This policy explains what personal data Impeltech LLC ("Impeltech", "we") collects, why we collect it, how long we keep it and what you can ask us to do with it.
We keep the amount of data to the minimum a service needs to work. We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use it to build profiles of people.
Summary
| Do we log VPN traffic? | No. We do not record the sites you visit, your DNS queries, or the contents of your traffic. See the VPN Service Policy. |
| Do we sell or share personal data? | No. We never sell personal data and never disclose it for advertising or unrelated purposes. |
| Are there ads, trackers or analytics SDKs in the apps? | No. The Plan B VPN application contains no advertising, no analytics SDK and no third-party trackers. |
| Do we require an account or an email address for the VPN? | No. Access is granted by an administrator through an access code. There is no public sign-up. |
| Where are the servers? | Frankfurt, Germany, and the United States. |
Who we are
Impeltech LLC, a limited liability company registered in the State of Wyoming, United States, is the controller of the personal data described here.
- Postal address: Cheyenne, Wyoming, USA (full registered address in Company Information)
- Email: info@impeltech.us
- Telephone: +1 646 243 9036
What this policy covers
This policy covers:
- the website impeltech.us, including its contact form;
- the Plan B VPN application for Android and iOS, and the VPN service behind it.
It does not cover:
- Plan B Planner, which has its own privacy policy at plnb.app/privacy;
- Flangapp AI, which our customers install and run on their own servers. In that arrangement the customer is the controller of their end users' data; we receive no end-user data from those installations. Purchases are handled by Envato Market under Envato's own terms.
Data we collect in the Plan B VPN application
Plan B VPN is a private access service: an administrator issues an access code, and the application exchanges that code for a tunnel configuration. There is no public registration, no account, no email address and no payment inside the application.
| Data | Why we need it | Where it is stored |
|---|---|---|
| Access code | Identifies which profile to issue and whether it is still valid | On your device and on our server, with the profile |
| Installation identifier | A random UUID generated on the device at first launch so a profile is not used on several devices at once. It is not a hardware identifier, not an advertising ID, and it is not linked to your identity | On your device and with the profile on our server |
| Profile name | A label chosen by the administrator (for example "Office laptop") so access can be revoked | On our server |
| Tunnel key material and assigned internal address | Required by the WireGuard-based protocol to establish an encrypted tunnel | On your device and on our server |
| Connection state | Your current public IP address (the endpoint of the tunnel) and the time of the last handshake, held in the VPN engine's memory while the tunnel is up | Server memory only; not written to disk and not kept as history |
| Application exclusion list | Which applications you choose to route outside the tunnel | Only on your device. This list is never sent to us |
Data we do not collect
We do not collect, and our servers are not configured to record:
- the websites, hosts or IP addresses you connect to through the tunnel;
- your DNS queries;
- the contents of your traffic;
- browsing history, bandwidth history per destination, or timestamps of individual connections;
- your name, email address, phone number or payment details;
- your precise location, contacts, photos, calendar, microphone or camera data;
- advertising identifiers or any cross-app identifiers.
Data we collect on the website
- Contact form. Your name, email address, the message text and the page you sent it from. We also record the IP address of the request to limit abuse. Messages are delivered to our team through a Telegram bot and stored in a file on our server.
- Server logs. Our web and API servers record the IP address, timestamp, requested path, status code and user agent of requests. These logs exist to keep the service running and to stop abuse; they are deleted after 7 days.
We do not use cookies for tracking, we run no advertising pixels, and there is no third-party analytics on impeltech.us.
Why we process this data, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the VPN service to the device you activated | Performance of a contract |
| Preventing abuse, including one profile being shared across devices | Legitimate interests |
| Answering messages you send us | Legitimate interests, or performance of a contract before entering into it |
| Keeping systems secure and available | Legitimate interests |
| Complying with the law | Legal obligation |
App store privacy disclosures
For Apple's App Privacy questionnaire and Google Play's Data safety form we declare the following for Plan B VPN:
- Data collected: an identifier (the random installation UUID) and the access code, both used solely for App Functionality, both not linked to your identity, and neither used for tracking.
- Data not collected: contact info, health, financial info, location, contacts, user content, search or browsing history, purchases, diagnostics or usage data.
- Tracking: none. We do not track users across apps or websites owned by other companies, and we do not share data with data brokers.
- Data encrypted in transit: yes — all traffic between the application and our servers, and the tunnel itself, is encrypted.
- Deletion: you can request deletion of your profile and associated data at any time; see Data Deletion.
Sharing and service providers
We do not sell personal data and we do not share it for advertising. We use a small number of providers to run the service:
| Provider | What they process | Where |
|---|---|---|
| Kamatera | Hosting of our servers, including the VPN gateway | Frankfurt, Germany |
| Telegram Messenger | Delivery of contact form messages to our team | International |
| Resend | Outgoing email, when we reply to you by email | United States |
We may disclose data if we are legally required to do so. What we are able to disclose about VPN use is limited by what we hold, which is described above and in the VPN Service Policy.
International transfers
Our company is in the United States and our VPN infrastructure is in Germany, so data may be processed in both. Where data of individuals in the European Economic Area or the United Kingdom is transferred to the United States, we rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.
How long we keep data
| Data | Retention |
|---|---|
| VPN profile (access code, installation ID, keys, profile name) | Until the administrator revokes the profile or you ask us to delete it |
| Connection state (current endpoint IP, last handshake) | Held in memory while the tunnel is active; discarded when the tunnel stops or the service restarts |
| Web and API server logs | 7 days |
| Contact form messages | Up to 24 months, so we can follow up on a conversation |
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where processing is based on consent.
If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your national data protection authority.
If you are a California resident, we confirm that we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not discriminate against anyone who exercises their privacy rights.
To exercise any of these rights, write to info@impeltech.us. We answer within 30 days. Because the VPN service holds no name or email address, we may need the access code or profile name to find the right record.
Children
Our services are not directed to children. Plan B VPN is intended for adults who receive an access code from an administrator, and we do not knowingly collect personal data from children under 13 (or under 16 in the European Economic Area). If you believe a child has provided us with personal data, write to us and we will delete it.
Security
- All traffic between the application and our servers uses TLS.
- The tunnel itself is encrypted end to end between your device and our gateway using the WireGuard-based AmneziaWG protocol (ChaCha20-Poly1305 for data, Curve25519 for key exchange).
- Access to the servers is restricted to named administrators using SSH keys; password authentication is disabled.
- Tunnel key material for a profile is generated per profile and can be revoked at any time.
Permissions the application asks for
| Permission | Why |
|---|---|
VPN service (Android VpnService, iOS Network Extension) |
The core function: routing your traffic through the encrypted tunnel. It is used for nothing else |
| Network state | To detect when connectivity changes and re-establish the tunnel |
| Notifications | To show the ongoing notification required by Android while a VPN is active, so the system does not stop the tunnel |
| Installed applications list (Android) | To let you choose which applications bypass the tunnel. The query is limited to launchable applications, the list stays on your device and is never sent to us |
Changes to this policy
If we change this policy we will update the date at the top of the page and, where the change is significant, describe it in the application or by email to the administrator of your profile.
Contact
Impeltech LLC — info@impeltech.us — +1 646 243 9036 — Cheyenne, Wyoming, USA.