you directly, without undue delay. De Nieuwe Stek B.V. has not appointed a Data Protection Officer. Privacy questions go to the address below.
Children
StekVPN is not directed at children under 16, and our terms require users to be 16 or older. We do not knowingly collect data about children. If you are a parent or guardian with a question about this, contact us at info@denieuwestek.nl.
Changes to this policy
When this policy changes, the version number and the "Last updated" date at the top of this page change with it. We do not send notices, so check this page for the current version. Earlier versions are available on request.
Contact us
Questions, requests or complaints about privacy go to:
- info@denieuwestek.nl
- Post
- De Nieuwe Stek B.V., Dapperstraat 92 D, 1093 BZ Amsterdam, the Netherlands
- Supervisory authority
- Autoriteit Persoonsgegevens
For general support, such as a server that won't connect or a feature request, please use the contact form instead: Contact