Transparency Report
How SafePassVPN handles legal requests, government inquiries, and privacy-related matters — the requests we have received during the reporting periods listed, and how we responded.
Last updated: September 27, 2026
Warrant Canary
Last verified September 27, 2026. As of that date, SafePassVPN confirms the following statements are true. If any of these statements are ever removed, users should treat that as a signal that our legal situation has changed.
We have NOT received any National Security Letters.
We have NOT received any binding gag orders.
We have NOT been compelled to install any backdoor or surveillance software.
We have NOT disclosed any private encryption keys.
We have NOT been forced to modify our systems to allow access by any third party.
We have NOT provided bulk access to user traffic to any government or agency.
What We Store vs. What We Don't
We do NOT store
We store for VPN and account operations
This list covers VPN and account operations; our Privacy Policy is the full inventory of the data we process, including app analytics and advertising data. Connection records are retained in accordance with our retention practices and applicable Indian legal requirements, and may be disclosed when required or permitted by applicable law, including in response to a valid legal request. We have no record of the sites you visit to give.
Server Infrastructure
How our servers are set up to protect your privacy:
VPN servers don't record your activity
Our VPN servers never record the websites you visit, your DNS queries, or the content of your traffic.
Connection records are kept separately
Connection records are stored on a separate, access-restricted system — not on the VPN servers you connect to.
Modern encryption
Every connection uses a modern, audited VPN protocol. In current app versions, your device generates its own private key, which never leaves your device — we only receive the public key.
DMCA & Government Requests
The table below shows the DMCA notices and government inquiries SafePassVPN received during the reporting periods listed, and the outcome of each. We will update this quarterly.
| Period | DMCA Notices | Gov. Inquiries | User Data Disclosed |
|---|---|---|---|
| Jan 1 – Mar 31, 2026 | 1 | 0 | 0 |
| Apr 1 – Jun 30, 2026 | 0 | 0 | 0 |
| Jul 1 – Sep 27, 2026 | 0 | 0 | 0 |
DMCA Incident — February 2026
SafePassVPN received a DMCA notice forwarded by our infrastructure provider relating to torrenting activity originating from one of our VPN server IPs. We responded by implementing infrastructure-level controls on that server. We did not identify or disclose the individual user. At the time, SafePassVPN did not keep connection records, so no user could be identified from the notice. No user data was disclosed.
Beginning in September 2026, we implemented retention of the connection records described in this report as part of our compliance and operational requirements. A complaint that identifies activity on a SafePassVPN server IP does not by itself tell us which user was responsible. Where a legal request seeks user information, we review it under applicable law and can disclose only information we actually hold — never the websites you visited, DNS queries, or traffic content, because we do not collect them.
How We Handle Legal Requests
We review every request carefully
We assess whether the request is legally valid, properly scoped, and issued by a jurisdiction we are legally required to comply with.
We notify users when permitted
If we receive a request and are legally allowed to inform the affected user, we will do so before complying.
We push back on overbroad requests
We challenge requests that are vague, overly broad, or lack proper legal basis.
Questions about this report?
If you're a researcher, journalist, or user with questions about our privacy practices or this report, reach out directly.
contact@safepassvpn.com